# SSL3 alert write:fatal:certificate unknown

**URL:** <https://forums.suse.com/t/ssl3-alert-write-fatal-certificate-unknown/6020>\
**Category:** General\
**Created:** [March 30, 2017, 4:21pm UTC](https://forums.suse.com/t/ssl3-alert-write-fatal-certificate-unknown/6020 "2017-03-30T16:21:43Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anitha](https://avatars.discourse-cdn.com/v4/letter/a/a587f6/32.png) [@Anitha](https://forums.suse.com/u/Anitha)\
**Post date:** [March 30, 2017, 4:21pm UTC](https://forums.suse.com/t/ssl3-alert-write-fatal-certificate-unknown/6020/1 "2017-03-30T16:21:44Z")

</div>

I am using OpenLDAP 2.4.33 in Linux and it is integrated with my application. Our customer is using certifcate chain.  
The certificate seem to work well with Openssl but fails when we authenticate with application.I have enabled debug statements and see it fails certificate unknown error with and I see below error:

ldap\_sasl\_bind\_s  
ldap\_sasl\_bind  
Inside ldap\_send\_initial\_request  
Calling ldap\_open\_defconn  
ldap\_new\_connection 1 1 0  
Calling ldap\_int\_open\_connection  
ldap\_int\_open\_connection  
Inside ldap\_connect\_to\_host  
In HAVE\_GETADDRINFO and HAVE\_INET\_NTOP  
host =[ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com)  
proto=1  
ldap\_connect\_to\_host: TCP [ITSUSRANADC41.na.jnj.com:3269](http://ITSUSRANADC41.na.jnj.com:3269)  
Calling ldap\_int\_socket  
ldap\_new\_socket: 19  
after Calling ldap\_int\_socket s=19  
Calling ldap\_int\_prepare\_socket  
ldap\_prepare\_socket: 19  
AF\_INET  
ldap\_connect\_to\_host: Trying 10.36.108.29:3269  
Calling ldap\_pvt\_connect  
Inside ldap\_pvt\_connect  
ldap\_pvt\_connect: fd: 19 tm: 10 async: 0  
ldap\_ndelay\_on: 19  
Calling ldap\_int\_poll  
ldap\_int\_poll: fd: 19 tm: 10  
ldap\_is\_sock\_ready: 19  
ldap\_ndelay\_off: 19  
after Calling ldap\_int\_poll  
ldap\_pvt\_connect: 0  
ldap\_pvt\_connect: 0  
After Calling ldap\_pvt\_connect rc=0  
Calling ldap\_int\_connect\_cbs  
Inside ldap\_int\_connect\_cbs  
leaving ldap\_int\_connect\_cbs retrun 0  
After Calling ldap\_int\_connect\_cbs err =0  
SSL\_CTX\_load\_verify\_locations=1  
SSL\_CTX\_set\_default\_verify\_paths=1  
In lo-\>ldo\_tls\_require\_cert  
In lo-\>ldo\_tls\_require\_cert i=3  
Calling SSL\_CTX\_set\_verify  
After Calling SSL\_CTX\_set\_verify  
TLS trace: SSL\_connect:before/connect initialization  
TLS trace: SSL\_connect:SSLv3 write client hello A  
TLS trace: SSL\_connect:SSLv3 read server hello A  
TLS trace: SSL\_connect:SSLv3 process tls extension  
TLS trace: SSL\_connect:SSL3 post/by-pass tls extension processing  
TLS trace: SSL\_connect:SSLv3 read server certificate A  
inside tlso\_verify\_cb  
TLS certificate verification: depth: 0, err: 0, subject: /CN=[ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com), issuer: /DC=com/DC=jnj/CN=JNJ Internal Online CA A2  
inside tlso\_verify\_cb  
TLS certificate verification: depth: 1, err: 0, subject: /DC=com/DC=jnj/CN=JNJ Internal Online CA A2, issuer: /DC=COM/DC=JNJ/CN=JNJ Internal Root Certification Authority  
inside tlso\_verify\_cb  
**_TLS certificate verification: depth: 2, err: 0, subject: /DC=COM/DC=JNJ/CN=JNJ Internal Root Certification Authority, issuer: /DC=COM/DC=JNJ/CN=JNJ Internal Root Certification Authority_**  
**_TLS trace: SSL3 alert write:fatal:certificate unknown_**  
**_TLS trace: SSL\_connect:error in SSL3 certificate verify A_**  
**_TLS: can’t connect: error:14090086:SSL routines:SSL3\_GET\_SERVER\_CERTIFICATE:certificate verify failed (ok)._**  
**_After Calling ldap\_int\_open\_connection rc = 0_**  
LDAP\_SERVER\_DOWN  
After calling ldap\_open\_defconn ,rc = -1  
ldp\_send\_initial\_request… ldap\_open\_defconn failed  
ldap\_err2string  
The same certificate (pem) connects perfectly with openssl commands.

[dmfs4adm@itsusral00157 ldapdb]$ openssl s\_client -CAfile /dmfs4/apps/documentum/dba/secure/ldapdb/INT-PROD-Root-Intermedia\_0320.pem -connect ITSUSRANADC41.na.j [nj.com:3269](http://nj.com:3269)  
CONNECTED(00000003)  
depth=2 DC = COM, DC = JNJ, CN = JNJ Internal Root Certification Authority  
verify return:1  
depth=1 DC = com, DC = jnj, CN = JNJ Internal Online CA A2  
verify return:1  
depth=0 CN = [ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com)  
verify return:1  
—  
Certificate chain  
0 s:/CN=[ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com)  
i:/DC=com/DC=jnj/CN=JNJ Internal Online CA A2  
1 s:/DC=com/DC=jnj/CN=JNJ Internal Online CA A2  
i:/DC=COM/DC=JNJ/CN=JNJ Internal Root Certification Authority

Server certificate  
----BEGIN CERTIFICATE----  
----END CERTIFICATE----  
subject=/CN=[ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com)  
issuer=/DC=com/DC=jnj/CN=JNJ Internal Online CA A2  
—  
Acceptable client certificate CA names  
/CN=[ITSUSRANADC41.na.jnj.com](http://ITSUSRANADC41.na.jnj.com)  
/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Roo t  
/C=US/O=JNJ/OU=JNJ Public Key Authorities/CN=JNJ 2048bit Root Certification Auth ority  
/C=US/O=JNJ/OU=JNJ Public Key Authorities/CN=JNJ Root Certification Authority  
/DC=COM/DC=JNJ/CN=JNJ Internal Root Certification Authority  
/C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=© 2008 VeriSign, Inc. - Fo r authorized use only/CN=VeriSign Universal Root Certification Authority  
/C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=© 2006 VeriSign, Inc. - Fo r authorized use only/CN=VeriSign Class 3 Public Primary Certification Authority - G5  
/C=US/O=VeriSign, Inc./OU=Class 3 Public Primary Certification Authority  
/C=US/O=VeriSign, Inc./OU=Class 3 Public Primary Certification Authority - G2/OU =© 1998 VeriSign, Inc. - For authorized use only/OU=VeriSign Trust Network  
/C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Root Certific ate Authority 2011  
/C=US/O=GTE Corporation/OU=GTE CyberTrust Solutions, Inc./CN=GTE CyberTrust Glob al Root  
/C=IE/O=Baltimore/OU=CyberTrust/CN=Baltimore CyberTrust Root  
/C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Root Certific ate Authority 2010  
/O=Symantec Corporation/CN=Symantec Root CA  
/OU=Copyright © 1997 Microsoft Corp./OU=Microsoft Corporation/CN=Microsoft Roo t Authority  
/C=US/O=Symantec Corporation/CN=Symantec Root 2005 CA  
/DC=com/DC=microsoft/CN=Microsoft Root Certificate Authority  
/CN=NT AUTHORITY  
—  
SSL handshake has read 5700 bytes and written 619 bytes  
—  
New, TLSv1/SSLv3, Cipher is AES128-SHA256  
Server public key is 2048 bit  
Secure Renegotiation IS supported  
Compression: NONE  
Expansion: NONE  
SSL-Session:  
Protocol : TLSv1.2  
Cipher : AES128-SHA256  
Session-ID: 743C00003D9B50EAA53C45E670C3E9682DBE86BA873CEA5B35BFB16B7CE5A625  
Session-ID-ctx:  
Master-Key: 0DB1DB6C4E9B3BE57E6E3A38B3A68EACAF96A78650EA978B4A8860B35BBDCCB4 61DA777F8C0D83ED53CCFE82748D3F86  
Key-Arg : None  
Krb5 Principal: None  
PSK identity: None  
PSK identity hint: None  
Start Time: 1490103903  
Timeout : 300 (sec)  
Verify return code: 0 (ok)  
—

The pem contains certificates JNJ Internal Root Certification Authority and CN=JNJ Internal Online CA C2 .
