SSL Certificate Chain Contains Unnecessary Certificates

This script is Copyright (C) 2011-2012 Tenable Network Security, Inc.


Synopsis :

The X.509 certificate chain used by this service contains
certificates that aren't required to form a path to the CA.

Description :

At least one of the X.509 certificates sent by the remote host is not
required to form a path from the server's own certificate to the CA.
This may indicate that the certificate bundle installed with the
server's certificate is for certificates lower in the certificate
hierarchy.

Some SSL implementations, often those found in embedded devices,
cannot handle certificate chains with unused certificates.

See also :

http://www.ietf.org/rfc/rfc4346.txt

Solution :

Remove unnecessary certificates from the certificate chain.

Risk factor :

None

Family: General

Nessus Plugin ID: 56472 ()

Bugtraq ID:

CVE ID: