SSL Certificate Chain Contains Unnecessary Certificates

This script is Copyright (C) 2011-2012 Tenable Network Security, Inc.

Synopsis :

The X.509 certificate chain used by this service contains
certificates that aren't required to form a path to the CA.

Description :

At least one of the X.509 certificates sent by the remote host is not
required to form a path from the server's own certificate to the CA.
This may indicate that the certificate bundle installed with the
server's certificate is for certificates lower in the certificate

Some SSL implementations, often those found in embedded devices,
cannot handle certificate chains with unused certificates.

See also :

Solution :

Remove unnecessary certificates from the certificate chain.

Risk factor :


Family: General

Nessus Plugin ID: 56472 ()

Bugtraq ID:


Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now