• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Seize the moment! nominate yourself or a tech enthusiast you admire & join the HP Community Experts!
Common problems for Connectivity Issues
We would like to share some of the most frequently asked questions about Printer Wi-Fi, Connectivity Issues and Offline Status. Check out this link: HP printer is offline or unavailable.
HP Recommended
HP M477fdn
Linux

I am having a problem getting certificates to work properly with my M477fdn printer. I used acme.sh (with DNS challenge) to generate a "letsencrypt" certificate and private key. I combined those two things into a pkcs12 file with openssl and successfully uploaded it to my printer. I also successfully uploaded letsencrypt's intermediate CA certificate (i.e. the certificate which signed the printer's certificate). However, on new TLS connections the printer is only returning its own certificate and is not returning the CA certificate as part of the certificate chain. How do I get the printer to return the CA certificate?

 

ca.png

$ openssl s_client -showcerts -connect m477fdn.tomiii.com:443
CONNECTED(00000003)
depth=0 CN = m477fdn.tomiii.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = m477fdn.tomiii.com
verify error:num=21:unable to verify the first certificate
verify return:1
---
Certificate chain
0 s:CN = m477fdn.tomiii.com
i:C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
-----BEGIN CERTIFICATE-----
MIIFWzCCBEOgAwIBAgISBDaNL+vDyqmtFy7p8yvpRzwkMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0yMDEwMTUwMzQ4NTNaFw0y
MTAxMTMwMzQ4NTNaMB0xGzAZBgNVBAMTEm00NzdmZG4udG9taWlpLmNvbTCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANFConAQHbbXj4qtsa5v3Owu41/Q
f4zEt3xMzA0xsVx1aYSJq2PRx3+9KOol0hYm+PpbtU6dIa4m2G5ChiA0OoY5b6BX
bXwpe5VsDpkMa+BtirE5J+tzeacPwp5MntTkB2YsamCr1cZYnp3+PkRQLAw1woFW
Vj1jin7kg2hp0WBZMquij6odDgwGwvmIYIRfCYxz+JkNKIBDXpJVTgP/MuYKnF9w
5t0lLwWkRFtduLVvEWIu0fRmJ8AYI78l75oV+0/4j1d2tA1dYhKiO5gK0akkdXnC
pbnyrhIhHTrtNw1GH72rjqt95Mc5qzDqpb4dYdIC6oJCT6qEnPPoxlw3Kt0CAwEA
AaOCAmYwggJiMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYI
KwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUpQR815OaiF6LjnU3z3wi
8G/A15owHwYDVR0jBBgwFoAUqEpqYwR93brm0Tm3pkVl7/Oo7KEwbwYIKwYBBQUH
AQEEYzBhMC4GCCsGAQUFBzABhiJodHRwOi8vb2NzcC5pbnQteDMubGV0c2VuY3J5
cHQub3JnMC8GCCsGAQUFBzAChiNodHRwOi8vY2VydC5pbnQteDMubGV0c2VuY3J5
cHQub3JnLzAdBgNVHREEFjAUghJtNDc3ZmRuLnRvbWlpaS5jb20wTAYDVR0gBEUw
QzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDov
L2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEDBgorBgEEAdZ5AgQCBIH0BIHxAO8AdgBc
3EOS/uarRUSxXprUVuYQN/vV+kfcoXOUsl7m9scOygAAAXUqluOJAAAEAwBHMEUC
IQCBoqhbMISHHDxlFaGGuYPax8tOSylP77R20ZLeb/QocwIgTRLqt1r8D5c/M8Q6
dwmVPK++cQH9akOaKjtMq2WmpVcAdQD2XJQv0XcwIhRUGAgwlFaO400TGTO/3wwv
IAvMTvFk4wAAAXUqluN2AAAEAwBGMEQCID+QltxotrP2cUjx7yevZcdo6aDDEDPr
ihmTF6/BoEggAiBrPFxJu/UGCoVvTBSTMKAx00fP2j+tdZBgchfirAQu3jANBgkq
hkiG9w0BAQsFAAOCAQEAhFXyrXS1IYXwC2NJCLlmNGaA5cZNnRVuDpYCXkOXpEq1
DlceKdxfmDxJuDZwnUZgG+ITYFIXlqTGfFm74Qb8PB/J0z34Ds0N8wBU583yl2r3
odCf6trpahAv0Dttma2YEWE6LqbxpN0GHI4Z6adq9uoRk5lD7rgyOEPCDisDcHfZ
HOkr9REa0HNiR/Vn2j7/QCa8NJM12IS5ul89WTUxW9sihqXZ4EF+RGBLniFQsgSH
p0kMlVF8yR/R9ZUrGNF7Zqjbb8KWOc/hGmigk0jfdpl81enQB9Wzzt5xdaQY7X/p
L8QS/vKnMZ2QovID78lrMWMIhQAr+iOznxmqyQnObg==
-----END CERTIFICATE-----
---
Server certificate
subject=CN = m477fdn.tomiii.com

issuer=C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3

---
No client certificate CA names sent
---
SSL handshake has read 1699 bytes and written 648 bytes
Verification error: unable to verify the first certificate
---

 

1 REPLY 1
HP Recommended

Not sure why my screenshot isn't visible in the original post. Here it is again in JPG format.

ca.jpg

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.