On Windows, Adding a self signed root cert and intermediate to the Trusted / Intermediate stores for the Local Machine allow for the X509Chain to validate the certificate chain is valid.
When attempting to run the same code on OS X, we load the self signed root CA to System.keychain and give the "Always Trust" settings.
When running the same code (tests), the tests valid. The self signed root cert is not present in the X509Store when opening and iterating
X509Store store = new X509Store(StoreName.Root, StoreLocation.LocalMachine);
store.Open(OpenFlags.ReadOnly);
When trying to validate a cert signed by this root and intermediate, the validation on OS X fails every time, seemingly since the cert is not located in the X509Store.
It seems as if X509Store is loading "System Roots" which cannot be modified by even administrators.
There is not, at this time, Keychain integration on OSX. The root certificate store is interpreted by OpenSSL's conventions only.
You can add a certificate file to /usr/local/etc/openssl/certs; or append the contents into /usr/local/etc/openssl/cert.pem.
Keychain integration is part of the project to convert from using OpenSSL on macOS to use CommonCrypto/SecurityTransforms/SecureTransport/Keychain, which is currently being tracked at dotnet/runtime#17597.
@bartonjs awesome thanks. Great work on .NET Core all together.
I assume this is the same for Linux itself?
@h3smith The paths for where the root certs go vary slightly by distro. The ones there are what it returned for me on OSX.10.11 (El Capitan). The file is at OPENSSLDIR/cert.pem; the directory is OPENSSLDIR/certs.
On Ubuntu:
$ grep "define OPENSSLDIR" /usr/include/x86_64-linux-gnu/openssl/opensslconf.h
#define OPENSSLDIR "/usr/lib/ssl"
Resulting in /usr/lib/ssl/certs, and /usr/lib/ssl/cert.pem. Though symlinks can always result in other paths also being valid.
@bartonjs Thanks a million.
Most helpful comment
There is not, at this time, Keychain integration on OSX. The root certificate store is interpreted by OpenSSL's conventions only.
You can add a certificate file to
/usr/local/etc/openssl/certs; or append the contents into/usr/local/etc/openssl/cert.pem.Keychain integration is part of the project to convert from using OpenSSL on macOS to use CommonCrypto/SecurityTransforms/SecureTransport/Keychain, which is currently being tracked at dotnet/runtime#17597.