Client CA Settings

Change the current CA-chain.

Warning

Answering “y” to “Remove current CA chain?” does not just delete the file — it also disables mTLS validation entirely (equivalent to Disable mTLS), since validation cannot continue without a trust anchor. If you only want to replace the CA chain, answer “n” here and then “y” to “Install a new CA chain?” instead — do not remove the old one first unless you specifically intend to disable mTLS.

Issuers in the CA chain (/isodevice/persistent/etc/nginx/ssl/storedsafe-mtls-ca.pem):
subject=C = SE, ST = Stockholm, O = Corp INC, OU = CA Team, CN = ca.corp.com
issuer=C = SE, ST = Stockholm, O = Corp INC, OU = CA Team, CN = ca.corp.com

Remove current CA chain? (y/<N>):
Install a new CA chain? (y/<N>):
Activate the existing CA chain? (<Y>/n):
Activate new settings? (<Y>/n):
No updates to crl from http://ca.corp.com/CorpInternalRootCAv1.crl
No updates to crl from http://ca.corp.com/CorpPerson4CAv1.crl
No updates to crl from https://dept.ca.corp.com/corp-crl.pem
Nothing to do

Restart the web server to activate the new settings? (<Y>/n):