[katello] GeoTrust/RapidSSL WildCard cert issue

I am trying to run "subscription-manager refresh" from my client server,
running CentOS 7, but I get the below error. My katello server is also
CentOS 7, but I have tried CentOS 6.6 and had the same problem.

[root@myclient ~]# subscription-manager refresh
Unable to verify server's identity: tlsv1 alert unknown ca

This is the error I am seeing in the rhsm.log file:

2014-12-16 03:25:03,477 [ERROR] rhsmd @cache.py:219 - Consumer certificate
is invalid
2014-12-16 07:11:23,629 [DEBUG] subscription-manager @plugins.py:533 -
loaded plugin modules: []
2014-12-16 07:11:23,630 [DEBUG] subscription-manager @plugins.py:534 -
loaded plugins: {}
2014-12-16 07:11:23,657 [DEBUG] subscription-manager @identity.py:130 -
Loading consumer info from identity certificates.
2014-12-16 07:11:23,663 [DEBUG] subscription-manager @profile.py:97 -
Loading current RPM profile.
2014-12-16 07:11:23,693 [INFO] subscription-manager @managercli.py:288 -
Client Versions: {'python-rhsm': '1.10.12-2.el7', 'subscription-manager':
'1.10.14-9.el7.centos'}
2014-12-16 07:11:23,694 [INFO] subscription-manager @connection.py:663 -
Using certificate authentication: key = /etc/pki/consumer/key.pem, cert =
/etc/pki/consumer/cert.pem, ca = /etc/rhsm/ca/, insecure = False
2014-12-16 07:11:23,694 [INFO] subscription-manager @connection.py:674 -
Connection Built: host: katello.office.mydomain.net, port: 443, handler:
/rhsm
2014-12-16 07:11:23,694 [INFO] subscription-manager @connection.py:670 -
Using no auth
2014-12-16 07:11:23,695 [INFO] subscription-manager @connection.py:674 -
Connection Built: host: katello.office.mydomain.net, port: 443, handler:
/rhsm
2014-12-16 07:11:23,696 [DEBUG] subscription-manager @connection.py:418 -
Loaded CA certificates from /etc/rhsm/ca/: candlepin-local.pem,
katello-server-ca.pem
2014-12-16 07:11:23,696 [DEBUG] subscription-manager @connection.py:450 -
Making request: GET /rhsm/
2014-12-16 07:11:24,110 [DEBUG] subscription-manager @connection.py:473 -
Response: status=200
2014-12-16 07:11:24,111 [DEBUG] subscription-manager @connection.py:690 -
Server supports the following resources:
2014-12-16 07:11:24,111 [DEBUG] subscription-manager @connection.py:691 -
{'available_releases': '/katello/api/available_releases', 'distributors':
'/katello/api/distributors/', 'content_overrides':
'/katello/api/content_overrides', 'environments':
'/katello/api/environments/', 'content_views':
'/katello/api/content_views/', 'content_view_filters':
'/katello/api/content_view_filters/', 'puppet_modules':
'/katello/api/puppet_modules/', 'host_collections':
'/katello/api/host_collections/', 'guestids': '/katello/api/guestids',
'systems': '/katello/api/systems/', 'gpg_keys': '/katello/api/gpg_keys/',
'status': '/katello/api/status/', 'capsules': '/katello/api/capsules/',
'users': '/katello/api/users/', 'sync_plans': '/katello/api/sync_plans/',
'subscriptions': '/katello/api/subscriptions/', 'content_view_versions':
'/katello/api/content_view_versions/', 'packages':
'/katello/api/packages/', 'organizations': '/katello/api/organizations/',
'package_groups': '/katello/api/package_groups/', 'repository_sets':
'/katello/api/repository_sets/', 'repositories':
'/katello/api/repositories/', 'products': '/katello/api/products/',
'activation_keys': '/katello/api/activation_keys/', 'errata':
'/katello/api/errata/'}
2014-12-16 07:11:24,112 [DEBUG] subscription-manager @connection.py:418 -
Loaded CA certificates from /etc/rhsm/ca/: candlepin-local.pem,
katello-server-ca.pem
2014-12-16 07:11:24,112 [DEBUG] subscription-manager @connection.py:450 -
Making request: GET /rhsm/status
2014-12-16 07:11:24,259 [DEBUG] subscription-manager @connection.py:473 -
Response: status=200
2014-12-16 07:11:24,260 [INFO] subscription-manager @managercli.py:299 -
Server Versions: {'candlepin': '2.0.0-0.el7-Katello', 'server-type': 'Red
Hat Subscription Management'}
2014-12-16 07:11:24,262 [DEBUG] subscription-manager @connection.py:418 -
Loaded CA certificates from /etc/rhsm/ca/: candlepin-local.pem,
katello-server-ca.pem
2014-12-16 07:11:24,262 [DEBUG] subscription-manager @connection.py:450 -
Making request: GET
/rhsm/consumers/7b0dc4c1-3e73-40dc-be52-1cdf14c5ee0e/certificates/serials
2014-12-16 07:11:24,285 [ERROR] subscription-manager @managercli.py:156 -
Unable to perform refresh due to the following exception: tlsv1 alert
unknown ca
2014-12-16 07:11:24,285 [ERROR] subscription-manager @managercli.py:157 -
tlsv1 alert unknown ca
Traceback (most recent call last):
File "/usr/share/rhsm/subscription_manager/managercli.py", line 541, in
_do_command
self.certlib.update()
File "/usr/share/rhsm/subscription_manager/certlib.py", line 69, in update
return self._do_update()
File "/usr/share/rhsm/subscription_manager/certlib.py", line 92, in
_do_update
return action.perform(lock=self.lock)
File "/usr/share/rhsm/subscription_manager/certlib.py", line 235, in
perform
expected = self._get_expected_serials(report)
File "/usr/share/rhsm/subscription_manager/certlib.py", line 322, in
_get_expected_serials
exp = self.get_certificate_serials_list()
File "/usr/share/rhsm/subscription_manager/certlib.py", line 315, in
get_certificate_serials_list
reply = self.uep.getCertificateSerials(self._get_consumer_id())
File "/usr/lib64/python2.7/site-packages/rhsm/connection.py", line 916,
in getCertificateSerials
return self.conn.request_get(method)
File "/usr/lib64/python2.7/site-packages/rhsm/connection.py", line 554,
in request_get
return self._request("GET", method)
File "/usr/lib64/python2.7/site-packages/rhsm/connection.py", line 457,
in _request
conn.request(request_type, handler, body=body, headers=headers)
File "/usr/lib64/python2.7/httplib.py", line 973, in request
self._send_request(method, url, body, headers)
File "/usr/lib64/python2.7/httplib.py", line 1007, in _send_request
self.endheaders(body)
File "/usr/lib64/python2.7/httplib.py", line 969, in endheaders
self._send_output(message_body)
File "/usr/lib64/python2.7/httplib.py", line 829, in _send_output
self.send(msg)
File "/usr/lib64/python2.7/httplib.py", line 791, in send
self.connect()
File "/usr/lib64/python2.7/site-packages/M2Crypto/httpslib.py", line 58,
in connect
sock.connect((self.host, self.port))
File "/usr/lib64/python2.7/site-packages/M2Crypto/SSL/Connection.py",
line 185, in connect
ret = self.connect_ssl()
File "/usr/lib64/python2.7/site-packages/M2Crypto/SSL/Connection.py",
line 178, in connect_ssl
return m2.ssl_connect(self.ssl, self._timeout)
SSLError: tlsv1 alert unknown ca

If I run "subscription-manager list --available" I get:

2014-12-16 07:12:32,194 [ERROR] subscription-manager @managercli.py:156 -
exception caught in subscription-manager
2014-12-16 07:12:32,195 [ERROR] subscription-manager @managercli.py:157 -
Error updating system data on the server, see /var/log/rhsm/rhsm.log for
more details.
Traceback (most recent call last):
File "/usr/sbin/subscription-manager", line 82, in <module>
sys.exit(abs(main() or 0))
File "/usr/sbin/subscription-manager", line 73, in main
return managercli.ManagerCLI().main()
File "/usr/share/rhsm/subscription_manager/managercli.py", line 2397, in
main
return CLI.main(self)
File "/usr/share/rhsm/subscription_manager/cli.py", line 160, in main
return cmd.main()
File "/usr/share/rhsm/subscription_manager/managercli.py", line 424, in
main
return_code = self._do_command()
File "/usr/share/rhsm/subscription_manager/managercli.py", line 2060, in
do_command
uninstalled=self.options.match_installed)
File "/usr/share/rhsm/subscription_manager/managerlib.py", line 322, in
get_available_entitlements
overlapping, uninstalled, text)
File "/usr/share/rhsm/subscription_manager/managerlib.py", line 526, in
get_filtered_pools_list
self.identity.uuid, self.facts, active_on=active_on):
File "/usr/share/rhsm/subscription_manager/managerlib.py", line 291, in
list_pools
facts.update_check(uep, consumer_uuid)
File "/usr/share/rhsm/subscription_manager/cache.py", line 183, in
update_check
raise Exception(
("Error updating system data on the server, see
/var/log/rhsm/rhsm.log "
Exception: Error updating system data on the server, see
/var/log/rhsm/rhsm.log for more details.

I run a cert test from the client to my katello server and it verified fine:

verify depth is 32
depth=2 C = US, O = GeoTrust Inc., CN = GeoTrust Global CA
verify return:1
depth=1 C = US, O = "GeoTrust, Inc.", CN = RapidSSL CA
verify return:1
depth=0 serialNumber = G7FkiJIImQR-ZrMucXArQ-1Lc5QBn9XP, OU = GT87906819,
OU = See www.rapidssl.com/resources/cps ©14, OU = Domain Control
Validated - RapidSSL®, CN = *.office.mydomain.net
verify return:1

CONNECTED(00000003)

··· --- Certificate chain 0 s:/serialNumber=G7FkiJIImQR-ZrMucXArQ-1Lc5QBn9XP/OU=GT87906819/OU=See www.rapidssl.com/resources/cps (c)14/OU=Domain Control Validated - RapidSSL(R)/CN=*.office.mydomain.net i:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA -----BEGIN CERTIFICATE----- MIIFMjCCBBqgAwIBAgIDFQOxMA0GCSqGSIb3DQEBBQUAMDwxCzAJBgNVBAYTAlVT MRcwFQYDVQQKEw5HZW9UcnVzdCwgSW5jLjEUMBIGA1UEAxMLUmFwaWRTU0wgQ0Ew HhcNMTQwOTAzMTE1NjQ4WhcNMTgxMTA0MDIzNjE2WjCBxTEpMCcGA1UEBRMgRzdG a2lKSUltUVItWnJNdWNYQXJRLTFMYzVRQm45WFAxEzARBgNVBAsTCkdUODc5MDY4 MTkxMTAvBgNVBAsTKFNlZSB3d3cucmFwaWRzc2wuY29tL3Jlc291cmNlcy9jcHMg KGMpMTQxLzAtBgNVBAsTJkRvbWFpbiBDb250cm9sIFZhbGlkYXRlZCAtIFJhcGlk U1NMKFIpMR8wHQYDVQQDDBYqLm9mZmljZS53ZWJhc3NpZ24ubmV0MIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzLmaTIoHo8bLA+E33YeJXwYZ+hRizkgD 6hUjFZaG5zHAw3V0Aosi9BDnhcuFiaBz3XOp9qOWWRT4MtB9ZFVmxPhnTTUF6m+V xNtCfJbf1ehRS0DbddcxJtHMt6bj3Tv/Yt3/GL6FL7UIoZ4PuA2xGefR6y7nvSap vwAZcdsTQPd0cv3/u+rQEsBcorVIythvziTF+h7heSBkuFcmA0o/aaRjUuvmpmJU c+kifUvz+sE9AX+g9zJhO4AuEXi7K4LfXyLN6CgSVI1t44moWNceo+37vUlV6yKr /qmWcXeBc593TuthLD31Pq5dNmBAugg4bsMXMYHZs6DURrdTccf8ewIDAQABo4IB sTCCAa0wHwYDVR0jBBgwFoAUa2k9ahhCSt2PAmU5/TUkhniRFjAwDgYDVR0PAQH/ BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAhBgNVHREEGjAY ghYqLm9mZmljZS53ZWJhc3NpZ24ubmV0MEMGA1UdHwQ8MDowOKA2oDSGMmh0dHA6 Ly9yYXBpZHNzbC1jcmwuZ2VvdHJ1c3QuY29tL2NybHMvcmFwaWRzc2wuY3JsMB0G A1UdDgQWBBSlaaWy/bml9DvX6QRzq36F3vNp8TAMBgNVHRMBAf8EAjAAMHgGCCsG AQUFBwEBBGwwajAtBggrBgEFBQcwAYYhaHR0cDovL3JhcGlkc3NsLW9jc3AuZ2Vv dHJ1c3QuY29tMDkGCCsGAQUFBzAChi1odHRwOi8vcmFwaWRzc2wtYWlhLmdlb3Ry dXN0LmNvbS9yYXBpZHNzbC5jcnQwTAYDVR0gBEUwQzBBBgpghkgBhvhFAQc2MDMw MQYIKwYBBQUHAgEWJWh0dHA6Ly93d3cuZ2VvdHJ1c3QuY29tL3Jlc291cmNlcy9j cHMwDQYJKoZIhvcNAQEFBQADggEBABejfbuzXLqBTu0QAGr0oZ77yWH1Ok0hIzHF qCqwwzFWjugc+FsSjPNli9q48wJqZNJW6VfOig4HabDJ8N/nYMH2pDSZf4OZC9Hb ShoslRiYk+d5WxENyyLueMxgVhg0wXAQlPdJCxXo1iz2WLog+LOxCyLGLQnaqiqd OfKX4YxrTUXfigLBSePYpgJKBk0mqPxVqrcCMiYmIliBf9SVbXv7H4zWth03aK6N STLdtYRfAd8p2mGWcXPp4tvwwM9tb8nV06xzAlxpXEkhHZPNCx5u8/oE4I9MSjIC tPbhxqKesRngC1ipuuGSIzWnmLiU5NKchmzurAQ9oLAhBOqNy4Y= -----END CERTIFICATE----- 1 s:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority -----BEGIN CERTIFICATE----- MIIDIDCCAomgAwIBAgIENd70zzANBgkqhkiG9w0BAQUFADBOMQswCQYDVQQGEwJV UzEQMA4GA1UEChMHRXF1aWZheDEtMCsGA1UECxMkRXF1aWZheCBTZWN1cmUgQ2Vy dGlmaWNhdGUgQXV0aG9yaXR5MB4XDTk4MDgyMjE2NDE1MVoXDTE4MDgyMjE2NDE1 MVowTjELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0VxdWlmYXgxLTArBgNVBAsTJEVx dWlmYXggU2VjdXJlIENlcnRpZmljYXRlIEF1dGhvcml0eTCBnzANBgkqhkiG9w0B AQEFAAOBjQAwgYkCgYEAwV2xWGcIYu6gmi0fCG2RFGiYCh7+2gRvE4RiIcPRfM6f BeC4AfBONOziipUEZKzxa1NfBbPLZ4C/QgKO/t0BCezhABRP/PvwDN1Dulsr4R+A cJkVV5MW8Q+XarfCaCMczE1ZMKxRHjuvK9buY0V7xdlfUNLjUA86iOe/FP3gx7kC AwEAAaOCAQkwggEFMHAGA1UdHwRpMGcwZaBjoGGkXzBdMQswCQYDVQQGEwJVUzEQ MA4GA1UEChMHRXF1aWZheDEtMCsGA1UECxMkRXF1aWZheCBTZWN1cmUgQ2VydGlm aWNhdGUgQXV0aG9yaXR5MQ0wCwYDVQQDEwRDUkwxMBoGA1UdEAQTMBGBDzIwMTgw ODIyMTY0MTUxWjALBgNVHQ8EBAMCAQYwHwYDVR0jBBgwFoAUSOZo+SvSspXXR9gj IBBPM5iQn9QwHQYDVR0OBBYEFEjmaPkr0rKV10fYIyAQTzOYkJ/UMAwGA1UdEwQF MAMBAf8wGgYJKoZIhvZ9B0EABA0wCxsFVjMuMGMDAgbAMA0GCSqGSIb3DQEBBQUA A4GBAFjOKer89961zgK5F7WF0bnj4JXMJTENAKaSbn+2kmOeUJXRmm/kEd5jhW6Y 7qj/WsjTVbJmcVfewCHrPSqnI0kBBIZCe/zuf6IWUrVnZ9NA2zsmWLIodz2uFHdh 1voqZiegDfqnc1zqcPGUIWVEX/r87yloqaKHee9570+sB3c4 -----END CERTIFICATE----- 2 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA -----BEGIN CERTIFICATE----- MIIDVDCCAjygAwIBAgIDAjRWMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYTAlVT MRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVzdCBHbG9i YWwgQ0EwHhcNMDIwNTIxMDQwMDAwWhcNMjIwNTIxMDQwMDAwWjBCMQswCQYDVQQG EwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UEAxMSR2VvVHJ1c3Qg R2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2swYYzD9 9BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEHCIjaWC9mOSm9BXiLnTjoBbdq fnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlCGDUUna2YRpIuT8rxh0PBFpVXLVDv iS2Aelet8u5fa9IAjbkU+BQVNdnARqN7csiRv8lVK83Qlz6cJmTM386DGXHKTubU 1XupGc1V3sjs0l44U+VcT4wt/lAjNvxm5suOpDkZALeVAjmRCw7+OC7RHQWa9k0+ bw8HHa8sHo9gOeL6NlMTOdReJivbPagUvTLrGAMoUgRx5aszPeE4uwc2hGKceeoW MPRfwCvocWvk+QIDAQABo1MwUTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTA ephojYn7qwVkDBF9qn1luMrMTjAfBgNVHSMEGDAWgBTAephojYn7qwVkDBF9qn1l uMrMTjANBgkqhkiG9w0BAQUFAAOCAQEANeMpauUvXVSOKVCUn5kaFOSPeCpilKIn Z57QzxpeR+nBsqTP3UEaBU6bS+5Kb1VSsyShNwrrZHYqLizz/Tt1kL/6cdjHPTfS tQWVYrmm3ok9Nns4d0iXrKYgjy6myQzCsplFAMfOEVEiIuCl6rYVSAlk6l5PdPcF PseKUgzbFbS9bZvlxrFUaKnjaZC2mqUPuLk/IH2uSrW4nOQdtqvmlKXBx4Ot2/Un hw4EbNX/3aBd7YdStysVAq45pmp06drE57xNNB6pXE0zX5IJL4hmXXeXxx12E6nV 5fEWCRE11azbJHFwLJhWC9kXtNHjUStedejV0NxPNO3CBWaAocvmMw== -----END CERTIFICATE----- 3 s:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA -----BEGIN CERTIFICATE----- MIID1TCCAr2gAwIBAgIDAjbRMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYTAlVT MRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVzdCBHbG9i YWwgQ0EwHhcNMTAwMjE5MjI0NTA1WhcNMjAwMjE4MjI0NTA1WjA8MQswCQYDVQQG EwJVUzEXMBUGA1UEChMOR2VvVHJ1c3QsIEluYy4xFDASBgNVBAMTC1JhcGlkU1NM IENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3H4Vsce2cy1rfa0 l6P7oeYLUF9QqjraD/w9KSRDxhApwfxVQHLuverfn7ZB9EhLyG7+T1cSi1v6kt1e 6K3z8Buxe037z/3R5fjj3Of1c3/fAUnPjFbBvTfjW761T4uL8NpPx+PdVUdp3/Jb ewdPPeWsIcHIHXro5/YPoar1b96oZU8QiZwD84l6pV4BcjPtqelaHnnzh8jfyMX8 N8iamte4dsywPuf95lTq319SQXhZV63xEtZ/vNWfcNMFbPqjfWdY3SZiHTGSDHl5 HI7PynvBZq+odEj7joLCniyZXHstXZu8W1eefDp6E63yoxhbK1kPzVw662gzxigd gtFQiwIDAQABo4HZMIHWMA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUa2k9ahhC St2PAmU5/TUkhniRFjAwHwYDVR0jBBgwFoAUwHqYaI2J+6sFZAwRfap9ZbjKzE4w EgYDVR0TAQH/BAgwBgEB/wIBADA6BgNVHR8EMzAxMC+gLaArhilodHRwOi8vY3Js Lmdlb3RydXN0LmNvbS9jcmxzL2d0Z2xvYmFsLmNybDA0BggrBgEFBQcBAQQoMCYw JAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmdlb3RydXN0LmNvbTANBgkqhkiG9w0B AQUFAAOCAQEAq7y8Cl0YlOPBscOoTFXWvrSY8e48HM3P8yQkXJYDJ1j8Nq6iL4/x /torAsMzvcjdSCIrYA+lAxD9d/jQ7ZZnT/3qRyBwVNypDFV+4ZYlitm12ldKvo2O SUNjpWxOJ4cl61tt/qJ/OCjgNqutOaWlYsS3XFgsql0BYKZiZ6PAx2Ij9OdsRu61 04BqIhPSLT90T+qvjF+0OJzbrs6vhB6m9jRRWXnT43XcvNfzc9+S7NIgWW+c+5X4 knYYCnwPLKbK3opie9jzzl9ovY8+wXS7FXI6FoOpC+ZNmZzYV+yoAVHHb1c0XqtK LEL2TxyJeN4mTvVvk0wVaydWTQBUbHq3tw== -----END CERTIFICATE----- 4 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority -----BEGIN CERTIFICATE----- MIIDfTCCAuagAwIBAgIDErvmMA0GCSqGSIb3DQEBBQUAME4xCzAJBgNVBAYTAlVT MRAwDgYDVQQKEwdFcXVpZmF4MS0wKwYDVQQLEyRFcXVpZmF4IFNlY3VyZSBDZXJ0 aWZpY2F0ZSBBdXRob3JpdHkwHhcNMDIwNTIxMDQwMDAwWhcNMTgwODIxMDQwMDAw WjBCMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UE AxMSR2VvVHJ1c3QgR2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEA2swYYzD99BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEHCIjaWC9m OSm9BXiLnTjoBbdqfnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlCGDUUna2YRpIu T8rxh0PBFpVXLVDviS2Aelet8u5fa9IAjbkU+BQVNdnARqN7csiRv8lVK83Qlz6c JmTM386DGXHKTubU1XupGc1V3sjs0l44U+VcT4wt/lAjNvxm5suOpDkZALeVAjmR Cw7+OC7RHQWa9k0+bw8HHa8sHo9gOeL6NlMTOdReJivbPagUvTLrGAMoUgRx5asz PeE4uwc2hGKceeoWMPRfwCvocWvk+QIDAQABo4HwMIHtMB8GA1UdIwQYMBaAFEjm aPkr0rKV10fYIyAQTzOYkJ/UMB0GA1UdDgQWBBTAephojYn7qwVkDBF9qn1luMrM TjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjA6BgNVHR8EMzAxMC+g LaArhilodHRwOi8vY3JsLmdlb3RydXN0LmNvbS9jcmxzL3NlY3VyZWNhLmNybDBO BgNVHSAERzBFMEMGBFUdIAAwOzA5BggrBgEFBQcCARYtaHR0cHM6Ly93d3cuZ2Vv dHJ1c3QuY29tL3Jlc291cmNlcy9yZXBvc2l0b3J5MA0GCSqGSIb3DQEBBQUAA4GB AHbhEm5OSxYShjAGsoEIz/AIx8dxfmbuwu3UOx//8PDITtZDOLC5MH0Y0FWDomrL NhGc6Ehmo21/uBPUR/6LWlxz/K7ZGzIZOKuXNBSqltLroxwUCEm2u+WR74M26x1W b8ravHNjkOR/ez4iyz0H7V84dJzjA1BOoa+Y7mHyhD8S -----END CERTIFICATE----- --- Server certificate subject=/serialNumber=G7FkiJIImQR-ZrMucXArQ-1Lc5QBn9XP/OU=GT87906819/OU=See www.rapidssl.com/resources/cps (c)14/OU=Domain Control Validated - RapidSSL(R)/CN=*.office.mydomain.net issuer=/C=US/O=GeoTrust, Inc./CN=RapidSSL CA --- Acceptable client certificate CA names /C=CN/O=CNNIC/CN=CNNIC ROOT /C=FR/O=Dhimyotis/CN=Certigna /O=TeliaSonera/CN=TeliaSonera Root CA v1 /C=ES/O=IZENPE S.A./CN=Izenpe.com /C=FI/O=Sonera/CN=Sonera Class2 CA /O=RSA Security Inc/OU=RSA Security 2048 V3 /C=RO/O=certSIGN/OU=certSIGN ROOT CA /O=Cybertrust, Inc/CN=Cybertrust Global Root /C=US/O=GeoTrust, Inc./CN=RapidSSL CA /CN=ComSign Secured CA/O=ComSign/C=IL /CN=Atos TrustedRoot 2011/O=Atos/C=DE /C=FR/O=Certplus/CN=Class 2 Primary CA /C=PL/O=Unizeto Sp. z o.o./CN=Certum CA /C=TW/O=Government Root Certification Authority /O=Digital Signature Trust Co./CN=DST Root CA X3 /C=US/O=AffirmTrust/CN=AffirmTrust Premium /C=US/O=GeoTrust Inc./CN=GeoTrust Global CA /CN=ACCVRAIZ1/OU=PKIACCV/O=ACCV/C=ES /C=DK/O=TDC Internet/OU=TDC Internet Root CA /C=JP/O=Japanese Government/OU=ApplicationCA /C=US/O=AffirmTrust/CN=AffirmTrust Commercial /C=US/O=AffirmTrust/CN=AffirmTrust Networking /C=US/O=GeoTrust Inc./CN=GeoTrust Global CA 2 /CN=ACEDICOM Root/OU=PKI/O=EDICOM/C=ES /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 2 /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 3 /C=CH/O=SwissSign AG/CN=SwissSign Gold CA - G2 /C=GB/O=Trustis Limited/OU=Trustis FPS Root CA /C=US/O=AffirmTrust/CN=AffirmTrust Premium ECC /C=US/O=GeoTrust Inc./CN=GeoTrust Universal CA /C=CH/O=SwissSign AG/CN=SwissSign Silver CA - G2 /C=HK/O=Hongkong Post/CN=Hongkong Post Root CA 1 /C=US/O=GeoTrust Inc./CN=GeoTrust Universal CA 2 /C=US/O=SecureTrust Corporation/CN=SecureTrust CA /C=SK/L=Bratislava/O=Disig a.s./CN=CA Disig /C=US/O=SecureTrust Corporation/CN=Secure Global CA /C=NO/O=Buypass AS-983163327/CN=Buypass Class 2 CA 1 /C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 CA 1 /OU=GlobalSign Root CA - R2/O=GlobalSign/CN=GlobalSign /OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign /C=DE/O=D-Trust GmbH/CN=D-TRUST Root Class 3 CA 2 2009 /C=NO/O=Buypass AS-983163327/CN=Buypass Class 2 Root CA /C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 Root CA /C=US/O=Equifax/OU=Equifax Secure Certificate Authority /C=DE/O=D-Trust GmbH/CN=D-TRUST Root Class 3 CA 2 EV 2009 /C=JP/O=SECOM Trust.net/OU=Security Communication RootCA1 /C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068 /C=TW/O=TAIWAN-CA/