• caglararli@hotmail.com
  • 05386281520

G4 cert using G2 intermediary cert

Çağlar Arlı      -    18 Views

G4 cert using G2 intermediary cert

I have an issue where I have an iOS app which is pinned to a root certificate of GlobalSign which is due to expire early February. This is their G2 root AlphaSSL cert.

We currently have a site certificate coming off of it which is due to expire on January 1st (10 days away) we have renewed the certificate and because its less than 6 month from the root expiry its been issued against the G4 root certificate.

If I update the site with the new cert with both the G4 issues site cert and G4 root cert the iOS app fails to work as the pinning is invalid. I have tried creating a PEM with the G4 site cert and G2 root cert but this fails for reasons I can't quite understand.

My question is am I barking up the wrong tree here is there a fundamental reason that the G4 issues site cert will not work with the G2 root cert until its expiry in Feb?

I had created the PEM as

SiteCert RootCert Key