<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Couldn't find a valid ssl certificate with thumbprint and the incorrect certificate used on hub in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455</link>
    <description>&lt;P&gt;A valid certificate with a Private Key is installed (according to &lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to change certificate for the Proxy&lt;/A&gt;). However, the certificate does not get recognized by the Proxy and the error&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;Couldn't find a valid ssl certificate with thumbprint&lt;/EM&gt;&lt;/SPAN&gt;&amp;nbsp;is printed in the Proxy Security logs.&lt;BR /&gt;&lt;BR /&gt;The Certification Path for the certificate shows that the certificate is OK and the service account has full access to the private key and certificate store.&amp;nbsp;&lt;/P&gt;
&lt;H4 class="qlik-migrated-tkb-headings"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Cause&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;While the &lt;STRONG&gt;Qlik Sense certificates&lt;/STRONG&gt; are all stored in the correct certificate store, the relevant&amp;nbsp;&lt;STRONG&gt;CA&amp;nbsp;&lt;/STRONG&gt;(Certificate Authority) certificates may have been imported in the&amp;nbsp;&lt;STRONG&gt;Personal store&amp;nbsp;&lt;/STRONG&gt;rather than the&amp;nbsp;&lt;STRONG&gt;Trusted Root Certificate Authorities&amp;nbsp;&lt;/STRONG&gt;store.&lt;/P&gt;
&lt;H3 class="qlik-migrated-tkb-headings"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Verify that every single &lt;STRONG&gt;CA Authority&lt;/STRONG&gt; in the Certificates trust chain is correctly imported as a &lt;STRONG&gt;"Trusted Root Certificate Authorities"&lt;/STRONG&gt; certificate store. They may have been installed in the &lt;STRONG&gt;"Personal / Certificates"&lt;/STRONG&gt; store instead.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If, for example, you are using a COMODO RSA Certificate, the COMODO RSA Certificate Authority Root Cert must be in the Trusted Root Certificate Authorities store.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003t0N6&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1506949667000" border="0" alt="User-added image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Move the CA Root certificates to the correct folder and restart the Proxy service. If Certification Path is marked as not found after that, attempt re-importing the certificate while in the Personal store selecting the "automatic" placement of all certificates contained in the .pfx file.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Updates-Blog/Qlik-Sense-Hub-and-QMC-with-a-custom-SSL-certificate/ba-p/1608077" target="_blank" rel="noopener"&gt;Qlik Sense Hub and QMC with custom SSL certificate&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Compatibility-information-for-third-party-SSL/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Requirements-for-configuring-Qlik-Sense-with-SSL/ta-p/1715916" target="_blank" rel="noopener"&gt;Requirements for configuring Qlik Sense with SSL&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2024 15:13:01 GMT</pubDate>
    <dc:creator>Daniele_Purrone</dc:creator>
    <dc:date>2024-03-20T15:13:01Z</dc:date>
    <item>
      <title>Couldn't find a valid ssl certificate with thumbprint and the incorrect certificate used on hub</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455</link>
      <description>&lt;P&gt;A valid certificate with a Private Key is installed (according to &lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to change certificate for the Proxy&lt;/A&gt;). However, the certificate does not get recognized by the Proxy and the error&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;Couldn't find a valid ssl certificate with thumbprint&lt;/EM&gt;&lt;/SPAN&gt;&amp;nbsp;is printed in the Proxy Security logs.&lt;BR /&gt;&lt;BR /&gt;The Certification Path for the certificate shows that the certificate is OK and the service account has full access to the private key and certificate store.&amp;nbsp;&lt;/P&gt;
&lt;H4 class="qlik-migrated-tkb-headings"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Cause&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;While the &lt;STRONG&gt;Qlik Sense certificates&lt;/STRONG&gt; are all stored in the correct certificate store, the relevant&amp;nbsp;&lt;STRONG&gt;CA&amp;nbsp;&lt;/STRONG&gt;(Certificate Authority) certificates may have been imported in the&amp;nbsp;&lt;STRONG&gt;Personal store&amp;nbsp;&lt;/STRONG&gt;rather than the&amp;nbsp;&lt;STRONG&gt;Trusted Root Certificate Authorities&amp;nbsp;&lt;/STRONG&gt;store.&lt;/P&gt;
&lt;H3 class="qlik-migrated-tkb-headings"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Verify that every single &lt;STRONG&gt;CA Authority&lt;/STRONG&gt; in the Certificates trust chain is correctly imported as a &lt;STRONG&gt;"Trusted Root Certificate Authorities"&lt;/STRONG&gt; certificate store. They may have been installed in the &lt;STRONG&gt;"Personal / Certificates"&lt;/STRONG&gt; store instead.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If, for example, you are using a COMODO RSA Certificate, the COMODO RSA Certificate Authority Root Cert must be in the Trusted Root Certificate Authorities store.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://qlik.my.salesforce.com/servlet/servlet.ImageServer?id=015D0000003t0N6&amp;amp;oid=00D20000000IGPX&amp;amp;lastMod=1506949667000" border="0" alt="User-added image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Move the CA Root certificates to the correct folder and restart the Proxy service. If Certification Path is marked as not found after that, attempt re-importing the certificate while in the Personal store selecting the "automatic" placement of all certificates contained in the .pfx file.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Related Content:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Updates-Blog/Qlik-Sense-Hub-and-QMC-with-a-custom-SSL-certificate/ba-p/1608077" target="_blank" rel="noopener"&gt;Qlik Sense Hub and QMC with custom SSL certificate&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Change-the-certificate-used-by-the-Qlik-Sense-Proxy-to-a/ta-p/1712773" target="_blank" rel="noopener"&gt;How to: Change the certificate used by the Qlik Sense Proxy to a custom third party certificate&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/ERR-CERT-COMMON-NAME-INVALID-when-using-3rd-party-certificate/ta-p/1715606" target="_blank" rel="noopener"&gt;ERR_CERT_COMMON_NAME_INVALID when using 3rd party certificate&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Compatibility-information-for-third-party-SSL/ta-p/1715975" target="_blank" rel="noopener"&gt;Qlik Sense: Compatibility information for third-party SSL certificates to use with HUB/QMC&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Requirements-for-configuring-Qlik-Sense-with-SSL/ta-p/1715916" target="_blank" rel="noopener"&gt;Requirements for configuring Qlik Sense with SSL&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 15:13:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Couldn-t-find-a-valid-ssl-certificate-with-thumbprint-and-the/ta-p/1715455</guid>
      <dc:creator>Daniele_Purrone</dc:creator>
      <dc:date>2024-03-20T15:13:01Z</dc:date>
    </item>
  </channel>
</rss>

