44.1 Resolving a -1226 PKI Error

When you create a certificate signing request, send it to a third-party issuer to be signed, and receive the server certificate from the third-party issuer, you sometimes receive a -1226 error when you try to import the signed certificate. You receive this error when the issuer does not sent back the trusted roots required to validate the issuer of the server certificate.

Use one of the following options to resolve this issue:

44.1.1 Using Internet Explorer to Add a Trusted Root Chain

The following procedure only works when Internet Explorer contains the trusted root certificate of the issuer of your certificate.

  1. In Internet Explorer, click Tools > Internet Options > Content > Certificates.

  2. Click Import and import your server certificate into the Other People tab.

  3. Click Other People, then double click on your certificate.

  4. Click Certification Path.

    • If the Certification Path shows that the certificate is OK, you now have the full certificate chain available for export. Click OK, then continue with Step 5.

    • If the Certification Path is not OK, you cannot use this method. Click OK, then contact your issuer for the certificate chain.

  5. Select the certificate, then click Export > Next.

  6. Select Cryptographic Message Syntax Standard - PKCS #7 Certificates (.P7B) as the format and select Include all certificates in the certification path if possible to include the certificate chain.

  7. Click Next, then specify a filename and path for the file.

  8. Click Next > Finish.

  9. Use this P7B file to import your server certificate into Access Manager.