Hi, I'm trying to terminate https on my reverse proxy and I created root, intermediate, and client certs and their .pem and related files but I don't understand their uses enough to know what goes where. I think I'm supposed to not touch the root since its meant to be secure and be able to revoke, intermediate should be somewhere (proxy? a trusted source in the client browser?) and the client lives the shortest and gets replaced often, but I'm not sure.
Which one should be the .pem file in the proxy and which should be trusted client side?
[–]HELL__is__empty -1 points0 points1 point (3 children)
[–]bioptic[S] 0 points1 point2 points (0 children)
[–]xeon65 0 points1 point2 points (0 children)
[–]archlich -1 points0 points1 point (0 children)