Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Reducing the size of certificate chain

Posted on 2016-10-05
2
Medium Priority
?
212 Views
Last Modified: 2016-10-14
HI,
Following is a capture of wireshark :
 Screen-Shot-2016-10-05-at-5.22.43-PM.pngHere there are 3 certificates and the size is : 4310 bytes
Here are the certificates as i see in chrome :

Screen-Shot-2016-10-05-at-5.22.54-PM.png
I read up the following rule for optimization of certificates :
Ideally, your sent certificate chain should contain exactly two certificates and A carefully managed certificate chain can be as low as 2 or 3 KB in size

But the certificate chain for my site exceeds 4 KB.
Please suggest any approach to lower this down.. I think i will have to somehow get away with the intermediate certificate..

Thanks
0
Comment
Question by:Rohit Bajaj
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 14

Assisted Solution

by:Schnell Solutions
Schnell Solutions earned 600 total points
ID: 41829973
If that is the chain of one specific certificate you cannot change it. What you can do is to use a 'different' certificate that uses a shorter chain. However, it means re-issue a new certificate and complete the entire process to implement the new one.

On another hand you will not wish to set one intermediate certificate as a root ca to shorten the path in your server as far as it would be a very bad security practice.
0
 
LVL 24

Accepted Solution

by:
Dirk Kotte earned 1400 total points
ID: 41830172
your book are from 2013. Last years we double the certificate length and nearly every CA add some sub-CAs.
The statement: "which will overflow the initial congestion windows size of older servers ..." is not current.

Using a certificate with fewer intermediate chains and / or a smaller public key size can reduce the amount of data but is not an option today ...mostly...
0

Featured Post

Introducing the WatchGuard 420 Access Point

WatchGuard's newest access point includes an 802.11ac Wave 2 chipset, providing the fastest speeds for VoIP, video and music streaming, and large data file transfers. Additionally, enjoy the benefits of strong security as the 3rd radio delivers dedicated WIPS protection!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question