GSKit certificate error

If the GSKit fails with an error when you try to import a signer or personal certificate, follow the steps to troubleshoot and resolve this error.

When you import a signer or personal certificate from an external certificate authority (CA) such as Entrust, the GSKit might fail with the following error:
An error occurred while receiving the certificate from the given file. 
The problem might occur because certificate returned from Entrust is a chain certificate, not a root certificate. You must have a root certificate to start a certificate chain. A chain certificate cannot start a certificate chain.

If you do not already have a root certificate, the following method is one way to obtain the root certificate.

An example of a root certificate is GTE Cybertrust, which is included in Internet Explorer (IE). However, it is not included by default in the GSKit kdb database. To obtain this certificate, you must do the following steps:

  1. Export one of the GTE Cybertrust certificates (there are 3) from Internet Explorer as Base64 encoded.
  2. Add the certificate as a trusted root certificate.
    Note: To use the GSKit option to set a certificate as a trusted root, the certificate must be self-signed.
  3. Add the chain CA certificate from Entrust.
  4. Receive the SSL certificate from Entrust.