Skip to content

Commit e8e11d5

Browse files
[CF1] signing cert clarification
1 parent f76f1d7 commit e8e11d5

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

src/content/docs/cloudflare-one/identity/devices/warp-client-checks/client-certificate.mdx

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,15 @@ The Client Certificate device posture attribute checks if the device has a valid
3030
## Prerequisites
3131

3232
- A CA that issues client certificates for your devices. WARP does not evaluate the certificate trust chain; this needs to be the issuing certificate.
33+
34+
:::caution[Upload the signing certificate that directly issued the client certificate]
35+
36+
When uploading a certificate to use in posture checks, Cloudflare does not differentiate between root and intermediate certificates. You must upload the actual signing certificate – the one that directly signed the client certificate.
37+
38+
The signing certificate might be an intermediate CA, not the root CA. If you upload the wrong certificate (for example, a root that did not sign the client cert), the posture check will fail.
39+
40+
:::
41+
3342
- Cloudflare WARP client is [deployed](/cloudflare-one/connections/connect-devices/warp/deployment/) on the device.
3443
- A client certificate is [installed and trusted](#configure-the-client-certificate-check) on the device.
3544

0 commit comments

Comments
 (0)