I have a X.509 certificate mycert.pem and a private-key mykey.pem for it.
Furthermore the certificate has a root-certificate and a intermediate-certificate to build a complete chain.
I had to add both the root-cert root.pem and the interm-cert interm.pem to /etc/ssl/certs with the correkt hash-link to make openssl verify the certificate OK.
mycert.pem: OK
Now I try to use openssl s_client.
I get an error at the server-side because I have set -key and also -cert but not -CAfile.
openssl s_client -connect my.host.org:433 -cert mycert.pem -key mykey.pem
I am not sure about that. How can I create the file for -CAfile?
I tried to set -CApath /etc/ssl/certs instead of -CAfile, but did not help.
