+
+ # print chain
+ if [ -n "${PARAM_FULL_CHAIN:-}" ]; then
+ # get and convert ca cert
+ chainfile="$(_mktemp)"
+ http_request get "$(openssl x509 -in "${certfile}" -noout -text | grep 'CA Issuers - URI:' | cut -d':' -f2-)" > "${chainfile}"
+
+ if ! grep -q "BEGIN CERTIFICATE" "${chainfile}"; then
+ openssl x509 -inform DER -in "${chainfile}" -outform PEM -out "${chainfile}"
+ fi
+
+ echo "# CHAIN #" >&3
+ cat "${chainfile}" >&3
+
+ rm "${chainfile}"
+ fi