# HL7800: Does +KCERTSTORE support PEM certificate chains?

**URL:** <https://forum.sierrawireless.com/t/hl7800-does-kcertstore-support-pem-certificate-chains/35920>\
**Category:** HL78\
**Tags:** debug\
**Created:** [July 2, 2026, 7:01pm UTC](https://forum.sierrawireless.com/t/hl7800-does-kcertstore-support-pem-certificate-chains/35920 "2026-07-02T19:01:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexander.dingwall](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@alexander.dingwall](https://forum.sierrawireless.com/u/alexander.dingwall)\
**Post date:** [July 2, 2026, 7:01pm UTC](https://forum.sierrawireless.com/t/hl7800-does-kcertstore-support-pem-certificate-chains/35920/1 "2026-07-02T19:01:58Z")

</div>

I am trying to load a signed certificate containing two concatenated PEM certificates (leaf certificate plus intermediate) using `+KCERTSTORE` on an HL7800 running firmware 4.6.9.4.

The upload returns:

```auto
+CME ERROR: 930

```

The AT guide describes this as “Content of input data is invalid or not supported,” but I cannot find documentation stating whether multiple PEM certificates in one uploaded object are supported.

Does `+KCERTSTORE` require exactly one certificate per stored entry? For an mTLS client certificate chain, should the leaf and intermediate be uploaded separately, and if so, how does the modem associate the intermediate with the local client certificate during TLS negotiation?

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)\
**Post date:** [July 3, 2026, 1:16am UTC](https://forum.sierrawireless.com/t/hl7800-does-kcertstore-support-pem-certificate-chains/35920/2 "2026-07-03T01:16:02Z")

</div>

does it work if you separate the certificates and store them in different indexes?

 ![image](https://us1.discourse-cdn.com/flex025/uploads/sierrawireless/original/2X/a/ada158c1b61f494da579ee66101bb77c3d0e5eec.png)

Actually I think you can also skip the intermediate certificate and just load the leaf certificate.
