SSL not trusted

SSL not trusted

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SSL not trusted Muson 08-27-2007
Posted by Muson on August 27, 2007, 3:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I created 2 tier CA infrastructure - ofline root CA, and domain joined
subordinate CA. I created certificate and installed it on web server. When
someone visits our page, gets message that certificate is not trusted, if i
try to install certificate on the client in IE, it finishes with success
message. But next time when i visit same site, server certificate still not
trusted, if i install root CA certificate on client, then it is ok.

The Question - How i can create certificate that could be trusted simple by
installing web servers certificate and will that certificate work with
mobile devices (ActiveSync).

--
Muson


Posted by S. Pidgorny on August 27, 2007, 6:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
All clients should trust the root. This is one of PKI desogn guiding
principles.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hello,
>
> I created 2 tier CA infrastructure - ofline root CA, and domain joined
> subordinate CA. I created certificate and installed it on web server. When
> someone visits our page, gets message that certificate is not trusted, if
> i try to install certificate on the client in IE, it finishes with success
> message. But next time when i visit same site, server certificate still
> not trusted, if i install root CA certificate on client, then it is ok.
>
> The Question - How i can create certificate that could be trusted simple
> by installing web servers certificate and will that certificate work with
> mobile devices (ActiveSync).
>
> --
> Muson



Posted by Muson on August 27, 2007, 7:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Then following question

I would like to import rootca certificate on client when visiting site, but
i don't see certificate hierarchy, to import (trust) root ca, i see only
target server certificate. So i have to export root ca certificate, copy it
to client machine and import it.

By the way, how self-signed certificate works..

--
Muson

> All clients should trust the root. This is one of PKI desogn guiding
> principles.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>> Hello,
>>
>> I created 2 tier CA infrastructure - ofline root CA, and domain joined
>> subordinate CA. I created certificate and installed it on web server.
>> When someone visits our page, gets message that certificate is not
>> trusted, if i try to install certificate on the client in IE, it finishes
>> with success message. But next time when i visit same site, server
>> certificate still not trusted, if i install root CA certificate on
>> client, then it is ok.
>>
>> The Question - How i can create certificate that could be trusted simple
>> by installing web servers certificate and will that certificate work with
>> mobile devices (ActiveSync).
>>
>> --
>> Muson
>
>


Similar ThreadsPosted
shutting down a trusted CA and raising a new trusted CA July 14, 2005, 1:32 pm
trusted ip address August 7, 2005, 10:23 am
Re: Can Microsoft be trusted? October 4, 2005, 3:06 am
Re: Can Microsoft be trusted? October 4, 2005, 7:15 am
Re: Can Microsoft be trusted? October 5, 2005, 12:02 pm
How to add certificates to the "Trusted Publishers" ? March 28, 2007, 5:19 pm
Updating Trusted Root CA May 6, 2008, 4:31 pm
Can we default to a trusted domain in IIS prompt? December 27, 2005, 1:11 pm
Trusting Certs from Non Trusted root March 23, 2007, 6:38 pm
List of trusted authorities - invalid? November 4, 2008, 11:13 am

The site map in XML format XML site map

Contact Us | Privacy Policy