Solved

certification authority

Posted on 2004-04-13
9
28,814 Views
Last Modified: 2012-05-04
I am having an issue with my server certificate, I installed CA service so that I can make and issue my server certificate.  I followed the instructions as per Microsoft’s website and all seems well from the server at least

Now when I have another box (not the server) connects to my web site: example: http://whatever.domain.com/. They get a “Security Alert” no problem there I guess.
It has a message that says:
“The server certificate was issues by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.”

Then at the end when it asks me if I want to proceed I have the options of ‘yes’, ‘no’, ‘view certificate’

When viewing the certificate in the General Tab it reads:
This certificate cannot be verified up to a trusted certification authority.
In the Certification Path is says all is OK.

I don’t know why this is happening because my server that also has the web server on it is the “certification authority”.

Also even when I install the certificate and revisit the site I get that pop up prompt

So… to make a long story short, I need some help (hand holding  ... walk through type of help).

I need to get this working in less than 8 hrs.
0
Comment
Question by:weguardyou
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 2

Expert Comment

by:JaniceLaw
ID: 10818701
The problem you are having is the CA itself is not trusted by the web browser. What you have at the moment is a self-signing certificate. Basically, you are telling the web browser to trust you because you trust yourself. For solutions, look at the question below.

http://www.experts-exchange.com/Networking/Q_20950930.html
0
 
LVL 1

Author Comment

by:weguardyou
ID: 10818885
Well that doesnt do it for me.  you see even when i test with my remote clients and install my certificate into their browser manually.
When i close out and revisit the site.  The same thig happens.  I get that pop/up again.
0
 
LVL 2

Expert Comment

by:JaniceLaw
ID: 10819223
Can you check something for me? After you install the certificate, double click on the lock icon and tell me what you find in the Certification Path. Also select the root entry and click on view certificate and what you have showing under the general tab.
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 23

Accepted Solution

by:
Tim Holman earned 500 total points
ID: 10822232
>When viewing the certificate in the General Tab it reads:
>This certificate cannot be verified up to a trusted certification authority.
>In the Certification Path is says all is OK.

This means that your certificate isn't trusted by any of the authorities that appear under this section of the web browser:

Tools > Internet Options > Content > Certificates

..this is normal behaviour, as your self-signed certificate has not been approved by higher sentient beings yet.  As soon as you get a proper server certificate from somewhere like Verisign, this will continue to be an issue.
Nonetheless, your SSL session is still safe and encrypted as long as you don't go giving away your keys to anyone !


0
 
LVL 1

Author Comment

by:weguardyou
ID: 10822922
Yes, I understand that now.  But my thing is this:  Even when a person on a remote system installs the certificate to their browser. And later on revisit the site, they again receive that message popup.  Is that normal?  In my thinking I was under the impression that it would no longer pop up that message.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10823523
Yes, this is normal.
I believe you can change this default behaviour by altering IE advanced settings, but then this isn't what 'the masses' should be expected to do just to be able to view your website, so again your forced down the valid, trusted certificate route...

IE > Tools > Internet Options > Advanced - 'warn about invalid site certificates'
0
 
LVL 3

Expert Comment

by:jermsmit
ID: 10938488
One solution is to get a cert from a root authority, this should allow you to give out certificates under your name to others and they will be valid due to a trust relationship.
 
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10939206
Any reason this last comment was accepted as an answer ??  
0
 

Expert Comment

by:huntermis
ID: 13167573
It's funny that the FireFox browser will install the certifiicate and will not prompt you again upon returning to the site while IE forces you to click "yes".  They don't even give you the opportunity to add the CA as a trusted source.  I guess I will have to spend a little dough.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

As cyber crime continues to grow in both numbers and sophistication, a troubling trend of optimization has emerged over the last year.
Ransomware continues to grow in reach and sophistication, putting data everywhere at risk. Learn how to avoid being caught in its sinister clutches with these 11 key tips.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question