certification authority

Posted on 2004-04-13
Last Modified: 2012-05-04
I am having an issue with my server certificate, I installed CA service so that I can make and issue my server certificate.  I followed the instructions as per Microsoft’s website and all seems well from the server at least

Now when I have another box (not the server) connects to my web site: example: They get a “Security Alert” no problem there I guess.
It has a message that says:
“The server certificate was issues by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.”

Then at the end when it asks me if I want to proceed I have the options of ‘yes’, ‘no’, ‘view certificate’

When viewing the certificate in the General Tab it reads:
This certificate cannot be verified up to a trusted certification authority.
In the Certification Path is says all is OK.

I don’t know why this is happening because my server that also has the web server on it is the “certification authority”.

Also even when I install the certificate and revisit the site I get that pop up prompt

So… to make a long story short, I need some help (hand holding  ... walk through type of help).

I need to get this working in less than 8 hrs.
Question by:weguardyou
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2

Expert Comment

ID: 10818701
The problem you are having is the CA itself is not trusted by the web browser. What you have at the moment is a self-signing certificate. Basically, you are telling the web browser to trust you because you trust yourself. For solutions, look at the question below.

Author Comment

ID: 10818885
Well that doesnt do it for me.  you see even when i test with my remote clients and install my certificate into their browser manually.
When i close out and revisit the site.  The same thig happens.  I get that pop/up again.

Expert Comment

ID: 10819223
Can you check something for me? After you install the certificate, double click on the lock icon and tell me what you find in the Certification Path. Also select the root entry and click on view certificate and what you have showing under the general tab.
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

LVL 23

Accepted Solution

Tim Holman earned 500 total points
ID: 10822232
>When viewing the certificate in the General Tab it reads:
>This certificate cannot be verified up to a trusted certification authority.
>In the Certification Path is says all is OK.

This means that your certificate isn't trusted by any of the authorities that appear under this section of the web browser:

Tools > Internet Options > Content > Certificates

..this is normal behaviour, as your self-signed certificate has not been approved by higher sentient beings yet.  As soon as you get a proper server certificate from somewhere like Verisign, this will continue to be an issue.
Nonetheless, your SSL session is still safe and encrypted as long as you don't go giving away your keys to anyone !


Author Comment

ID: 10822922
Yes, I understand that now.  But my thing is this:  Even when a person on a remote system installs the certificate to their browser. And later on revisit the site, they again receive that message popup.  Is that normal?  In my thinking I was under the impression that it would no longer pop up that message.
LVL 23

Expert Comment

by:Tim Holman
ID: 10823523
Yes, this is normal.
I believe you can change this default behaviour by altering IE advanced settings, but then this isn't what 'the masses' should be expected to do just to be able to view your website, so again your forced down the valid, trusted certificate route...

IE > Tools > Internet Options > Advanced - 'warn about invalid site certificates'

Expert Comment

ID: 10938488
One solution is to get a cert from a root authority, this should allow you to give out certificates under your name to others and they will be valid due to a trust relationship.
LVL 23

Expert Comment

by:Tim Holman
ID: 10939206
Any reason this last comment was accepted as an answer ??  

Expert Comment

ID: 13167573
It's funny that the FireFox browser will install the certifiicate and will not prompt you again upon returning to the site while IE forces you to click "yes".  They don't even give you the opportunity to add the CA as a trusted source.  I guess I will have to spend a little dough.

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Ever wonder what it's like to get hit by ransomware? "Tom" gives you all the dirty details first-hand – and conveys the hard lessons his company learned in the aftermath.
Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question