Solved

certificate is expired or not yet valid

Posted on 2006-07-18
9
2,694 Views
Last Modified: 2010-08-05
Hello,

platform:  Win2K/SP4, IIS 5 (yea that could be the problem right there).

my web server seems to have a random problem with its Verisign SSL cert (as complained to from users trying to establish the socket).  On the server, the cert is valid and properly registered.  some users complain that through their browser connection, they receive an Info window on the SSL cert that says "The certificate is expired or not yet valid".  the cert is registered to the host and doesn't expire until next year.  however, apparently within the cert (when viewed on a machine that experiences this problem) under the Certification Path tab, it displays a problem with Common Name.

Being new to the organization, I am still trying to find account info for Verisign, as one of my thoughts was to ask for a reissue.  another thought is to forgo the next year of validation, and buy a new cert now.  I haven't found any consistent path to recreating this error/problem.  

as the site that the cert is used for is financial and personal data, this is an extremely important post for me.

thanks in advance.  I hope I have illustrated the problem correctly.
0
Comment
Question by:Moabrocks
  • 4
  • 3
  • 2
9 Comments
 
LVL 9

Expert Comment

by:blandyuk
ID: 17134425
When you issue a certificate, the "Issue To" name has to be the same as the domain it's on. Example:

https://secure.mysite.com/

Issuing it to www.mysite.com will generate a common name problem. I've had this issue before with free certificates from:

www.cacert.org

I fixed it in the end and it worked fine. You could use CACert to get your SSL certificates right and then get one from Verisign once you know how to do it.

I would have thought you could issue a wildcard on your domain from Verisign but I don't know. Would be handy to know.
0
 
LVL 9

Expert Comment

by:blandyuk
ID: 17134429
Sorry, wildcard as in on your sub-domain:

*.mysite.com

Not the whole domain ;)
0
 
LVL 77

Expert Comment

by:arnold
ID: 17136045
Post the URL and will be in a better position to assist you.

Is there something common to those who exprience this problem like the browser/browser version/OS?
0
 

Author Comment

by:Moabrocks
ID: 17139523
we are trying to get users to give us all that info on their browsers, however we have now seen this inhouse..  XP/IE 6x (patched)..  what we see is a red X on the Verisign cert line with the status window that says the Verisign cert is "expired or not yet valid" but our cert shows no red X on the icon, and the status window shows "this certificate is ok".

Is there a way to upload a bitmap/jpeg thru experts-???

0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 77

Expert Comment

by:arnold
ID: 17141999
You can capture the image and place it on a site to which you post the URL.
on the inhouse systems that have the red X, look through the certificate path and see the expiration and information for the certificate that breaks the chain.  Then compare that information to the certificate path on the system that does not have this issue.

What is the issue with the certification path on the systems that has this problem?
0
 

Author Comment

by:Moabrocks
ID: 17142139
the difference between them that I see is that a client machine seeing the error, has a problem seeing "Verisigns" certificate as valid, in fact when you drill down to "view certificate", it shows it expired 1/7/2004.  

This now seems more clear that Verisign Tech support is needed?!!  Is there a way for a client machine to clear old certificates?

how do I paste screen shots to Experts-exchange?
0
 
LVL 9

Expert Comment

by:blandyuk
ID: 17144828
As arnold said, save the screenshot as a jpeg and upload to a location on your website / webserver and post the URL in here.
0
 
LVL 77

Assisted Solution

by:arnold
arnold earned 500 total points
ID: 17145237
On the systems where the error exist you need to update the root certificates.  verisign has issued an intermediary certificate that should correct this problem.  I think this is the class three certificate.  Check out verisign's web site for the applicable certificate and have those individuals import the certificate on their systems..
0
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 17145248
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Three simple tips to quickly and efficiently back up and protect the contents of your PC and Mac®.
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
A simple description of email encryption using a secure portal service. This is one of the choices offered by The Email Laundry for email encryption. The other choices are pdf encryption which creates an encrypted pdf of your email and any attachmen…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now