Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


IE7's problem with self signed certs

Posted on 2008-10-29
Medium Priority
Last Modified: 2013-12-08
Accessing OWA via SSL on a SBS03 server w/SP2 and all current updates IE7 displays the "...problem with this site's certificate..." message.  The PC is XP Pro /SP3.  On the PC installing the cert into the Trusted Root Certificate Authority location makes no difference.  Of course it work flawlessly with IE6.  Anyone know what the fix for IE7 is assuming there is one.
Question by:johncfds
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2

Expert Comment

ID: 22836981
The only fix I am aware of for this issue is to use a certificate signed by a certificate authority (even if it is via Certificate Services in Windows 2003).

Once you have the Root CA certificate installed to the trusted root certificates, you will be able to open OWA without getting the certificate warning.

If you do not want to buy a commercial certificate, or run your own CA, there are providers out there offering free certificates, in which case you could get a certificate from them and import their Root CA certificate as a Trusted Root Certificate.

Try as an example.

Author Comment

ID: 22845322
Had a look at  I am considering it.  Does anyone know if IE8 beta behaves differently?

Expert Comment

ID: 22857637
your problem comes from the fact that IE 7 is looking to verify the self signed certificate against a root certificate which is not installed on the machine.
To solve this install both the self signed certificate and the root certificate on the workstations.

when you installed your certification authority (i'm going to assume windows based) it generates it's own root certificate. It's the same as going through a free certification authority but you have already done the work to get those certs setup.
Learn how to optimize MySQL for your business need

With the increasing importance of apps & networks in both business & personal interconnections, perfor. has become one of the key metrics of successful communication. This ebook is a hands-on business-case-driven guide to understanding MySQL query parameter tuning & database perf


Author Comment

ID: 22862063
From within IE7 I have clicked "Certificate Error" "View Certificate" "Install Certificate" and installed it to Trusted Root Certificate Authorities with no change. Which of the two cert installs you say must be done is this and how / where do I do the second?
Thank You,

Expert Comment

ID: 22862160
here is a guide to importing Root CA certificates into e-mail clients.
While this is not exactly the guide you need it will give you the proper steps for exporting the Root Cert.

The certificate you installed if the Web site certificate, If you go into that certificate and check it's certification path you will see that it has another certificate on top of it, that is your Root cert, and the one the guide i linked you will help you get.

Expert Comment

ID: 22863752
Assuming you are using a self-signed certificate, the instructions curwengroup has linked to will never work because IE7 needs a root CA certificate in order to verify the authenticity of the server/website certificate.

I believe this was intended design in IE7 so I doubt that IE8 will go back to the way IE6 behaves.  

Expert Comment

ID: 22863802
The linked instructions were not a step by steps of what needs to be done to accomplish this. it only points him in the direction he needs to look to be able to retrieve his self signed root CA certificate, and install it on client machine, to get them to accept the web certificate.

Accepted Solution

Onlyodin earned 500 total points
ID: 22863872
Yes, but if it is a Self-Signed certificate there will be no Root CA Certificate.  Your instructions are good however only applicable if johncfds was running an internal Certificate Authority.  

In my experience IE7 will not acknowledge a Self-Signed certificate even if it is installed as Trusted Root Certificate.

Assisted Solution

curwengroup earned 500 total points
ID: 22864030
In my experience you need some sort of a certification authority to issue the certificate. I have always done it by installing the Windows Certificate Authority on a server and issuing a web certificate, judging by  johncfds description that is what he did.

in my experience IE7 will always recognize the certs if the machine is part of the domain that the CA is issuing Certs for, it will also always recognize the certs if they are installed in the proper order, ie Root Cert first, web site Cert second. Otherwise it's a draw between update level for OS and update status for IE.

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
In threads here at EE, each comment has a unique Identifier (ID). It is easy to get the full path for an ID via the right-click context menu. However, we often want to post a short link within a thread rather than the full link. This article shows a…
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question