Solved

policy or certification issue maybe?

Posted on 2011-03-18
7
1,481 Views
Last Modified: 2013-11-25
When trying to install a custom VB application on an XP machine, the following message is given

Application Install – Security Warning
Your administrator has blocked this application because it potentially poses a security risk to your computer.
Name:  xxxxxxxxxxx
From: D:\ xxxxxxxxxxxx

Publisher:  Unknown Publisher
 
Your security settings do not allow this application to be installed on computer.

(I replaced the app's name and location)

The user has admin rights on the laptop. I believe this miight be happening if a group policy
was set on the laptop, or if XP is just having issues with the certification of the software.

Any advise?
0
Comment
Question by:BJBExEx
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 22

Expert Comment

by:plusone3055
ID: 35169813
if this is happening at a work station the IT boys desabled some features..
0
 

Author Comment

by:BJBExEx
ID: 35169875
Thanks for your reply,

I think that might be right, but it's the IT guy having the issue with the software (at a remote location). I can't get my hand on the laptop, but the error message in my original note is the exact error message. I believe this must be an item in the security policy (local or group) that needs to be adjusted, but I'm just not sure what. I am also not certain if group policy is active or not. I am trying to find out more. It is important for us to try and get this operational rather quickly. The app does not have a certification, it is seen as being from an unknown publisher. What I am looking for is the policy setting that would allow an application from an "unknown" publisher to be installed. The app was developed by a co-worker, so we know there is no security issue with it. It works fine on the XP PC it was written and compiled on.
0
 
LVL 7

Expert Comment

by:CSI-Windows
ID: 35169930
Could you please share the following details:

What is the operating system?

Is the application being installed via Windows Installer, Click Once, Setup.exe ?

If Windows Installer is being used, please run the attached MSI-Verbose-Logging-ON.REG file to generate a verbose log of the next attempt and attached it to a reply message.
MSI-Verbose-Logging-ON.reg
MSI-Verbose-Logging-OFF.reg
0
Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

 

Author Comment

by:BJBExEx
ID: 35169961
Thanks for your reply.

The laptop is running XP Pro, I believe SP2. Windows Installer was used. Thanks for the links, Unfortunately, the laptop is accross the counrty from me so I can't try it now. I'm sending the links to the app developer to ask him to speak to the user to try the links. I will reply with the requested info when available.
0
 
LVL 7

Accepted Solution

by:
CSI-Windows earned 250 total points
ID: 35171311
Great.

Couple other questions:

Is the attempted install being done through a web browser?

Is the application a .NET application?

Is the D:\ drive a local drive or a network mapped drive?

This is a classic policy message, but there is no Windows Installer specific group policy that would block an install based on code signing.

It would have to be one of these:
*) GPO: Software Restriction Policy - Certificate Rule
*) Web Browser Security (if being installed via browser)
*) GPO: App Locker Policy (Win7 Enterprise ONLY)
*) .NET ClickOnce Security policies

Given the message you are receiving the last seems like a real possibility.

Assuming the App is .NET I would advise that you check whether you are including a ClickOnce manifest when building the App.  Maybe at one time someone thought they'd use click once and changed these settings and now it gets embedded in the MSI and is being processed?

Here is an article that explains some of the GPO settings and Visual Studio settings that might be affecting you: http://msdn.microsoft.com/en-us/library/aa719097(v=vs.71).aspx#clickonce_topic8
0
 
LVL 40

Expert Comment

by:Vadim Rapp
ID: 35775467
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, you will read about the trends across the human resources departments for the upcoming year. Some of them include improving employee experience, adopting new technologies, using HR software to its full extent, and integrating artifi…
With User Account Control (UAC) enabled in Windows 7, one needs to open an elevated Command Prompt in order to run scripts under administrative privileges. Although the elevated Command Prompt accomplishes the task, the question How to run as script…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…
Introduction to Processes

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question