Solved

This CA root certificate is not trusted. to enable trust, install this certificate in the trusted root certification authorities store.

Posted on 2011-09-19
9
28,081 Views
Last Modified: 2016-08-31
I was able to renew a self signing certificate on Exchange 2007 using the console, but I cannot make it trusted. The Exchange box is part of a domain, but the DC doesn't have SSL enabled so I'm working on the exchange box only. How do I add this cert to the trusted root cert authorities store?
0
Comment
Question by:fnillc
9 Comments
 
LVL 16

Expert Comment

by:jessc7
ID: 36563772
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 36563926
are you trying to install a certificate from public CA ? or internal CA ? if public, no need for more config just install it.
0
 

Author Comment

by:fnillc
ID: 36564110
I need to add the cert to the trusted root CA on the exchange server itself, not a workstation. I renewed the cert using the Exchange Management Shell on the Exchange box via "Get-ExchangeCertificate -thumbprint "xxx" New-Exchangecertificate". I'm getting the "install this certificate in the trusted root certification authorities store" in the IIS Manager - Default Web Site Properties - View Certificate.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 16

Expert Comment

by:jessc7
ID: 36564174
Manage Trusted Root Certificates (Windows 7, Windows Server 2008 R2)http://technet.microsoft.com/en-us/library/cc754841.aspx
0
 
LVL 16

Expert Comment

by:jessc7
ID: 36564177
Diregard the previous link. It wasn't what I thought - sorry.
0
 
LVL 8

Accepted Solution

by:
Shmoid earned 500 total points
ID: 36564802
Just copy it from the installed location to the trusted root store.

To do so:

Launch MMC.
Add Certificates Snap-in for Local Computer.
Expand Certificates (Local Computer)
Expand Personal
Click Certificates folder
Right click on the self-signed cert and choose copy
Expand Trusted Root Certification Authorities
Right click Certificates folder (under Trusted Root...) and select Paste.
You will be prompted with a security warning. Verify the cert listed is the self-signed cert and click yes.
0
 

Author Comment

by:fnillc
ID: 36569480
Thanks Shmoid! your sugestion fix it.
0
 
LVL 1

Expert Comment

by:Versatile450
ID: 40851391
What happens if I run that command and I get prompted to insert a smartcard?..
0
 

Expert Comment

by:Jason Jason
ID: 41779062
Thank you so much Shmoid! You just saved my hide.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question