Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

This CA root certificate is not trusted. to enable trust, install this certificate in the trusted root certification authorities store.

Posted on 2011-09-19
9
Medium Priority
?
35,145 Views
Last Modified: 2016-08-31
I was able to renew a self signing certificate on Exchange 2007 using the console, but I cannot make it trusted. The Exchange box is part of a domain, but the DC doesn't have SSL enabled so I'm working on the exchange box only. How do I add this cert to the trusted root cert authorities store?
0
Comment
Question by:fnillc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 16

Expert Comment

by:jessc7
ID: 36563772
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 36563926
are you trying to install a certificate from public CA ? or internal CA ? if public, no need for more config just install it.
0
 

Author Comment

by:fnillc
ID: 36564110
I need to add the cert to the trusted root CA on the exchange server itself, not a workstation. I renewed the cert using the Exchange Management Shell on the Exchange box via "Get-ExchangeCertificate -thumbprint "xxx" New-Exchangecertificate". I'm getting the "install this certificate in the trusted root certification authorities store" in the IIS Manager - Default Web Site Properties - View Certificate.
0
Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

 
LVL 16

Expert Comment

by:jessc7
ID: 36564174
Manage Trusted Root Certificates (Windows 7, Windows Server 2008 R2)http://technet.microsoft.com/en-us/library/cc754841.aspx
0
 
LVL 16

Expert Comment

by:jessc7
ID: 36564177
Diregard the previous link. It wasn't what I thought - sorry.
0
 
LVL 8

Accepted Solution

by:
Shmoid earned 2000 total points
ID: 36564802
Just copy it from the installed location to the trusted root store.

To do so:

Launch MMC.
Add Certificates Snap-in for Local Computer.
Expand Certificates (Local Computer)
Expand Personal
Click Certificates folder
Right click on the self-signed cert and choose copy
Expand Trusted Root Certification Authorities
Right click Certificates folder (under Trusted Root...) and select Paste.
You will be prompted with a security warning. Verify the cert listed is the self-signed cert and click yes.
0
 

Author Comment

by:fnillc
ID: 36569480
Thanks Shmoid! your sugestion fix it.
0
 
LVL 1

Expert Comment

by:Versatile450
ID: 40851391
What happens if I run that command and I get prompted to insert a smartcard?..
0
 

Expert Comment

by:Jason Jason
ID: 41779062
Thank you so much Shmoid! You just saved my hide.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
Are you an Exchange administrator employed with an organization? And, have you encountered a corrupt Exchange database due to which you are not able to open its EDB file. This article will explain all the steps to repair corrupt Exchange database.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question