Solved

Detect ssl warning message

Posted on 2012-12-20
3
253 Views
Last Modified: 2012-12-31
I work for a company that ships data storage appliances with a GUI web application and several rest API services that the GUI web app talks to through SSL. Because each customer has a different domain, the SSL warning comes up in the browser. So the customer has to hit each rest API service first, click OK for the SSL warning, and only then will the entire application work. My question is if there is some way to facilitate this process where if the customer hits the front end web app first, we can detect that the warning is occurring with the rest API services and maybe bring up a separate window to allow the user to click OK for the warning.
0
Comment
Question by:opike
3 Comments
 
LVL 52

Expert Comment

by:Scott Fell, EE MVE
Comment Utility
What about installing a self signed certificate.   I think the warning will only come up once.
0
 

Author Comment

by:opike
Comment Utility
We are already using a self-signed certificate and you're correct about the warning only coming up once (unless the browser data is cleared), but that is the situation I'm trying to more elegantly handle.
0
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
Comment Utility
This is by design - its what the certs are *supposed* to do.

In order for no alert to come up, the cert must meet the following:

a) the name must be correct (i.e. what the user typed into the browser must be what the certificate contains)
b) the date range must be correct (i.e. the certificate must have a start time in the past and an end time in the future)
c) the certificate must be signed by a CA the browser trusts.

of the three, the latter is usually the hardest. Its easy for a server to self-generate and self-sign the certificate to meet a), and specifying "now until ten years from now" usually takes care of b), leaving only c) to deal with.  In a modern MS environment though, you can usually expect that there is a corporate CA available, so that means arranging for your appliance to request a certificate from such a CA rather than generating internally.  This should be part of setup - so after getting a dns name and ip, display a CSR and request it be signed, offering  - as the alternative - to import a pfx file and/or self-generate a cert.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Read about why website design really matters in today's demanding market.
Although it can be difficult to imagine, someday your child will have a career of his or her own. He or she will likely start a family, buy a home and start having their own children. So, while being a kid is still extremely important, it’s also …
This tutorial walks through the best practices in adding a local business to Google Maps including how to properly search for duplicates, marker placement, and inputing business details. Login to your Google Account, then search for "Google Mapmaker…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now