Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 913
  • Last Modified:

the certificate is not from a trusted certifying authority

Please help!  

I have a simple server that I have enabled RDP on at work.  I go home, fire up Remote Desktop, type in a public IP address, log on with my credentials, and I'm in.  

During the logon process, I get an alert like the one attached: "the certificate is not from a trusted certifying authority".  If I go through the process of installing the certificate, I get the prompt "The server name on the certificate is incorrect".  

I don't want to ignore the prompt (I have to explain the prompt to management).  Is there a way I can get rid of it without having to buy an external certificate, setup an enterprise CA, or setting Remote Desktop to not warn me about it (advanced tab > server authentication option)?  Can I safely ignore it, since I'm using an IP address that I know, and can be fairly certain it's not a man in the middle attack?  I do have NLA enabled on the remote box.  

The remote box is server 2012 and my home computer is Windows 7 with the latest version of Remote Desktop.  

Thank you all, I appreciate any help I can get.
0
npinfotech
Asked:
npinfotech
  • 3
  • 3
  • 2
2 Solutions
 
Dave BaldwinFixer of ProblemsCommented:
Self-signed certificates are never 'trusted'.  You have to purchase a certificate from a reputable vendor to get it to be "from a trusted certifying authority".  Only then will there be a certificate chain that leads back to a "trusted certifying authority".
0
 
David Johnson, CD, MVPOwnerCommented:
Since you don't want to set up a proper certificate you can elect to ignore it.  If the certificate changes you will have to agree to ignore it in the future.
0
 
npinfotechAuthor Commented:
Thank you for the responses, I appreciate them.  

My understanding is that the point of the prompt is to ultimately help prevent man-in-the-middle attacks.  Since I am using NLA and am using an IP address to connect, is a man-in-the-middle still possible, or highly unlikely?
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
Dave BaldwinFixer of ProblemsCommented:
I thought your problem was having to explain why you are getting the prompt.  If you use the current cert, each new user will get the prompt and have to accept it.  The only way around that is to buy a cert that is traceable to a "trusted certifying authority".
0
 
npinfotechAuthor Commented:
Thanks.  Is there a way I can visually tell if the information on the prompt is actually legitimate (spot if something is wrong)?
0
 
Dave BaldwinFixer of ProblemsCommented:
Certificate error messages normally give the details of their complaint.  A valid certificate will show in the address bar where you can click on it to get more info about it.
0
 
David Johnson, CD, MVPOwnerCommented:
With a self-signed certificate ANYONE can create a certificate using ANY name including the expected name that you are expecting. If you are worried about MITM then vpn into the domain then connect your rdp session. MITM isn't that easy to implement without physical access to the internet endpoints.
0
 
npinfotechAuthor Commented:
I will be opening another thread based on this
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

  • 3
  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now