Bug in Certificates viewer on Win 2K

From: Sam Wilson (sam.wilson_at_bentley.com)
Date: 10/23/03


Date: Thu, 23 Oct 2003 15:22:26 -0400

We have a class 3 code-signing certificate issued by Verisign. Somebody incorrectly installed the certificate on a Windows 2000 machine, which brought to light the following bug in the Windows Certificates viewer:

All certificates involved in this are installed in the machine store.

The intermediate CA's certificate was incorrectly installed by someone here in the Personal store, rather than in the Intermediate Ceritificate Authorities store where it should have been.

Here's the bug:

The Certificates viewer presented our class 3 certificate as trusted and showed a Certification Path that included the intermediate CA and tracing back to the root CA.

The signcode.exe program, however, refused to use our class 3 certificate, reporting:

    Error: Failed to build the certificate chain as requested
    Error: Signing Failed. Result = 800b010a, (-2146762486)

One of the two is incorrect. I believe that signcode is correct and the Certificates viewer is incorrect.

-------------------------------------------------
Samuel W. Wilson Bentley Systems, Inc.
sam.wilson@bentley.com www.bentley.com



Relevant Pages

  • Re: Web Service Call Using Digital Certificates
    ... that the certificate needs to be installed in the "Certificates (Local ... You can access this store through ... Computer Account --> Local Computer. ... I set up a Windows application to make a call to ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: ipsec with certificate authentication issue
    ... much less logging than Windows 2003. ... certificate from the computer store. ... The cert was obtained via ms cert ...
    (microsoft.public.win2000.security)
  • Re: Active Directory Federation Services
    ... that is associated with their profile and the machine itself has a store. ... Just wanted to let you know that I got the cert problem fixed. ... the user certificate store. ... FSP was looking for certs in the local ...
    (microsoft.public.windows.server.active_directory)
  • Re: Accessing certificate store from ASP.NET web project
    ... the cert must be in the local computer/personal) store - it will then open ... Have a look at the source code to open the right cert store... ... One of the locations requires a x509 certificate in order ... different user context than my vb.net web project. ...
    (microsoft.public.dotnet.security)
  • RE: How to store/ use encoded private key at windows certificate store
    ... Please note that Windows protects the MY store with the user's credential ... > When I do certificate creation I ask for Password, ... > this password to encrypt my private key. ...
    (microsoft.public.platformsdk.security)

Quantcast