Re: invalid certificate



Look at the Best Practices whitepaper available at www.microsoft.com/pki.
You need to designate your root CA as a trusted root for all clients. I assume that client's are connecting from their home computers, etc. In this case, you should have used a certificate that chained to a commercial root CA.

The best purpose for internal CAs is for WEb sites that are *only* connected to by internally managed clients.
Brian

"tree leafs" <treeleafs@xxxxxxxxxxx> wrote in message news:%23ryKhAM3HHA.5360@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
I have just installed windows certificate service and selected an enterprisse root ca. I then issued a certificate to the default website for enabling OWA over HTTPS. All seemed OK, but when users connect to the OWA site the certificate cannot be installed into the trusted root CA. When viewing the certificate, it says "This certificate cannot be verified up to a trusted certificate authority". Is this normal for windows CA? or there is something wrong in installing the CA and creating the certificate?

Thanks in advance,


.



Relevant Pages

  • Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
    ... If a subordinate chains to a trusted root CA, ... Best bet is for your to read the certificate revocation and status checking whitepaper that describes how certificates are verified. ...
    (microsoft.public.windows.server.security)
  • Re: why does WSE fail in trusting certificate chain?
    ... root on the machine in question and use that. ... why does WSE fail in trusting certificate chain? ... But can I import the test CA root in my computer as a Trusted Root ... if the trust chain in a certificate that is received ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: OWA Security Alert Prompt Question
    ... Yes - ALL clients need to install the cert and place it in the Trusted Root ... > - The certificate was issued by a company you have not chosen to trust ...
    (microsoft.public.exchange2000.admin)
  • Re: Securing Webservice
    ... This is all much easier if you get a certificate from a public CA as they ... of the standard root CAs, and they get this to work by installing their root ... to put the cert itself in the trusted root store. ... The problem apppears to be that I am not installing the certificate ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Require SSL certificate
    ... you should only need to give them the root certificate in the ... trust chain the issued your certificate and have all the clients install ...
    (microsoft.public.dotnet.framework.aspnet.security)