sparkeh Posted March 7, 2013 Posted March 7, 2013 So following on from this thread: http://www.edugeek.net/forums/internet-related-filtering-firewall/109788-quickly-check-something-me-please.html it appears that our Windows 7/8 machines cannot access https://extranet.hse.gov.uk/lfserver/external/F2508IE due to a cert error. Our XP machines are fine. I can't get my head around the problem as Win 7 is supposed to auto grab certs as it visits pages right? So what can I do about this?
Jamo Posted March 7, 2013 Posted March 7, 2013 So following on from this thread: http://www.edugeek.net/forums/internet-related-filtering-firewall/109788-quickly-check-something-me-please.html it appears that our Windows 7/8 machines cannot access https://extranet.hse.gov.uk/lfserver/external/F2508IE due to a cert error. Our XP machines are fine. [ATTACH=CONFIG]17461[/ATTACH][ATTACH=CONFIG]17462[/ATTACH] I can't get my head around the problem as Win 7 is supposed to auto grab certs as it visits pages right? So what can I do about this? Are these machines updated? Windows update would usually pick up any new root certs, this one is signed by verisign which should be a globally trusted certificate in the OS itself.
sparkeh Posted March 7, 2013 Author Posted March 7, 2013 Are these machines updated? Windows update would usually pick up any new root certs, this one is signed by verisign which should be a globally trusted certificate in the OS itself. Updates won't help - windows 7 doesn't get its root certs from windows update, but anyhow the machines are fully patched. Ok so, the cert it is looking for is "VeriSign Class 3 International Server CA - G3" which is an 'Intermediate Certification Authority" and doesn't appear on our Win 7 machines. Installed it and the site works.
pete Posted March 7, 2013 Posted March 7, 2013 (edited) Updates won't help - windows 7 doesn't get its root certs from windows update, but anyhow the machines are fully patched. That's not strictly true. Microsoft originally said they wouldn't be pushing any out via WSUS or Windows Update, but they've pushed out several Root cert updates for Windows 7 if you use WSUS. KB931125 was the latest in Dec 2012. A quick reading would imply it's XP only, but... They're under the general "updates" classification. Edited March 7, 2013 by pete 1
sparkeh Posted March 7, 2013 Author Posted March 7, 2013 Thanks @pete I didn't know that, all the MS literature states they don't so this but yes I have Dec 2012 Root Updates in WSUS. However, turned out it wasn't a root cert issue
edutech4schools Posted March 7, 2013 Posted March 7, 2013 Updates won't help - windows 7 doesn't get its root certs from windows update, but anyhow the machines are fully patched. Yep our certs will not work on W7 until I have run the updates.
sparkeh Posted March 7, 2013 Author Posted March 7, 2013 Ok let me slightly revise what I said earlier: From Windows root certificate program members Windows Vista, Windows 7 Root certificates on Windows Vista and later are distributed via the automatic root update mechanism – that is, per root certificate. When a user visits a secure Web site (by using HTTPS SSL), reads a secure email (S/MIME), or downloads an ActiveX control that is signed (code signing) and encounters a new root certificate, the Windows certificate chain verification software checks Microsoft Update for the root certificate. If it finds it, it downloads the current Certificate Trust List (CTL) containing the list of all trusted root certificates in the Program, and verifies that the root certificate is listed there; it then downloads the specified root certificate to the system and installs it in the Windows Trusted Root Certification Authorities Store. If the root certificate is not found, the certificate chain is not completed, and the system returns an error. To the user, a successful root update is seamless. The user does not see any security dialog boxes or warnings. The download happens automatically. In addition, Windows Vista and later client SKUs support weekly pre-fetching from Microsoft Update to check for updated root certificate properties (for example, extended validation (EV), code signing or server authentication properties, which are certificate properties added to a root certificate). Interesting that they decided to push some out via WSUS.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now