Theldron Posted July 3, 2017 Posted July 3, 2017 On one PC and one alone I am getting a: Your connection is not private Attackers might be trying to steal your information from http://www.gov.uk (for example, passwords, messages or credit cards). NET::ERR_CERT_AUTHORITY_INVALID Automatically send some system information and page content to Google to help detect dangerous apps and sites. Privacy Policy I thought it was just the user, but I have tried many logins and get the same. We are a SWGFL school and I have deployed the latest certificate and all seemed well. But on the Head's PA comp, I get the error. I have tried re-imaging the PC but get the same issue. I have removed it from the domain and put it back still not helped. Any more ideas would be great? Cheers
dapaulio Posted July 3, 2017 Posted July 3, 2017 (edited) Hmm I suspect if date and time were out it wouldn't have allowed the domain join. Check your smoothwall hasn't got any old dated rules linking the ip address the pa IP address. You could actually set a static IP address different from the dhcp address to see if that is the case Is the heads pa computer alone in a ou with any group policies that may have set a strict Internet zones Are you sure the certificate is installing by running mmc and adding the certificate snapin Edited July 3, 2017 by dapaulio
Theldron Posted July 4, 2017 Author Posted July 4, 2017 Hi both, I have checked the time and date and ensured it is syncing with the DC, so the date and time are right. We are a SWGFL school and have installed their certificate which I have checked on the PC and it has installed. The PC is in its own OU, but only for printer purposes. Ill try a static IP. Cheers
Theldron Posted July 4, 2017 Author Posted July 4, 2017 Tried the static IP still getting the SSL error.
mdrabble Posted July 4, 2017 Posted July 4, 2017 Have you deployed the certificate to the right place? Needs to be in the Trusted Root Certification Authorities.
Theldron Posted July 4, 2017 Author Posted July 4, 2017 Have you deployed the certificate to the right place? Needs to be in the Trusted Root Certification Authorities. Yeah I deployed it to the TRCA, cheers.
dapaulio Posted July 4, 2017 Posted July 4, 2017 Just realised that smoothwall was not part acronym of swgfl. When you get the certificate error. What are the details of the certificate? All details correct?
LemonEntry Posted July 5, 2017 Posted July 5, 2017 Clear the certificate cache on the smoothwall? Guardian > HTTPS Inspection > Settings > "Clear and restart" button (Does not restart Smoothwall, only HTTPS inspection engine!)
Theldron Posted July 5, 2017 Author Posted July 5, 2017 Sorry for the confusion guys, we don't use smoothwall, SWGFL is our ISP (South West Grid For Learning).
Boredguy Posted July 5, 2017 Posted July 5, 2017 @sadams1980 it is the SHA384 version of the SWGfL certificate you have installed isn't it? Are you using the User Based Filtering or still on the old single level filtering?
Theldron Posted July 5, 2017 Author Posted July 5, 2017 @sadams1980 it is the SHA384 version of the SWGfL certificate you have installed isn't it? Are you using the User Based Filtering or still on the old single level filtering? We are using the User Based Filtering mate.
Theldron Posted September 5, 2017 Author Posted September 5, 2017 Still getting the certificate error for certain students, doesn't make sense.
Theldron Posted September 5, 2017 Author Posted September 5, 2017 It's only happening on a few computers, so not sure what is going on. Any help would be appreciated.
paulellam Posted September 5, 2017 Posted September 5, 2017 We had this where the station had a two RM certs installed an older and a newer one, deleted both and re-imported the current one and all was fine. Had to close browsers etc though. Also noticed if you login with new user, chrome wont accept until IE has been opened first, then Chrome is happy. Not sure if this will solve it but just some things we found.
Theldron Posted September 6, 2017 Author Posted September 6, 2017 Found the solution to this if anyone else is having an issue. It was only affecting a couple of machines and for some reason the Google Internet Authority Certificate was not being trusted and placed into Trusted Root Certificates. I exported the certificate for Google (GEOTrust Global) from a working machine and imported into non-working machine and it is now all good. Not sure why the certificate is not importing automatically though. Task for another day, me thinks!!!!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now