Jump to content

Recommended Posts

Posted

I'm guessing that a few people here use ipsCA as a free SSL cert provider. Following the recent root CA change, I find that browsers reject the root CA. I was assuming that IE (at least) would have grabbed the root CA from "somewhere" in an update? Perhaps I have somehow missed an update in WSUS but I will check. Im not too up on how the root CA's get updated on client machines but I would have guessed from an MS update.

 

Anyway, I must have set up the cert renewal correctly in IIS and imported the correct *new* intermediate and root certificates in both IIS server and the ISA 2006 server as my browser correctly states the new intermediate and new ipsCA Global CA Root.

 

What action have other people taken for the change? Have you installed the ipsCA Global CA Root certificate on your local machines or was there an update I have missed?

 

Telling the teachers to install a certificate at home will be a nightmare....

  • Thanks 1
Posted
I'm guessing that a few people here use ipsCA as a free SSL cert provider. Following the recent root CA change, I find that browsers reject the root CA. I was assuming that IE (at least) would have grabbed the root CA from "somewhere" in an update? Perhaps I have somehow missed an update in WSUS but I will check. Im not too up on how the root CA's get updated on client machines but I would have guessed from an MS update.

 

Anyway, I must have set up the cert renewal correctly in IIS and imported the correct *new* intermediate and root certificates in both IIS server and the ISA 2006 server as my browser correctly states the new intermediate and new ipsCA Global CA Root.

 

What action have other people taken for the change? Have you installed the ipsCA Global CA Root certificate on your local machines or was there an update I have missed?

 

Telling the teachers to install a certificate at home will be a nightmare....

 

Hi,

 

The users don't need to install the root certs because if they have access to windowsyodate.microsoft.com or download.microsoft.com then when they visit the page that is encrypted the OS will automatically download the root cert automatically. In networks behind the firewall or proxy servers the *.download.microsoft.com could be added so it allows the browser to connect and update the root cert automatically.

 

At the moment the IPSCA will work with IE but Firefox has not added the root certs on to their list and you will get cert error using firefox.

 

Ash.

Posted
I use them, we didn't install the new certificates as in thier email it said it was due to expire on the 29th dec and I was not in work then. It's still working on the old certificates and I won't do anything until it goes tits up.
Posted

interesting....

 

I still have the original certs in the cert stores on both the IIS boxes and my ISA box so I might switch back to see if that cures things temporarily. Just ran MS update locally on a client giving the CA root error (sp 3, IE7) still giving root cert error. As you can see it is the global certificate giving the error.

caroot.JPG

Posted

Old Certificate failed correctly on the 28th December. You can get this working again by trusting the out of date signing certificate if you need to.

 

New one installed fine, but does not seem to auto update on servers. Has auto updated on home machines and school machines (XP SP3, IE8).

 

Jonathan

Posted

I have teachers telling me they get the cert error message at home. I think i'll bite the bullet and get a 5 domain godaddy cert for a year until I am confident that MOST peoples machines will have updated as I have difficulty in explaining email to some of them, let alone getting a certificate pack installed.

 

I knew "free" was too good to be true. :D

Posted

So even with the intermediate certificates installed on the server using it (in our case Exchange) we'll still get the error in Firefox?

 

Never had this problem before the certificate change... will be a right pain if it requires updates at the client end :(

 

Wish I could order GoDaddy but it's American and will be a problem for PO's by looks of it...

Posted

If I install the cert pack update then all is well. However, this screenshot is taken from a staff laptop that has automatic updates enabled. It is windows XP and has IE7 on it. The new intermediate cert is being served up along with the chain reporting back to the new root CA - however the root CA is not trusted.

 

Some (maybe most probably) will have little difficulty - perhaps there is some rhyme or rule that gets IE to check for new root CA's. Although there are other large establishments out there who have identical issues (when I was googling the problem).

 

It all boils down to what you want. If you want a seamless no problems SSL cert then IPSCA isnt the one for you at the moment (hey its free!). If you are using it for internal use and maybe staff only then go for it.

cert2.jpg

Posted

Have to say - the new root certificate is working fine for us.

 

I have checked that it is auto updating on XP as follows (running on a student low privalege login):

1. Checked that the only relevant trusted root certificate is the old one

2. Access the secure site. The server has the new certificate and the new intermediate CA and the new root CA in the relevant places.

3. Client machine seems to realise that it may need to update the certificates and initiates a connection to microsoft. These are logged in the event log by crypt32. The messages are as follows:

 

Successful auto update retrieval of third-party root list sequence number from:

 

Successful auto update retrieval of third-party root list cab from:

 

and then 14 seconds later:

 

Successful auto update retrieval of third-party root certificate from:

 

Successful auto update of third-party root certificate:: Subject: Sha1 thumbprint: <3C71D70E35A5DAA8B2E3812DC3677417F5990DF3>

 

4. Page displayes fine with no warnings

5. New root certificate is now in the store with the old one.

 

Now, The site makes some reference to this process only working if you use IE and not Firefox, and indeed I suspect that if it cannot get a connection to the microsoft site at that moment it will fail but it has worked fine for us on all machines so far.

 

Do your machines attempt to make this link out to Microsoft? You should be able to see either a success or failure in the event log.

 

Hope this helps

 

Jonathan

Posted

I fixed the internal machines by added the KB (suggested above) to WSUS.

 

The 2 laptops that still had issues were standalone teacher personal ones (I couldnt be bothered fault finding so I simply installed the same KB). since these machines were personal ones (with automatic updates switched on) then they might have some odd firewall or other MS updates issues - either way you might have fun with some external machines not playing ball.

Posted
So even with the intermediate certificates installed on the server using it (in our case Exchange) we'll still get the error in Firefox?

 

Never had this problem before the certificate change... will be a right pain if it requires updates at the client end :(

 

Wish I could order GoDaddy but it's American and will be a problem for PO's by looks of it...

 

Hi,

 

You need to install both the global cert into the Trusted Root Certification authorities and the Level 1 cert in the Intermediate Certification authorities on the servers where the certificate is bound to a site. This is detailed in the instructions but once this is done then the error you seeing with be gone and the cert will be fully validated.

 

Ash.

Posted (edited)

Remember that if you have ISA you need to import them on the ISA server also - not just your IIS machine (and exchange IIS if you have a different machine for OWA etc). To swap over your ISA SSL Listener certificate at the same time you swap over your IIS directory security certificate too. The first time I installed the intermediate (old) certificate I did need to restart ISA2006, the second time I when I was "renewing" my certificate I did not need to restart the ISA server in order to serve the intermediate certificate.

 

As for godaddy - yes, PO's are a problem. It is one of the only two occasions that I pay on my credit card and claim back (the other is a foreign laptop spare parts company)

Edited by KK20
  • Thanks 1
Posted
I'm still waiting for my certs to come though!!! What the heck is the holdup my SharePoint portal is broken as ISA server is upset about expired certificates.
Posted
seems odd, I had a random email almost immediately about "It was not possible to connect to a Whois Server". Then another email the next day asking me to agree to terms, shortly after the new certificate was included as an attachment.
Posted
Hi,

 

You need to install both the global cert into the Trusted Root Certification authorities and the Level 1 cert in the Intermediate Certification authorities on the servers where the certificate is bound to a site. This is detailed in the instructions but once this is done then the error you seeing with be gone and the cert will be fully validated.

 

Ash.

 

Yup did that as the standard procedure as we had an ipsCA cert when we upgraded to Exchange 2007 a few years back, IE seems fine but Firefox looks like it's still moaning when I tried it from home this morning :confused:

Posted
Yup did that as the standard procedure as we had an ipsCA cert when we upgraded to Exchange 2007 a few years back, IE seems fine but Firefox looks like it's still moaning when I tried it from home this morning :confused:

 

Hi,

 

Yeah firefox will still display the error because they (mozilla) have not yet put the global root CA for the IPSCA on their CRL list and hence you get the error. Both IPSCa and mozilla are working on it and it will be added soon, at least this is what i have read on the forums.

 

Ash.

Posted
I still have yet to get my cert! I am not happy about that, and its causing chaos for us, I think I will just get a 12 month Godaddy one for now they were cheap enough and then use that for 12 months and hope this is sorted this time next year
Posted (edited)
My advice is, if you're waiting for ipsCA, just grab a free 90 day one from somewhere like here - http://www.instantssl.com/ , then try again for your free 2 year cert from ipsCA in a month or two when they've settled down. Alternatively, maybe try a free one from here - http://cert.startcom.org/ - I beleive they are valid for one year. Edited by tonyd
  • Thanks 1
Posted (edited)

An update as sorts. The staff who use firefox are savvy enough to not care about the certificate after I explained to them. The staff who were having issues (all XP) were given the november certificate update pack from microsoft and told to install. None have returned with issues.

 

One thing I have noticed is that it has thrown peoples mobiles out. My mobile refused to accept the new root CA so I needed to actually install the root cert before OMA and sync worked. The same thing for the blackberrys, they didnt seem to want to talk to our exchange server either so again I needed to import the root CA. This was only for our SMT (and me) though so not a major issue, however, if you use mobile devices around the school - be aware that you may have issues.

 

Internally I distributed the cert pack via WSUS. I have no idea why I.E. was not picking up the certificates internally - I *suspect* that WSUS prevents this as squid or DG has not picked up any traffic (from one of my test machines) when I tried to access the seemingly untrusted root CA, hence me needing to keep up to date with the cert packs on WSUS.

 

In any case, i'll stick with ipsCA for a while, simply because it works for what I want it too at the moment and since im moving our exchange server to x64 2008 and exchange 2007 over summer I would prefer a free wildcard certificate to a cheaper godaddy UCC cert.

Edited by KK20
Posted
Just updated to the new IPSCA certficates on our Moodle server, still getting invalid certificate from workstations. We are CC3 so I can't use WSUS to install the Microsoft certificate update. I can see in the eventviewer "Successful auto update retrieval of third-party root certificate" everytime I hit the SSL login page with acompanying 10 second delay. At the moment I'm worse off than before I had the new certificate, at least it would fail faster before the update.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...