Adding a "Trusted Root"

Hello, all!

I have a quick question… I have created tokens that hold X.509 certificates to allow people to logon to an R6.0.2 server in SSL. The certificates were done by my own CA.

What do I need to do to install the “Trusted Root Certificate” in an IE browser? If we were to use Verisign certs instead, could I assume the Trusted Root comes by default with the IE browser?

I’m not really an admin guy, but I wear the hat by default. Any help would be great!

Thanks, in advance!

Steve in Montreal

Subject: AD - Adding a “Trusted Root”

You can add a Trusted Root Certification Authority via Active Directory if you have that environment. Import the cert into a new GP (or an existing one) under: Computer Configuration-Security Settings-Public Key Policies-Trusted Root Certification Authority. This will be deployed to all items that you assign the GP to.

I hope this helps.

Thanks,

Matt

Subject: Adding a “Trusted Root”

Steve – I’ve never had to try and install a trusted root certificate into a browser, but I do know it would be a pain since it would have to be done for every browser anywhere they would be using your system in a secure mode. If you get VeriSign certs, they will inherently be trusted by all browsers out there.

Subject: RE: Adding a “Trusted Root”

Hi, Michael!

It’s ok… I got it. The client will be using Verisign certs, so it shouldn’t be a problem. For the test machine, I just exported my trusted root cert, and imported it into the other machine. You’re right that that would be a hassle for a lot of users! =8P

Thanks!

Steve in Montreal