SO - Certificate Import Wizard

 3 Replies
 0 Subscribed to this topic
 11 Subscribed to this forum
Sort:
Author
Messages
Chris12
Veteran Member Send Private Message
Posts: 150
Veteran Member
I was just looking into a way to automate installing the self sign certificates into the users PC.
As of right now, when use SO for the first time, they have to navigate thru the Certificate Import Wizard to ioad the certificate into the browser.

Just was wondering if anyone had a way to automate this ....

TY,

Chris

Karin
Veteran Member Send Private Message
Posts: 57
Veteran Member
You should be able to use group policies to push out the root as a trusted root. Perhaps this will help you. http://technet.microsoft....ibrary/cc754841.aspx

Or this: The certificate can be deployed through a group policy by exporting the certificate and importing it to the Trusted Root Certification Authorities list under Computer Configuration\Windows Settings\Security Settings\Public Key Policies.

As far as I know there is no script way to do it but you can use AD group policies.

I assume all client PCs are in the same domain.

I would recommend using an in-house certificate server and use that and store the certificate from the CA as a trusted root instead of the specific grid certificate. Then you have one trusted root for all internal web sites and secure communication.
http://technet.microsoft....ibrary/hh831740.aspx

It will be interesting to know what type of SSL certificate is the most used. Self signed is easiest to get started with but I always replace that grid certificate with an Infor CA when I install internal environments here at Infor. Our Certificate server has a web UI where I can paste the certificate request and download a certificate directly after authenticating myself with my domain credentials. That CA is a trusted root for all clients PCs.
Regards Karin http://smartofficeblog.com
Chris12
Veteran Member Send Private Message
Posts: 150
Veteran Member
Thanks Karin !!!
Chesca
Veteran Member Send Private Message
Posts: 490
Veteran Member
Our network admin had it installed on the server so we no longer have to worry about installing it on user's pc.