Sign in
in
   
"It is the mark of an educated mind to be able to entertain a thought without accepting it."  -Aristotle

About Me

I am a co-founder of Notches, an early stage startup currently based in NYC. We are building a free, open reviews network that anyone can participate in and anyone can build on top of. You can find out more on our official blog.

Read more about my background.

Connect with me on...

Recent Readers

Flickr Photos

 

Warning:

This article is more than 45 days old. Given the speed at which the technology world moves, this post is probably somewhat out of date. Please keep this in mind when reading the post. If this is a tutorial, please check whether you are using the same versions mentioned in the article.

Installing self-signed Certificates in Vista

This post tells you how to install the key. According to Eric Lawrence, the program manager for IE Networking, "unlike on XP, you must click the 'Place all certificates in the following store' radio button, and choose the “Trusted Root Certification Authorities” store.  If you don’t do this, the certificate goes in your personal store, and it isn’t trusted by IE." 

This is cumbersome, he goes on to explain, but is there for a good reason: "Self-signed certificates are quite dangerous, because unless you manually compare the thumbprint/hash via secure or out-of-band communication, you have no assurance that your connection isn't being man-in-the-middle attacked."  In my case, I'm less concerned about a man-in-the-middle attack than connecting to my Exchange server.

What's most frustrating for me right now is that Vista seems to randomly "lose" the certificate. That is, after some time, I stop connecting again as if the certificate was never installed, and sure enough when I check the certificate store it's no longer there. The same thing happens with a private certificate for my school's wireless network (issued to a Cisco network device), and I know Alex is seeing similar issues. I wonder if there is a job that does some additional validation?

I've pinged Eric about this is - he said he hadn't heard of certificates going missing, but he was going to ask around. I'll keep you guys updated if I hear anything.

Only published comments... Jan 18 2007, 04:40 AM by Tim

View related posts

 

Bammo said:

Experiencing a similar problem, we use a self signed cert from SBS2003, remote users connect via rpc over http proxy, vista just gives the untrusted cert error, after manually installing in trusted certs, it seems to work for a few days then locks out again, at the present time we have gone back to XP as this is a pain

February 13, 2007 9:04 AM