IE 7 and SSL Certificates

Associate
Joined
30 May 2005
Posts
1,533
Location
Greater Manchester
This is rather annoying.

A few months ago we decided to implement SSL on our Outlook Web Access to make things nice and secure.

So I set about getting SSL (using a self certified certificate) working through ISA Server 2004 and a Front End Exchange Server 2003. Took quote a lot of messing about / learning to get it to work, but we managed it.

Things were rosy until Internet Explorer 7.0 was released. Now when people connect to our mail server they get this ominous warning from their client:

ie7cert.jpg


Which I think will scare most of our staff and students off, and not check their emails. Especially as it recommends that they do not visit the site.

Has anyone found a way around this ?

I don't mind producing a document they need to follow once to download and install our certificate, and add our site to their IE7 bowsers "trusted sites" - but no matter what I do, it always pops this warning every single time...
 
It seems everyone of your OWA users will have to do this to continue to use OWA without that warning popping up all the time.
 
Thanks for that. For some reason, once the certificate is installed, it still pops that warning up... every time :confused:

I don't mind them having to do something once to stop this happening. It's fair enough, so their browser protects them from other sites.
 
Who was the issuing CA? IE won't trust a certificate unless it trusts the Root CA that issues athat Cert. The SSL connection will work (ie it will be encrypted), but the server won't be "Trusted" by the client.
 
We did. I made a certificate authority server internally and it is issued from there.

I understand that it isn't a paid for Verisign type certificate, so it isn't trusted automatically - but I hoped that I could do something to allow our clients to download the certificate, to stop IE 7 moaning every visit as in my OP...
 
oddjob62 said:
You can set up a GPO to automatically add the root CA's cert to each PCs list of trusted CAs

I am talking about the staff and students home machines here... so they can check their email from home.
 
oddjob62 said:
They will need to manually install the root cert.


That being the original certificate I created on the servers, and not the one they can download through the web browser ?

I thought they were the same thing?

(thanks for your help BTW)
 
Back
Top Bottom