SSL Cert problem with Outbreak

bscott at ntisys.com bscott at ntisys.com
Thu Feb 12 00:21:14 EST 2004


On Wed, 11 Feb 2004, at 4:40pm, colet at code-energy.com wrote:
> Here's the problem.  Outlook is complaining every time they connect about
> the fact that the certificate isn't signed by a recognized authority.

  Wow, for once, Microsoft did something right.  I'm sure it was an 
oversight.

  Publish your certificate somehow.  Just the certificate -- *NOT THE 
PRIVATE KEY*.  You can just put it up on a webserver or a file server or an 
FTP server or whatever.  This, in itself, is safe, as the certficiate is the 
"public key" component of the crypto keypair.

  Download certficiate to Windoze box.  If the cert is in PEM format, rename 
it to "cert.crt".  If the certificate is in DER format, rename it to 
"cert.der".

  Open Internet Exploiter.  Tools menu, Options.  "Content" tab.  Click the 
"Certificates" button.  You have to click it twice; don't ask me why.  Click 
the "Import" button and follow the prompts.  I'm not sure what store and 
type Outlook Express will want (I've only used this for IPsec VPN stuff), 
but there aren't that many options.

-- 
Ben Scott <bscott at ntisys.com>
| The opinions expressed in this message are those of the author and do  |
| not represent the views or policy of any other person or organization. |
| All information is provided without warranty of any kind.              |




More information about the gnhlug-discuss mailing list