Stephen Drew September 19, 2015 at 11:34 / Reply Thanks Elizabeth - I have read many articles on this often infuriating subject, and yours is by far the clearest and most

so when i am signing binary with this certificate and just checking certificate it's displayed "A certificate's basic constraint extension has not been observed. ". In the old pictures I had generated a certificate with the CN parameter set to "CN=ServerSSL" which is why it was displayed like so in the MMC. Sincerely Silvio Prakash Sajwan September 21, 2016 at 12:17 / Reply best article on this topic .Thanks :) Andrew November 17, 2016 at 13:46 / Reply Thank you!

When I run the .cmd file, it pops up with the 1st box and I enter the key twice.


CN = commonName (for example, "CN=My Root CA") OU = organizationalUnitName (for example, "OU=Dev") O = organizationName (for example, "O=Jayway") L = localityName (for example, "L=San Francisco") S = stateOrProvinceName

We will create this with a new command batch file in notepad just like before, this time with these parameters: makecert.exe ^ -n "CN=yourdomain.com" ^ -iv CARoot.pvk ^ -ic CARoot.cer ^ In Chrome I see some different behavior.

Believe it or not the date was set for July 2014 for some reason. When you do this, the certificates are not trusted by default. Max November 13, 2015 at 14:42 / Reply My company wants to use client certificates for clients on production. You must therefore add the root CA to your machine's Trusted Root Certification Authorities Store through the Microsoft Management Console.

In the Microsoft Management Console, click File ➜ Add/Remove Snap-in Double-click Certificates again, but this time choose My user

Gerard January 17, 2015 at 10:17 / Reply Dear Elizabeth, This is a "Wow!" post. Your CARoot certificate should now be in you Trusted Root Certification Authorities store.

The makecert.exe parameters: -n "CN=CARoot" ➜ Subject's certificate name and must be formatted as the standard: "CN=Your CA Name Here" You can also add more than one in the -n parameter

Let's do all of this step by step: Open an empty notepad document and copy and paste the following into notepad: makecert.exe ^ -n "CN=CARoot" ^ -r ^ -pe ^ -a OutOfTouch6947 August 5, 2015 at 22:29 / Reply My fault I was not putting in the correct password of my Issuer(RootCACert) to sign this new cert. It revolves around the passwords.

Then the 3rd box pops up and I enter the key again and after I hit click OK, I get an Error: Can't load the issuer certificate ('RDS-SERVER.cer'} Failed

  • Thank you!!
  • Elizabeth Andrews October 21, 2014 at 15:14 / Reply I understand you got confused there Prabhu, I have changed the pictures for the server certificate to correctly display the CN name
  • As I understand we need CA root to create client certificate.
  • Please let me know how you get on.
  Go next ➜ Browse to find the CARoot.cer file we created earlier Keep going next until finish where a message box should appear saying "The import was successful".

makecert -n "CN=CARoot Sub" -iv CARoot.pvk -ic CARoot.cer -pe -a sha512 -len 4096 -cy authority -sv SCARoot.pvk SCARoot.cer -sr LocalMachine -ss Root ****Optional parameters pvk2pfx -pvk SCARoot.pvk -spc SCARoot.cer -pfx SCARoot.pfx The .pvk file contains your private key for your .cer certificate and the .pfx file contains both the certificate .cer and the private key .pvk, which means that others can sign that will see how long it takes sky to fix it information on this site regarding the problem At first i got the impression that i could invent my own " -eku" identifier.

Make sure you install the pfx (private key) into the cert store not the public key (.cer). Apr 17, 2014 1:16 AM Helpful (0) Reply options Link to this post by ArmaghOmar, ArmaghOmar Apr 17, 2014 2:33 AM in response to chuck81mm Level 1 (0 points) Apr 17

But it is curious that it's only apple devices suffering this issue in UK. The domain I am using is 'angularjsauthenticationweb.com' and I have modified the hosts file according to the sample.

After that I created a certificate for IIS to use. Are you connected to Wifi when trying to view?

Can somebody please help me out with this issue? Identifies that this is an SSL Server certificate. For security, I want to use different passwords where possible, knowing that some of them need to be the same.

But then later on there are more passwords to create. To check for mutual authentication i am using X509Certificate2 class, while doing this in SslPolicyErrors i am encountering error stating RemoteCertificate name mismatch

I soon learned this is not the case. Thanks a lot. The MMC doesn't display the file name, it displays the CN name (what you wrote in your CN="yourdomain.com" parameter). but now i want to use it on my live server still it is not working well on live server.

None is any close to this detailed and clear explanation. For a walk-through on setting up IIS to use your self-signed certificates check out my next blog post: http://blog.jayway.com/2014/10/27/configure-iis-to-use-your-self-signed-certificates-with-your-application/ Check out my blog post for getting self signed certificates to work with