- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-13-2018 07:28 AM
Hello
I have added our selfsign SSL that we generated from a windows CA server for our district. When I add it to the firewall under the Device Cert and use it for the forward trust I am getting this error
ssl err_cert_authority_invalid
I am not sure what could be causing this error
Unless it is caused by the fact the domain is not listed in the Default Trusted CA in the firewall
Any help would be great
03-13-2018 07:36 AM
is the selfsigned cert a CA itself, and is the workstation you used part of the domain and aware of the CA?
you may need to import the root cert onto the firewall to have a proper chain available to the client
03-13-2018 07:41 AM
Yes the self signed is a CA as well
The devices are chromebooks that are enrolled to our district and the cert has been added to the chrome devices via google admin
03-13-2018 08:33 AM
And I am using the cert as a Forward Trust
but when I go to a site on a chromebook I get this SSL err
cert_authority_invalid
03-14-2018 09:49 AM
I have also had my cert signed by an external authority and once that is in place I can not make that a CA or a forward trust
So I am not sure what I am doing wrong
Also when I update a cert in the firwall how long can it take for a device to see that
Thanks again for all your help in advance
03-14-2018 12:48 PM
Can you verify on one of the chromebooks that the cert is acually pushing correctly.
chrome://settings/certificates
Authorities
Should be able to see the cert that you pushed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!