Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsFree MagazinesWhite PapersSubmit Content
Discussion GroupsASP.NETWindows FormsLanguages.NET FrameworkVisual Studio.NET
Articles.NET FrameworkASP.NETToolsWindows Forms
.NET DirectoryOpen Source ProjectsUser GroupsWeb Resources
Related Topics
Visual Basic 6SQL ServerMS AccessOther DB ProductsMS Server ProductsMore Topics ...

.NET Forum / Windows Forms / WinForm General / August 2006

Tip: Looking for answers? Try searching our database.

Windows cannot verify certificate of ClickOnce application

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Zoodor - 04 Aug 2006 08:48 GMT
I have a ClickOnce application code-signed with a code signing certificate
from Thawte. When a user (running IE on WinXP SP2) tries to run the app, if
they click the Publisher hyperlink a warning is shown in the "Certificate"
dialog with the warning "Windows does not have enough information to verify
this certificate". Selecting the "Certification Path" tab shows a status of
"The issuer of this certificate could not be found".

Now, I am sure this is down to the fact that our certificate is not signed
by Thawte's root certificate, but by their intermediary "Code Signing CA"
certificate, which is not installed on the client. If a user tries to run the
app. from a machine with this intermediate certificate installed, there are
no warnings and everything is great, with a full chain of trust shown in the
"Certification Path" tab. My question is this: how can I sign the app so that
this intermediate certifcate is included so users do not see a warning (which
renders the whole code-signing process pretty redundant)?

When I created the ".pfx" file that is used for the signing (by exporting
from my machine's Certificate Store), I chose the option to "Include all
certificates in the certification path if possible", but this obviously
hasn't worked. I am new to this whole code signing lark, so it is entirely
possible I have made some newbie error with this, but I have followed all the
instructions I have found.

I would really appreciate any help on this,

Thanks

(note I posted this question in dotnet.distributed_apps, but got no reply,
so am trying again here in case that was the wrong group to post this
question in).
Andy - 09 Aug 2006 21:04 GMT
You may want to talk to Thawte about this.. they should be signing with
a cert that's already going to be installed on the users machine.

Andy

> I have a ClickOnce application code-signed with a code signing certificate
> from Thawte. When a user (running IE on WinXP SP2) tries to run the app, if
[quoted text clipped - 26 lines]
> so am trying again here in case that was the wrong group to post this
> question in).

Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.