Windows 10: An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...

Discus and support An invalid [self-signed] CA certificate exists on Windows 10 Pro, but... in AntiVirus, Firewalls and System Security to solve the problem; Statement of the Problem: An invalid self-signed CA certificate which all browsers says it's using, can't be found by standard Windows tools so it can... Discussion in 'AntiVirus, Firewalls and System Security' started by arinbiorn, Jun 4, 2023.

  1. arinbiorn Win User

    An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...


    Statement of the Problem: An invalid self-signed CA certificate which all browsers says it's using, can't be found by standard Windows tools so it can be removed.Background: I have a small self-hosted environment in Docker on Windows 10. I've identified a bogus CA certificate present on the box because it is self-signed by "Linuxserver.io". It appears that this is being presented when I connect to that Docker service over SSL instead of the one from Let's Encrypt and therefore the connection fails.Details of Identified Certificate: When I hit localhost on the host port of 844

    :)
     
    arinbiorn, Jun 4, 2023
    #1
  2. grawity Win User

    Accept self-signed certificate system-wide without installing as root CA

    If the server is under your control:

    1. Create an actual root CA (e.g. with easy-rsa or Xca or Windows Server CA role).
    2. Replace the self-signed server certificate with one issued by your custom CA.
    3. Make sure the certificate you just issued is actually marked as a "leaf" / "end-entity" certificate. Look for the "X.509v3 Basic Constraints" extension – it must be present and say "CA: FALSE".
    4. Install the custom CA's root certificate into your computer.
    5. Safely store the CA private key so that it's only accessible whenever you need to issue a new cert.

    As the server's certificate contains "Basic Constraints: CA: FALSE", it will not be able to issue new certificates using just its own key.

    (The reason you need the CA to be separate is because directly installing the server's self-signed certificate into the "Trusted CA" folder may cause the system to ignore Basic Constraints – after all, it's installed as an authority. Separation avoids this problem, because you can safeguard the root CA keys.)

    As a bonus feature, you won't need to re-trust the server certificate when it expires or when its name changes – just use the same root CA to issue a new cert.
     
    grawity, Jun 4, 2023
    #2
  3. How to add self-signed certificate to my PC?

    My PC is Windows 10 Pro x64 and I have Edge and Chrome browsers installed.

    I installed my firewall's Certificate Authority into the windows certificate store by going to MMC, adding Certificates, and adding it to the Trusted Root CA. I now see my firewall root CA as (firewallCA).

    Now I created a CNAME in my DNS to access my firewall as fw.example.com which only resolves internally. I then generated on my firewall a self-signed certificate. Once created, I downloaded the certificate and also added it to the MMC->Certificates.

    I can now open IE or Edge and go to https://fw.example.com and not get a certificate error. However, if I use Chrome, I still get the error. I went to the Chrome advanced settings and see the firewallCA listed, but not the self-signed cert. I guess I have to add it manually, but I want it to apply to any user on this PC. How can I add the self-signed cert to Chrome for all users?
     
    throwmedowntheriver4444, Jun 4, 2023
    #3
  4. PhilLab Win User

    An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...

    Accept self-signed certificate system-wide without installing as root CA

    For an intranet server I use a self-signed certificate which I want to trust system-wide. I added the certificate exception to Firefox, but this is not possible in Chrome, console applications, IDEs, ...

    This is why I want the certificate to be trusted system-wide. As I understood it, the recommended way is to install it as root CA: Installing a Self-Signed Certificate as a Trusted Root CA in Windows Vista

    As I also understood it, this means that whoever controls the self-signed certificate now controls a root authority which can sign forged certificates for any site on my machine. Is this true and if yes, how can I prevent this? I just want to have a single intranet server self-signed, not potentially all services I use.

    What is the recommended way to deal with intranet TLS here?
     
    PhilLab, Jun 4, 2023
    #4
Thema:

An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...

Loading...
  1. An invalid [self-signed] CA certificate exists on Windows 10 Pro, but... - Similar Threads - invalid self signed

  2. An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...

    in Windows 10 Gaming
    An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...: Statement of the Problem: An invalid self-signed CA certificate which all browsers says it's using, can't be found by standard Windows tools so it can be removed.Background: I have a small self-hosted environment in Docker on Windows 10. I've identified a bogus CA certificate...
  3. An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...

    in Windows 10 Software and Apps
    An invalid [self-signed] CA certificate exists on Windows 10 Pro, but...: Statement of the Problem: An invalid self-signed CA certificate which all browsers says it's using, can't be found by standard Windows tools so it can be removed.Background: I have a small self-hosted environment in Docker on Windows 10. I've identified a bogus CA certificate...
  4. accidentally deleted the CA certificate template

    in Windows 10 Gaming
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  5. accidentally deleted the CA certificate template

    in Windows 10 Software and Apps
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  6. Ftps with self-signed certificate. Remote access issue

    in Windows 10 Network and Sharing
    Ftps with self-signed certificate. Remote access issue: Hi,Sorry I’m not very experienced with this topic. As the title suggests, I created a self signed certificate and set up a ftp over ssl with port 21 explicit. Than forwarded the 21 port in my router and assigned an external one. I’m able to connect to it locally, with the pc...
  7. Invalid certificate

    in AntiVirus, Firewalls and System Security
    Invalid certificate: Hello Please can you explain why I'm seeing these errors https://ibb.co/xz5QXYh Thank you https://answers.microsoft.com/en-us/windows/forum/all/invalid-certificate/82ea04fb-692b-46e8-9ac4-a4e2cc6f70b4
  8. Secure Credentials with Self-Signed Certificates for PowerShell Script

    in Windows 10 News
    Secure Credentials with Self-Signed Certificates for PowerShell Script: Hello everyone, I’m Preston K. Parsard, specializing in Platforms, Azure Infrastructure and Automation topics, and I’d like to share some insights for securing PowerShell credentials using certificates. This post is based on a recent customer project, but we’ll also wrap a...
  9. How to sign Powershell profile w/ self-signed certificate?

    in Windows 10 Support
    How to sign Powershell profile w/ self-signed certificate?: About self-signing drivers: check in with Fernando (Dieter, the owner/operator) at Win-RAID.com. He's been doing that for years because of all the driver mods he posts on his site. Once you load his certificate, you can also load and use any of his drivers. It's a fair amount...
  10. Self-Signed Certificates no longer working since update

    in Windows 10 Support
    Self-Signed Certificates no longer working since update: Morning all, annoyingly Windows decided to update itself over the weekend and rebooted my PC. This also happened with a few other work PCs and left users unable to login for an hour while it forced the update on us. Luckily we only have a handful of Win 10 PCs and decided...