<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Alert when accessing a https page in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642493#M286117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured SSL to the JAVA system. I got the digitally sigend certificate from the MS Certification Authority.I imported the certificate and the root certificate to the key-storage after to a new entry in the service-ssl view.&lt;/P&gt;&lt;P&gt;I stopped and started the Key-storage and SSl provider services. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to browse the portal via SSL but I get a Security alert which says " the certificate is issued by a company you have not chosen to trust"And there is a red mark in the certificate which says " certificate cannot be verified up to a trusted certification authority"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have imported the root certificate also to the JAVA visual administrator then why am i getting this security alert.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I dont get this alert only if I download the root certificate to the browser's certificateion store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way through which I can get rid of this message without downloading the root certificate to each and every client browsers Certificate store.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Nov 2006 10:11:56 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2006-11-13T10:11:56Z</dc:date>
    <item>
      <title>Security Alert when accessing a https page</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642493#M286117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured SSL to the JAVA system. I got the digitally sigend certificate from the MS Certification Authority.I imported the certificate and the root certificate to the key-storage after to a new entry in the service-ssl view.&lt;/P&gt;&lt;P&gt;I stopped and started the Key-storage and SSl provider services. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to browse the portal via SSL but I get a Security alert which says " the certificate is issued by a company you have not chosen to trust"And there is a red mark in the certificate which says " certificate cannot be verified up to a trusted certification authority"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have imported the root certificate also to the JAVA visual administrator then why am i getting this security alert.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I dont get this alert only if I download the root certificate to the browser's certificateion store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way through which I can get rid of this message without downloading the root certificate to each and every client browsers Certificate store.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2006 10:11:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642493#M286117</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-11-13T10:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Security Alert when accessing a https page</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642494#M286118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One way to add your own MS Certification Authority (I'm assuming you have insstalled a local certificate server which and that you are not using a cerfitifcate from a real trusted root CA) into the browsers is via policies in the network logon. But this of course requires that every client is part of your Windows domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2006 10:39:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642494#M286118</guid>
      <dc:creator>MarcelRabe</dc:creator>
      <dc:date>2006-11-13T10:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security Alert when accessing a https page</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642495#M286119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for the quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that could be a way. also I have found scripts which when run will install the certificate on the clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have imported the root certificate directly to the JAVA system then why is it still throwing the error security warning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so does it mean there is no way by which we can eliminate this security warning by installing the root certificate in one central point or server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Priya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2006 11:03:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642495#M286119</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-11-13T11:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security Alert when accessing a https page</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642496#M286120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Priya&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as i know not. The list of trusted root CA's is filled by the browser suppliers  with CA's that they trust. Any other CA's you will have to import manually or via scripts/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2006 11:43:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642496#M286120</guid>
      <dc:creator>MarcelRabe</dc:creator>
      <dc:date>2006-11-13T11:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security Alert when accessing a https page</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642497#M286121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The &amp;lt;b&amp;gt;root certificate&amp;lt;/b&amp;gt; need to be present (i.e. in the local keystore) at the SSL client (here: the web browser); the SSL client &amp;lt;u&amp;gt;must not&amp;lt;/u&amp;gt; trust the SSL server (even if the SSL server would provide the root certificate in the https response during the SSL handshake).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most web browsers are shipped with a bunch of root certificates (and intermediate certificates) to simplify the initial setup. If you operate your own CA then definetly the corresponding root certiticate is not present in the web browser's keystore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers, Wolfgang&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2006 12:21:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-alert-when-accessing-a-https-page/m-p/1642497#M286121</guid>
      <dc:creator>Wolfgang_Janzen</dc:creator>
      <dc:date>2006-11-13T12:21:01Z</dc:date>
    </item>
  </channel>
</rss>

