GPO to trust a specific SSL certificate?


is there way configure workstations via gpo trust specific ssl certificate specific web site without automatically trusting every certificate ever signed ca in future? 

your question twofold:

  1. can distribute certificate trusted clients in gpo. yes, shown in image here:
  2. your other question isn't gpo specific. you're asking if possible trust single certificate issued ca, not trust other certificates issued ca. answer no. think of ca local dmv , certificates drivers licenses. how police possibly "trust authenticity" of drivers license, while not trusting issuing agency?

more on concept here: http://serverfault.com/questions/490276/is-it-possible-to-trust-a-certificate-in-windows-without-trusting-its-root-ca


mike crowley | mvp
my blog -- baseline technologies



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...