Deploy an Internal Certificate Authority – How to

certificategroup-policySecuritywindows

IE7 aggressively warns about certificate failure; we have some internal sites that run over HTTPS and thus need a valid cert. We appear to have an certificate authority on the intranet that can sign SSL certs, but we have a problem: how do we mass configure desktops to trust the internal CA?

Is it possible to deploy the internal CA cert locally, via GPO?

Best Answer

The certificate can be distributed by group policy.

From: http://unixwiz.net/techtips/deploy-webcert-gp.html

In the Group Policy Object Editor, navigate down to: Computer Configuration

  • Windows Settings
  • Security Settings
  • Public Key Policies
  • Trusted Root Certification Authorities
  • Then right-click and select Import.