Tools
Cannot verify self-signed certificate (error 12045) when attempting to connect to the Dameware Central Server
This article resolves an issue where the user cannot verify the self-signed certificate (error 12045) when attempting to connect to the Dameware Central Server.
First published date
Last published date
Overview
When attempting to connect to the Central Server, you can receive an error similar to one of the following:
- Some Unknown error occurred: Error Code 12045
- Cannot verify the self-signed server certificate
Product section
Cause
Resolution
You must install the Dameware Central Server certificate on computers with DRS or MRC installed on them that attempt to connect to the Dameware Central Server.
Depending on your security policy, you can resolve this in at least three ways:
- Modify the security settings on your domain controller.
- Create a group policy to automatically distribute the certificate.
- Manually install the certificate.
Note: If your security policy does not allow users to trust self-signed certificates, you must modify your security policy on the domain controller.
Modify the security settings on your domain controller
Modify your security settings to allow self-signed certificates.
- Log onto your domain controller with domain administrative privileges.
- In Administrative Tools, open Group Policy Management. If this option is not available, either check your credentials or install the Group Policy Management feature in the Server Manager.
- In the console tree, navigate to the domain containing the default domain policy that you want to edit.
- Right-click the Default Domain Policy, and then click Edit.
- Go to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.
- Open Certificate Path Validation Settings.
- In the Stores tab, select Define these policy settings.
- Under Per user certificate stores, select both of the following options:
- Allow user trusted root CAs to be used to validate certificates (recommended) - this allows users to install self-signed certificates to their Trusted Root security store.
- Allow users to trust peer trust certificates (recommended) - this allows users to trust self-signed certificates. - Click OK.
You may need to restart the computers with DRS or MRC installed on them for the security policy to take immediate effect.
Create a group policy to distribute the certificate
If your security policy allows users to trust self-signed certificates, create a group policy to distribute the self-signed certificate.
Export the certificate from the Dameware Central Server:
- Log onto the computer running the Central Server as a local administrator.
- Press the Windows key + R, and enter certmgr.msc.
- Open the Trusted Root Certification Authorities\Certificates folder.
- Find the Dameware certificate for the Central Server.
- Right-click on the certificate and select All Tasks and then Export....
- Click Next in the Certificate Export Wizard.
- Select No, do not export the private key..., and click Next.
- Follow the prompts in the Certificate Export Wizard to save the exported certificate.
- Move the exported certificate to the computer from which you are creating the group policy.
Create the group policy:
- In Administrative Tools, open Group Policy Management.
- Right-click on the domain, and select Create a GPO in this domain, and Link it here....
- Name your new group policy.
- Click OK.
- Right-click on the group policy object you just created, and select Edit.
- Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.
- Right-click Trusted Root Certificate Authorities, and select Import....
- Click Next.
- Browse to the location of the exported certificate, and then click Next.
- Follow the prompts in the Import Wizard to import the saved certificate.
The Dameware Central Server self-signed certificate should now be visible under the Trusted Root Certificate Authorities Store.
Manually install the certificate
Export the certificate from the Dameware Central Server and then import the cert to the Trusted Root Certificate store on the computer with DRS or MRC installed on it.
Export the certificate from the Dameware Central Server:
- Log onto the computer running the Dameware Central Server as a local administrator.
- Press the Windows key + R, and enter certmgr.msc.
- Open the Trusted Root Certification Authorities\Certificates folder.
- Find the Dameware certificate for the Central Server.
- Right-click on the certificate and select All Tasks and then Export....
- Click Next in the Certificate Export Wizard.
- Select No, do not export the private key..., and click Next.
- Follow the prompts in the Certificate Export Wizard to save the exported certificate.
- Move the exported certificate to the computer with DRS or MRC.
Install the certificate on the computer with the DRS or MRC applications installed:
- Log onto the computer as a local administrator.
- Open the exported certificate.
- Click Install Certificate....
- Click Next in the Certificate Import Wizard.
- Select Place all certificates in the following store.
- Click Browse and select Show physical stores.
- Select Trusted Root Certification Authorities\Local Computer.
- Finish the certificate installation.
- Click Yes to approve the certificate installation.
- Press the Windows key + R, and enter certmgr.msc.
Verify that the certificate is installed in the Trusted Root Certification Authorities\Certificatesfolder. You may need to refresh the view.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.