Network Management
Configuration wizard deletes the self-signed certificate created during configuration
When you select the Generate Self-Signed Certificate option in the Configuration wizard, the certificate is removed immediately after being created. Modify the group policy that deletes the certificate or use another certificate for the HTTPS binding.
First published date
Last published date
Overview
Verify the following:
-
Check that the browser warning includes the following message:
NET::ERR_CERT_AUTHORITY_INVALID -
In the Event Viewer, check the Application log and look for lines coming from the CAPI2 source with the following text in the Description:
Successful auto delete of third-party root certificate. -
Check the Trusted Root CA on Local Machine store and confirm that you cannot see a certificate with:
Issued To = Issued By = hostname or FQDN
Product section
Cause
Resolution
To modify the policy:
-
Open Local Group Policy Editor (gpedit.msc).
Note: If your computer is part of a domain, the policy has to be tweaked on Domain Controller via Group Policy Management (gpmc.msc) by editing an active policy located under Group Policy Objects. -
Drill down the policy tree:
Computer Configuration > Administrative Templates > System > Internet Communication Management > Internet Communication Settings - Click "Turn off Automatic Root Certificate Update" and Enable it (by default it's not configured or Disabled)