Why it is necessary to install CA certificates in the Microsoft CAPI certificate store?
Installing root certificates into the Microsoft CAPI store serves two purposes. It allows Microsoft CAPI to successfully build certificate path to the root certificate, which is necessary for the initial handshake to succeed regardless of whether Webcullis is installed. Adding a root certificate to the store will also make it appear in the hint list send by IIS, ensuring that clients with credentials issued by that infrastructure will be offered the opportunity to present their certificate. When Webcullis is installed, this is safe because the final trust decision is made using the Webcullis trust store rather than the CAPI store.
Related Questions
- Do I need to install any certificates in my browser to access web sites that use SSL or EV certificates issued by the InCommon Certificate Service?
- I am an Administrator. How do I install the webCARES Root and Issuing CA certificates into my Microsoft web server or application?
- Where can I locate the CA Certificate Chain for 2048-bit BPIA certificates?