The root CA certificate is not installed on the workstation, the CA is not in the list of trusted CA’s, or the CRL can not be contacted.
Check the CRL:
- Navigate to the website
- When the "Revocation information" prompt appears click View Certificate
- Select the Details tab
- Select the CRL Distribution Points field if it exists.
- Copy the CRL URL
- Navigate to the CRL URL e.g.
http://crl.thawte.com/ThawteSGCCA.crl
- A prompt to download should appear if there are no issues
Check the Certificate Path:
- Navigate to the website
- When the "Revocation information" prompt appears click View Certificate
- Select the Certification Path tab
If the Certificate Authority has a red cross because it is not trusted:
- Select the Certificate Authority and click View Certificate
- Click Install Certificate
- Click Next on the Certificate Wizard
- Select the Place all certificates in the following store radio button
- Click Browse
- Select the Trusted Root Certificate Authorities store and click OK
- Click Next on the Certificate Wizard
- Click Finish on the Certificate Wizard
- Click Yes to install the certificate
- Click OK
- Close all certificates
Trusted Root Certificate Authorities can be added per computer using the following Group Policy:
- Computer Configuration | Windows Settings | Security Settings | Public Key Policies | Trusted Root Certification Authorities