(Related to Skype for Business 2015) "Update Root Certificates" feature isn't enabled ??

Copper Contributor

I have just done a "Connectivity Analyzer" test with my company's Skype for Business 2015 system.

In the result, there's a yellow exclamation mark for "Root Certificate Update" issue.  Here is the whole passage:
-----------------------------------
(OK)
The Microsoft Connectivity Analyzer is attempting to build certificate chains for certificate CN=sip.xxxxx.com, OU=xxxxx, O=xxxxx, L=xxxx, S=xxxxx, C=xx.
One or more certificate chains were constructed successfully.

Additional Details
A total of 1 chains were built. The highest quality chain ends in root certificate CN=GeoTrust Global CA, O=GeoTrust Inc., C=US.
Elapsed Time: 17 ms.

(Yellow exclamation mark)
Analyzing the certificate chains for compatibility problems with versions of Windows.
Potential compatibility problems were identified with some versions of Windows.

Additional Details
The Microsoft Connectivity Analyzer can only validate the certificate chain using the Root Certificate Update functionality from Windows Update. Your certificate may not be trusted on Windows if the "Update Root Certificates" feature isn't enabled.
-------------------------
 
I don't know what "Update Root Certificates" feature it's talking about.  Is that something I could do in my Skype for Business server?  Or should I contact GeoTrust about their root certificates?

Thanks in advance

 

2 Replies

What's the purpose of this "tech community" if questions are left answered?

 

So lame

If your edge server or frontend servers are missing an updated root certificate that's needed to support the remote contacts "certificate-root", then there is always the solution to import the remote CA-rootcert on your server.
An easy way to fix this is using RUCT.exe (as admin) It has a tab to verify remote server certs. (And fix cert-chain locally)
http://blog.insidelync.com/2011/11/the-remote-uc-troubleshooting-tool-ruct/