Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Group Policy and Trusted Publishers

Status
Not open for further replies.

iLinkTech

IS-IT--Management
Nov 28, 2003
133
DE
Hi,

This may not be the right place to post this but this is where I'll start. Network administrator for a Windows 2003 domain w/ XP clients. One of my users has an Excel spreadsheet w/ macros that is used for various administrative tasks (non I.T.) The spreadsheet always pops the macro warning dialog when it starts up and for some users it has become an "annoyance".

I tried to sign the macro w/ my domain CA-issued code signing cert but when I did this, only I was able to click the box to "Always trust macros from this publisher.." - the box was grayed out for everyone else (non-admins).

Obviously I'm missing or don't understand something - I do not have the "Trusted Publisher lockdown" enabled in Group Policy and as this is the first time I've played around with code-signing I don't believe that any GP-initiated restrictions have been set in the past (I'm the only one working on GP).

Anyone have any thoughts? Suggestions?

Thanks...
 
Have you installed the Office ADM that is available, see whats in there?

Hope this Helps.

Neil J Cotton
njc Information Systems
Systems Consultant
 
Yeah, didn't see anything that would help right off the bat but I plan on looking again today.

Thanks...
 
Figured it out - because we use a stand-alone CA (OpenSSL) for code signing Windows could not implicitly trust the Publishers Certificate as it had no reference to the stand-alone CA's root cert. Using Group Policy to import the root ca cert resolved the issue.

As an interesting side-note, I was also able to use the CAPICOM sdk from Microsoft to create an installer for the standalone root ca cert. The cert installer enables automated import of the CA cert onto computers that are not joined to the domain but still need to have the capability to trust signed macros.

Thanks again for everyone's assistance...:)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top