已安装证书仍遭拒绝?局域网访问证书错误及连接问题求助
Let's break this down step by step—first we'll fix the certificate trust problem, then we'll look into that telnet error because it might be tied to why your browsers are still throwing warnings.
1. Verify the Certificate Was Properly Imported
Sometimes the PowerShell command reports success, but the certificate doesn't end up in the right store. Let's confirm manually:
- Open the Certificates - Local Computer console: Press Win+R, type
mmc, go to File > Add/Remove Snap-in, select "Certificates", choose "Computer account", pick "Local computer", then finish. - Expand Trusted Root Certification Authorities > Certificates and look for your imported certificate. If it's missing, your command had redundant parameters—try this simplified version instead:
Or use the GUI for more reliability: Right-click thecertutil -addstore -enterprise -f Root .\certificate.pem.pemfile > Install Certificate > Local Machine > Place all certificates in the following store > Browse > Select "Trusted Root Certification Authorities" > Complete.
2. Check for Certificate Mismatches
Even if the certificate is trusted, browsers will throw errors if the certificate doesn't match the URL you're visiting:
- Double-click the certificate file, go to the Details tab, and check the Subject Alternative Name (SAN) and Subject fields. Make sure they include the exact domain or IP address you're accessing (e.g., if you visit
https://192.168.1.50, that IP must be listed in these fields). - This is the most common reason for browser security warnings after importing a root certificate.
3. Clear Browser Caches & Restart
Browsers often cache old certificate statuses, so clearing their caches can reset this:
- Firefox: Press Ctrl+Shift+Delete, check "Cached Web Content" and "Site Settings", then clear and restart the browser.
- Internet Explorer: Go to Internet Options > General > Delete, check "Temporary Internet Files and Website Files" and "Cookies and Website Data", delete, then restart IE.
4. Fix the Telnet Connection Error
This error signals that the server's port isn't accepting connections, which might indirectly cause browser issues. Here's how to check:
- On the target server, run
netstat -ano | findstr :<your-port-number>to confirm the service is listening on the port. - Verify that both your local firewall and the server's firewall allow TCP traffic on that port.
- If the service isn't running or the port is blocked, your browser can't establish a proper HTTPS connection—leading to confusing security warnings even if the certificate is trusted.
5. Test with Other Browsers/Devices
Try accessing the URL with Chrome/Edge, or import the certificate on another LAN device and test. If the problem persists across devices, the issue is likely with the server's SSL configuration (e.g., the wrong certificate is bound to the service) rather than your local trust setup.
内容的提问来源于stack exchange,提问作者ArthurTheLearner

