<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: System.Net.WebException: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.</title>
	<atom:link href="http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/feed/" rel="self" type="application/rss+xml" />
	<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/</link>
	<description>The blog for developers</description>
	<lastBuildDate>Wed, 11 Apr 2012 20:31:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Alexandre Ponso</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-239203</link>
		<dc:creator>Alexandre Ponso</dc:creator>
		<pubDate>Tue, 13 Mar 2012 19:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-239203</guid>
		<description>Worked for me too. thanks.</description>
		<content:encoded><![CDATA[<p>Worked for me too. thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carl</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-227575</link>
		<dc:creator>Carl</dc:creator>
		<pubDate>Mon, 13 Feb 2012 02:20:04 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-227575</guid>
		<description>Using Go Daddy certificates?

When you look at the Go Daddy Certification Path of that certificate on the web server, do you see Go Daddy Class xxx or Starfield Class xxx ?

And from your non-legacy client i.e Windows Vista upwards, what does the Go Daddy Certification Path display? Go Daddy Class xxx or Starfield Class xxx ?

And these clients that get the warning, are they legacy clients? i.e WinXP and older?

Root Certificate updates works differently as of Windows Vista.

http://support.microsoft.com/kb/931125

Root certificates on Windows Vista and later are distributed via the automatic root update mechanism ? that is, per root certificate. When a user visits a secure Web site (by using HTTPS SSL), reads a secure email (S/MIME), or downloads an ActiveX control that is signed (code signing) and encounters a new root certificate, the Windows certificate chain verification software checks Microsoft Update for the root certificate. If it finds it, it downloads the current Certificate Trust List (CTL) containing the list of all trusted root certificates in the Program, and verifies that the root certificate is listed there; it then downloads the specified root certificate to the system and installs it in the Windows Trusted Root Certification Authorities Store.

You&#039;ll probably find that your Go Daddy Certification Path on the web server thinks it&#039;s Starfield Class 2 instead of Go Daddy Class 2 so you installed the wrong root certificate. It caught me out as when you view in on the web server it doesn&#039;t display a root certificate warning, download and install the Do Daddy class 2 root cert and remove the Starfield one and your problem should dissapear.</description>
		<content:encoded><![CDATA[<p>Using Go Daddy certificates?</p>
<p>When you look at the Go Daddy Certification Path of that certificate on the web server, do you see Go Daddy Class xxx or Starfield Class xxx ?</p>
<p>And from your non-legacy client i.e Windows Vista upwards, what does the Go Daddy Certification Path display? Go Daddy Class xxx or Starfield Class xxx ?</p>
<p>And these clients that get the warning, are they legacy clients? i.e WinXP and older?</p>
<p>Root Certificate updates works differently as of Windows Vista.</p>
<p><a href="http://support.microsoft.com/kb/931125" rel="nofollow">http://support.microsoft.com/kb/931125</a></p>
<p>Root certificates on Windows Vista and later are distributed via the automatic root update mechanism ? that is, per root certificate. When a user visits a secure Web site (by using HTTPS SSL), reads a secure email (S/MIME), or downloads an ActiveX control that is signed (code signing) and encounters a new root certificate, the Windows certificate chain verification software checks Microsoft Update for the root certificate. If it finds it, it downloads the current Certificate Trust List (CTL) containing the list of all trusted root certificates in the Program, and verifies that the root certificate is listed there; it then downloads the specified root certificate to the system and installs it in the Windows Trusted Root Certification Authorities Store.</p>
<p>You&#8217;ll probably find that your Go Daddy Certification Path on the web server thinks it&#8217;s Starfield Class 2 instead of Go Daddy Class 2 so you installed the wrong root certificate. It caught me out as when you view in on the web server it doesn&#8217;t display a root certificate warning, download and install the Do Daddy class 2 root cert and remove the Starfield one and your problem should dissapear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ravi</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-212569</link>
		<dc:creator>Ravi</dc:creator>
		<pubDate>Thu, 05 Jan 2012 18:00:49 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-212569</guid>
		<description>Thanks. work like a charm..</description>
		<content:encoded><![CDATA[<p>Thanks. work like a charm..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jarosław Dobrzański</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-208386</link>
		<dc:creator>Jarosław Dobrzański</dc:creator>
		<pubDate>Mon, 26 Dec 2011 14:00:13 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-208386</guid>
		<description>Terence, have you followed suggestions from my post? Also, from the top of my head, have you tried making the certificate trusted? This can be done with Certificates MMC Snap-in.

Jarek</description>
		<content:encoded><![CDATA[<p>Terence, have you followed suggestions from my post? Also, from the top of my head, have you tried making the certificate trusted? This can be done with Certificates MMC Snap-in.</p>
<p>Jarek</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karthik</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-206637</link>
		<dc:creator>karthik</dc:creator>
		<pubDate>Thu, 22 Dec 2011 09:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-206637</guid>
		<description>Thanks for the code, You are the champ and your code worked like a charm...</description>
		<content:encoded><![CDATA[<p>Thanks for the code, You are the champ and your code worked like a charm&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: terence chua</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-202663</link>
		<dc:creator>terence chua</dc:creator>
		<pubDate>Wed, 14 Dec 2011 15:16:47 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-202663</guid>
		<description>Just wish to check, my development application as client is function well when the server is connect to http web service.

now i try to move to other environment which having setup of https (or ssl). then i hit the error below:-

&quot;The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel&quot;

I already install the certificate provided by the web service. I try to use SOAPUI as tools to check it working fine from my client to the server. but my application just not work.

need help urgently. thanks a lot</description>
		<content:encoded><![CDATA[<p>Just wish to check, my development application as client is function well when the server is connect to http web service.</p>
<p>now i try to move to other environment which having setup of https (or ssl). then i hit the error below:-</p>
<p>&#8220;The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel&#8221;</p>
<p>I already install the certificate provided by the web service. I try to use SOAPUI as tools to check it working fine from my client to the server. but my application just not work.</p>
<p>need help urgently. thanks a lot</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Asif</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-178920</link>
		<dc:creator>Asif</dc:creator>
		<pubDate>Mon, 24 Oct 2011 07:47:59 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-178920</guid>
		<description>Thanks for this great piece of code, it save my lot of time.</description>
		<content:encoded><![CDATA[<p>Thanks for this great piece of code, it save my lot of time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donald</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-135929</link>
		<dc:creator>Donald</dc:creator>
		<pubDate>Fri, 08 Jul 2011 16:22:25 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-135929</guid>
		<description>Thanks, and to Lee Oades as well.  I had to use his code to get it working.</description>
		<content:encoded><![CDATA[<p>Thanks, and to Lee Oades as well.  I had to use his code to get it working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vicky</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-128230</link>
		<dc:creator>vicky</dc:creator>
		<pubDate>Mon, 20 Jun 2011 08:47:51 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-128230</guid>
		<description>Implementing this solution does solve the issue, but now i am not sure of thefact, whether we are bypassing certification check of our SMTP server or server which is receiving the mail.

Essentially i am trying to send mail using (TLS) within a webpart embded in SharePoint environment.

Any pointers on  security risks, involved??</description>
		<content:encoded><![CDATA[<p>Implementing this solution does solve the issue, but now i am not sure of thefact, whether we are bypassing certification check of our SMTP server or server which is receiving the mail.</p>
<p>Essentially i am trying to send mail using (TLS) within a webpart embded in SharePoint environment.</p>
<p>Any pointers on  security risks, involved??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kabs</title>
		<link>http://dobrzanski.net/2009/04/01/systemnetwebexception-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssltls-secure-channel/comment-page-1/#comment-114182</link>
		<dc:creator>kabs</dc:creator>
		<pubDate>Thu, 12 May 2011 10:39:04 +0000</pubDate>
		<guid isPermaLink="false">http://dobrzanski.net/?p=284#comment-114182</guid>
		<description>Thank u very much.Fixed my issue.</description>
		<content:encoded><![CDATA[<p>Thank u very much.Fixed my issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

