Introduction

Many Oracle E-Business Suite environments, and the APEX, ORDS and other internal web applications around them, run on HTTPS with a self-signed certificate rather than one issued by a public certificate authority. The connection is encrypted, but the browser cannot verify who issued the certificate, so every user sees a Your connection is not private page with the error NET::ERR_CERT_AUTHORITY_INVALID and has to click through it each time.

Chrome warning Your connection is not private with NET::ERR_CERT_AUTHORITY_INVALID for a self-signed certificate

The warning goes away once the certificate is imported into the Windows trusted root certificate store. This post shows the steps in Google Chrome on Windows 11, using our APEX server apex.enginatics.com as the example. Microsoft Edge reads the same Windows store, so the import covers Edge as well.

1 Export the certificate from the browser

Open the application URL, click Not secure to the left of the address and click the icon next to Certificate details.

Chrome Not secure site information panel with the Certificate details button

In the Certificate Viewer, open the Details tab and click Export….

Chrome Certificate Viewer Details tab with the Export button

Select DER-encoded binary, single certificate as the file type and change the file extension from .der to .cer, so that the Windows import dialog lists the file.

Save As dialog saving the certificate as DER-encoded binary with a .cer file extension

2 Import the certificate as a trusted root

2.1 Open the Windows certificate manager

In Chrome, open Settings > Privacy and security > Security, or enter chrome://settings/security in the address bar.

Chrome Settings Privacy and security page with the Security entry

Scroll down to Advanced and click Manage certificates.

Chrome Security settings with Manage certificates

In the Certificate Manager, click Manage imported certificates from Windows. This opens the Windows Certificates dialog.

Chrome Certificate Manager with Manage imported certificates from Windows

Click Import…. The dialog opens on the Personal tab, but the store is chosen in the wizard that follows.

Windows Certificates dialog with the Import button

2.2 Run the Certificate Import Wizard

On File to Import, click Browse… and select the .cer file you saved.

Certificate Import Wizard File to Import step selecting the exported .cer file

On Certificate Store, select Place all certificates in the following store, click Browse… and choose Trusted Root Certification Authorities. The browser only trusts the certificate from this store.

Certificate Import Wizard placing the certificate in the Trusted Root Certification Authorities store

Check the settings and click Finish.

Completing the Certificate Import Wizard with the Finish button

Windows asks for confirmation and shows the certificate’s SHA-1 thumbprint. Compare it with the thumbprint from your server administrator, or with the one on the General tab of the Certificate Viewer on a machine you trust, then click Yes.

Windows Security Warning showing the certificate thumbprint before installing a root certificate
Certificate Import Wizard message The import was successful

3 Verify the connection

Close all Chrome windows and open the application URL again. The page loads without the warning, and the address bar shows the site information icon instead of Not secure.

Blitz Report APEX login page opened in Chrome without a certificate warning

4 Notes

  • Host name. Open the application with the host name the certificate was issued for. Chrome checks the Subject Alternative Name field, so a URL using the IP address, a short host name, or a certificate carrying the name only in the Common Name still fails, now with NET::ERR_CERT_COMMON_NAME_INVALID.
  • Firefox keeps its own certificate store. Import the file under Settings > Privacy & Security > Certificates > View Certificates > Authorities, or set security.enterprise_roots.enabled to true in about:config so that Firefox uses the Windows store.
  • Many users. The import above applies to the current Windows user only. To roll the certificate out to all PCs, distribute it with a group policy under Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies > Trusted Root Certification Authorities.
  • Renewal. When the server certificate is regenerated, the new one has to be imported again.

If you have questions about running Blitz Report on your EBS environment, please contact us.