Eu consegui que isso funcionasse criando um rootCA com um nome diferente do que o servidor identificado no certificado do servidor. Em vez de usar server1.widgets.com
como CN no rootCA, usei Widgets Dev
como o CN. Eu instalei esse rootCA na caixa do Windows 7 através do console do MMC. Em seguida, criei o certificado do servidor usando server1.widgets.com
como CN e instalei isso no servidor.
Note que eu não precisei converter o rootCA do formato .pem para que a importação seja bem-sucedida na caixa do Windows.
Conteúdo completo do rootCA alterado abaixo:
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 11541727865071105011 (0xa02c7457b3ca73f3)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=New York, L=New York, O=Widgets, Inc., OU=Widgets Dev, CN=Widgets Dev
Validity
Not Before: Mar 12 14:47:54 2016 GMT
Not After : Dec 14 14:47:54 2070 GMT
Subject: C=US, ST=New York, L=New York, O=Widgets, Inc., OU=Widgets Dev, CN=Widgets Dev
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:ef:2a:75:c1:e1:a4:07:c3:27:46:94:49:2f:2a:
27:0c:6d:33:d7:4c:84:ee:59:d0:83:18:10:c8:f9:
7e:8f:4e:19:ef:c3:6f:04:a7:a3:b2:9f:6f:03:de:
fb:9a:f6:17:4e:87:8c:29:93:9b:a3:52:63:19:29:
93:1e:cc:a0:22:fe:4e:7c:00:83:8f:82:c3:83:f1:
65:9d:2b:5e:b4:9e:4f:cc:29:62:a6:5f:5e:11:51:
99:2b:55:55:6b:17:13:6c:30:14:44:6f:a7:42:d0:
16:2b:02:76:5c:ae:76:4a:2b:60:b2:ea:1f:64:61:
09:8a:c6:9f:23:ef:85:82:c6:fb:f6:7d:ce:b4:c2:
a3:89:f8:98:79:f8:6a:df:6a:c5:44:75:41:f2:11:
7c:94:32:82:00:fd:ae:d4:ef:51:0f:7f:bc:2a:25:
d6:b3:53:fd:3f:13:21:7c:e0:d6:b7:87:5f:09:19:
79:7c:2f:cc:b1:c1:a2:49:bb:17:62:8f:e3:cd:db:
99:6a:2b:fc:d3:f8:9a:58:2d:0c:d0:bd:21:a1:2e:
64:f7:c0:84:7d:48:53:94:62:79:c4:bf:51:ba:04:
9e:1a:15:3e:a8:ec:3d:c2:c9:05:ed:67:dc:c0:ef:
6d:e0:fa:a7:0e:56:51:f7:7b:dd:1c:a4:88:f0:f4:
50:17
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
E9:F3:EC:16:D9:48:85:EC:29:E8:DB:8A:CD:1E:76:F2:37:9F:AA:F1
X509v3 Authority Key Identifier:
keyid:E9:F3:EC:16:D9:48:85:EC:29:E8:DB:8A:CD:1E:76:F2:37:9F:AA:F1
X509v3 Basic Constraints:
CA:TRUE
Signature Algorithm: sha256WithRSAEncryption
d0:e1:08:6b:4a:19:3e:29:06:27:fd:79:00:ed:a3:31:50:24:
be:99:67:c7:a7:d3:4a:fa:6e:f0:a0:b6:97:67:b2:c0:ce:a9:
4a:8c:d4:de:ee:be:9e:cb:53:33:c3:4e:ee:7a:21:e2:3d:5a:
8d:f8:23:77:65:34:9f:f1:f7:1a:d3:c5:4b:b2:80:eb:06:22:
4a:8c:94:86:b5:1b:db:2f:48:ab:55:5f:d3:7c:74:22:8e:dd:
b1:64:1b:5a:ce:f5:ee:f3:10:d7:8e:28:d7:6a:35:e7:1f:9a:
a9:9e:56:54:93:2e:a1:fb:e4:6c:88:57:56:73:f9:94:c4:96:
bc:b7:08:4b:df:e8:80:a4:25:01:0e:07:c1:1b:68:d6:51:3f:
5f:4e:0f:a9:22:f4:22:38:a8:d5:8b:fe:2a:19:2e:ed:0e:c0:
c9:bd:b3:1a:49:a5:69:32:ad:54:2c:19:17:57:0d:9c:93:86:
3e:51:77:e7:15:38:d3:90:13:7b:0e:db:75:45:1f:28:9d:ab:
5a:90:3f:3d:6c:34:37:ca:e0:ac:fd:8e:33:03:42:00:03:c7:
5b:9c:c1:ce:55:57:b4:67:f8:81:55:2c:9d:e6:2a:c9:44:74:
22:4a:87:0f:fd:bf:a9:57:d5:88:79:b7:a9:a8:57:14:00:e3:
16:af:0a:e1