Accessing DoD Enterprise Email, AKO, and other DoD websites with Internet Explorer & Edge (Windows 10) on your Windows computer Performing these fixes.

Slides:



Advertisements
Similar presentations
How to Install a CAC Reader and software on your Personal Computer
Advertisements

B: STUDENT DRIVE MOVE INSTRUCTIONS. Using Internet Explorer: From your computers desktop, double click on the Internet Explorer icon. (Internet Explorer.
Presented by: Michael J. Danberry Last Revision: 17 January 2014
SM Online Group Administration Technical Configuration & Testing O L G A.
Installation & User Guide
Web Shift Booking System
04/24/2014April 2014 Chapter Meeting1 Forcing IE 10 & 11 to play nicely with Retail Link™ Dan Batson Sr. Analyst / Category Advisor Fujifilm North America.
Enlighten V2.2 Manual – User Level Access
1 Unit & District Tools Phase 1. 2 To access the new Unit and District Tools, you will need to click on the link embedded in the MyScouting Flash page.
Student Getting Started Guide Updated June Ensure that you are connected to the Internet. 2. Launch your web browser (Internet Explorer, Firefox,
Steps to Recover Private Encryption Keys
For Removal Info: visit
15.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 15: Configuring a Windows.
NetAcumen ActiveX Download Instructions
Installing SAS 9.3 Raymond R. Balise Health Research and Policy.
Making DoD Enterprise , AKO, and other DoD websites work with Internet Explorer on your Windows computer. Presented by: Michael J. Danberry Last.
Installing SAS 9.3 Raymond R. Balise Health Research and Policy.
Microsoft Windows Vista Chapter 6 Customizing Your Computer Using the Control Panel.
1 of 6 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Downloading and Installing AutoCAD Architecture 2015 This is a 4 step process 1.Register with the Autodesk Student Community 2.Downloading the software.
File sharing. Connect the two win 7 systems with LAN card Open the network.
Step 1 - Start your PC and place your Windows XP CD in your CD/DVD- ROM drive. Your PC should automatically detect the CD and you will get a message saying.
Configuring Active Directory Certificate Services Lesson 13.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
How to Install a CAC Reader on your Personal Computer
Digital Certificate Installation & User Guide For Class - 2 Certificates.
How to Digitally Sign a form using IBM Forms viewer (formerly Lotus Forms) and eSign (formerly ApproveIt) Presented by: Michael J. Danberry Last Update.
LGC Website and Customer On-line Tools LGC RESOURCE 2014.
Panorama High School E.G.P./ Training to Put Students’ Grades on the Website Wednesday, September 29,
Downloading and Installing PAF Insight PAF Insight can be easily downloaded Or can be installed from a CD A license is needed t0 activate the program.
Configuring the MagicInfo Pro Display
So – You want to learn how to put an article onto the state website. (Note: If you have not done so, you will need to review the web training provided.
1 Enterprise How to access your from the web.
Troubleshooting Windows Vista Security Chapter 4.
Parent Guide for staying connected. To Begin using Skyward Family Access you will need:  A computer connected to the internet  A web browser (Windows.
IntroductionSlide #1 Stanford Math Professional Development: Technical Training © 2009 EPGY Stanford University.
So – You want to learn how to put a BLOG article onto the state website. (Note: If you have not done so, you will need to review the web training provided.
Downloading and Installing Autodesk Revit 2016
Microsoft Access 2010 Chapter 10 Administering a Database System.
Downloading and Installing Autodesk Inventor Professional 2015 This is a 4 step process 1.Register with the Autodesk Student Community 2.Downloading the.
ARMS Advanced Risk Management System User Documentation.
ISEC: Excellence in Engineering DoD PKI Automatic Key Recovery Adam Simmons (520) , DSN , or ,
If browser is blocking some government web sites, this job aid may help you fix the problem. Please note that in addition to the certificates issues, IE.
Making the new AKO webmail work faster on your computer Last Revision: 19 September 2010 I am now performing this fix on people’s computers who use AKO.
Testing External Survey Automatic Credit Granting Shepherd University Department of Psychology.
Adding DoD certificates to your Mac Presented by: Timothy Solberg and Michael J. Danberry Last Review: 07 October 2015 Adding these certificates are “normally”
So – You want to learn how to put an article onto the state website. (Note: If you have not done so, you will need to review the web training provided.
Maryknoll Wireless Network Access Steps for Windows 7 As of Aug 20, 2012.
How to fix Error code 0x80072ee2 in Windows 8.1? Fix%20%20Update%20Error%200x80072EE2%20in%20Windows%20 8.1,%20Windows%2010!%20-%20Fix%20PC%20Errors.htm.
FROM INFINIT-I: We have recently performed an upgrade to our Infinit-I platform that could create a challenge accessing a video or completing a.
Fixing Windows 10 Automatic Updates Install Problem
Windows Vista Configuration MCTS : Internet Explorer 7.0.
How to fix Netflix Signing In Issues? For More Details Visit Our Website
Installing RMS 3.0 Contractor Mode
Unit & District Tools Phase 1
Performing these fixes “should” fix most access problems.
Bomgar Remote support software
Performing these fixes “should” fix most access problems.
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
A Quick Guide To Fix QuickBooks Error QuickBooks is a leading accounting software that has assisted millions of small and mid-sized business in.
A high-tech accounting software, QuickBooks is a highly trusted software by small and medium sized business. It streamlines accounting processes of a.
GTS WebSocket General Guide
Quick Reference (Edge)
End User Guide.
How to Create and Start a Test Session
Performing these fixes “should” fix most access problems.
DoD PKI Automatic Key Recovery
Performing these fixes “should” fix most access problems.
Dell Latitude Laptop Student setup.
Business Zone - Clearing your Cache
Presentation transcript:

Accessing DoD Enterprise , AKO, and other DoD websites with Internet Explorer & Edge (Windows 10) on your Windows computer Performing these fixes in Internet Options “should” fix most access problems. Last Revision / review: 12 November 2015 Presented by: Michael J. Danberry Personnel utilizing this guide without CACs should only skip the pages marked: “This page is CAC Specific.” CAC holders need to follow ALL slides. The most up to date version of this presentation can be found at: 1

To successfully access DoD websites, you MUST install the Department of Defense (DoD) certificates Download links for the InstallRoot file(s) can be found on: It will not harm your computer to run this file more than once If after installation of DoD certs you see “There is a problem with this website’s security certificate” or see red certificate errors, follow this guide: 2

Open Internet Explorer (IE) Make sure the page you are having problems accessing is NOT open in any tabs or another IE browser, Select Tools Image from Internet Explorer 9, 10, & 11 You may also click the “Alt & T” keys on your computer keyboard 3

Windows 8 / 8.1 users need to use the Internet Explorer from the Desktop 4 NOT the one from the Start tiles Windows 10 users go to slide 5

Select Internet Options after clicking the ‘gear’ 5 Windows 10 users [using Edge instead of IE] need to “Right click” the Windows logo in the lower left corner of your screen, click Control Panel and select Internet Options. Now go to slide 7 to continue

Select Internet Options 6

Check the Delete browsing history on exit (box) (IE 11 users, See note below) and then click the Delete… (button) 7 NOTE: IE 11 users may have problems if you check this box.

Check all boxes, except for Passwords, click Delete 8

Click Settings 9

Change this number to 50, click OK NOTE: This is my personal recommended size. Making it smaller will make your browser look for an updated page more often. The larger it is, the more web sites are being stored on your computer. 10

Click the Security (tab)(1), Trusted sites (green checkmark)(2), then Sites (button)(3)

Remove all websites that end in.mil from the Websites: box by clicking the listed website, selecting Remove, then clicking Close Exception: If you have an Oberthur 5.5 (or G&D FIPS 201) CAC on Windows 8.1 / 8 (NOT Windows 10), you need to add websites to the zone (see Examples below - left). NOTE2: Some people will argue that AKO “should be” in the trusted sites. Here’s what I’ve been able to deduce: it IS needed with IE 6 & 7, however, if using: IE 8, 9, 10, or 11 you will be “recycled” to the AKO home page. So, IE 8, 9, 10, and 11 users REMOVE it. EXCEPT for Exception above. This is the Websites: box NOTE: Most Government owned computers will not let you access this area to make changes. 12 Examples for Oberthur 5.5 & G&D FIPS 201 CAC holders, type in, then click Add: (Mail.mil) (AKO) (DTS) (DCS) (Navy sites)

Click the Content (tab), Certificates (button) Click: Clear SSL state 13

Most people will only see 3 DOD certificates (2 with and 1 without) under the Personal (tab) Issued By (column). If you see more than 3, look at slide 23 for further instructions. Dual CAC holders will see a 4th certificate once their PIV is activated. This page is CAC Specific 14

Click the Intermediate Certification Authorities (tab). First, verify you have DOD CA-25 through DOD CA-32 under the Issued To (column) (if you don’t, go back to slide #2 and install the DoD Root Certificates again). Second, scroll down to below the DOD CA-32 and look for any of the certificates in the Certificates image below and any shown in - Cross Cert remover Automated file (you may need to run as administrator) to remove certificates Listed above (same as slide 2) : Download from MilitaryCAC (13 AUG 14 version)MilitaryCAC Download from DISA (13 AUG 14 version)DISA Issued ToIssued ByExpiration Common Policy EntrustCommon Policy VeriSign Digital ID Certificate Date is Expired Information about the Cross Cert Remover 15 Another way to remove the certificates utilizing certmgr.mscAnother way to remove the certificates utilizing certmgr.msc This guide can be used if the method above doesn’t work for you. the blue box below. IF you see any of these certificates, select it, and click Remove. If you don’t see them, select Close on this window and continue with this guide

Click the Connections (tab)(1), LAN settings (button)(2), make sure none of the boxes are checked(3) (Personal Computers only), click OK

Click the Advanced (tab), scroll to the bottom of the list, make sure that only TLS 1.0, 1.1, & 1.2 (see NOTE2 below) are checked. SSL 2.0 & 3.0 are NOT checked NOTE: Windows XP and Vista users will not see TLS 1.1 & 1.2, they are only seen on Windows 7 and above NOTE: If you are receiving the error: “Error 107 (net::ERR SSL PROTOCOL ERROR): SSL protocol error” or Unknown error you might need to leave SSL 2 checked. Very rare now 17 NOTE: The Air Force AROWS, Navy NROWS, Army’s MilSuite & ALMS Websites may need TLS 1.1 & 1.2 unchecked to be accessed. So, if you are having problems with some sites, uncheck these and try again. NOTE: “Some” computers refuse to leave TLS 1.0 checked and SSL 2.0 unchecked. If this happens, click the Reset… (button).

When using Edge in Windows 10, select options (…), then select Open with Internet Explorer 18

Compatibility View is necessary when using IE to access some government websites like: OWA / Webmail, NKO, DTS, Army Reserve Citrix / RAP, and others Look for the “torn paper” icon and click it (IE 8-10 only) Internet Explorer 11 users will not see the “torn paper.” You need to Click Tools (or “Alt” & “T” keys on your keyboard), Compatibility View Settings, and enter: “army.mil”, “osd.mil”, “navy.mil”, and “apps.mil” in the “Add this website:” box. Click Add, then Close The next slide shows images how to do this Further information regarding this issue can be read on Microsoft.com 19

Reasons to do this: The website worked before, but not now Internet Explorer 11 is your browser Add website to compatibility view Internet Explorer 11 Compatibility View with Windows 7, 8, 8.1, and mail.mil osd.mil army.mil apps.mil navy.mil An easy way to add the site is to go to the website then click Compatibility View settings. The correct website should be automatically inserted into the Add this website (box). -DoD Enterprise may need: mail.mil added -DTS needs: osd.mil added -Army Reserve Remote Access Portal (Citrix) and some other Army websites need: army.mil added -DCS (DCO replacement) needs: apps.mil added -Navy personnel need: navy.mil added

21 If you are still having issues, uncheck "Enable Enhanced Protected Mode*“ This is sometimes needed to sign evaluations on EES (Army’s OER system). See more information at NOTE: Running Enhanced Protected Mode* helps prevent attackers from installing software or modifying system settings if they manage to run exploit code. It is an extra layer of protection that locks down parts of your system that your browser ordinarily doesn’t need to use. - Unfortunately it blocks access and functionality to / on some DoD websites like HRC’s EES. To try this option, Click Tools, Internet Options, Advanced (tab)

If the previous adjustments did not work, select Reset… at the bottom of the Advanced (tab), AND what you see on the next page 22

You may need to Remove your certificates (see slide 14 for instructions on how to get to this location). Dual persona personnel will have 4 certs after they have activated their PIV certificate. NOTE2: You will receive a message stating: You cannot decrypt data encrypted using the certificates. Select: Yes This page is CAC Specific 23 NOTE: Removing certs and your CAC, then reinserting CAC is a way to test if your reader and middleware are working properly.

Your certificates “should” automatically be available to Windows when you remove and reinsert your CAC into the reader, however… If you have ActivClient x installed.. You can double click the ActivClient icon (by your clock in the lower right corner of your screen) now go to slide 26 If you don’t see it there: Windows XP, Vista, & 7 users can Click Start / Windows logo, All Programs, ActivIdentity, ActivClient, User Console. Now go to next slide Windows 7, 8 / 8.1, & 10 native users will not see an ActivClient icon, since you are not using it. This page is CAC Specific 24

Forget state for all cards in ActivClient x, this helps Dual CAC holders immediately after a PIV activation Click Tools, Advanced, Forget state for all cards (twice) DOE.JOHN.ANDREW ’s This page is CAC Specific Go to next page to Make Certificates available to Windows Make Certificates available to Windows... Forget state for all cards 25

How to make your certificates available to Windows when using ActivClient x Click Tools, Advanced, Make Certificates available to Windows DOE.JOHN.ANDREW ’s This page is CAC Specific You should see this message 26

Try these additional items if you are still having issues: Try using the 32 bit version of Internet Explorer (if you have 64 bit Windows) Please know that IE runs in 32 bit mode by default if you are using IE 10 or IE 11 in Windows 7, 8 / 8.2, & 10 Here’s how to get to the 32 bit IE in IE 9 and below: Click Start, All Programs, Internet Explorer (NOT Internet Explorer (64-bit)). NOTE: In some occasions, your time on your computer may be off by more than the server’s 5 minute limit. Please check your clock and time zone. 27

Try logging into a CAC enabled DoD website with your CAC, it “should” now work If all of the previous ideas did not work, please visit: to start troubleshooting your CAC readerhttps://militarycac.com/cacdrivers.htm 28

Presentation created and maintained by: Michael J. Danberry If you still have questions, visit: