Toon posts:

Macros enablen with High security

Pagina: 1
Acties:

Verwijderd

Topicstarter
Ha,

Tgaat hier om office XP

We kregen bij ons bedrijf een probleem binnen, wat al een poosje open staat. Overal zoeken, ik word er markant gek van..ik hoop dat misschien 1 van jullie dit al eens eerder heeft gehad of ervaring ermee heeft. Het gaat over Macros in office, zelfgemaakten, die op high security level gewoon geaccepteerd moeten worden.....

we need a digital signature in order to sign embeded macros in office xp (word) as from a trusted source. This will enable the user of the (locked) template to run the macro's on a high security level. A self created signature will not work. This will still require the user to set the security to medium level.

signature should preferably not be limited to a machine or person.

Signature will be used in document templates.
The macros are typically used to invoke user forms or field updates in order to speed up the document creation stage.

Hopenlijk heef tiemand hier een oplossing voor....

[ Voor 2% gewijzigd door Verwijderd op 07-12-2005 14:57 . Reden: Office versie erbij gezet. ]


  • Gulf_5
  • Registratie: Maart 2004
  • Laatst online: 20-10-2024

Gulf_5

Lucht-v/w-aardig

van de Micro$soft site:
ik krijg een pesthumeur van microsoft verbasteringen, vooral van die afgezaagde

Digitally signing a macro
You can use the program Selfcert.exe to sign macros or templates you create for your own personal use. Certificates created for use on your own computer are accepted only for the computer the certificate was created on.

Selfcert.exe calls Makecert.exe; both programs are available with Office in the Office 2003 folder and are not available with the Microsoft Office 2003 Editions Resource Kit. However, signing a macro, template, or file with Selfcert.exe does not provide a high enough level of authentication to provide reliable tracking of the source of the file back to its developer. Therefore, if a file you sign with a signature created from Selfcert is distributed to other users, they will not be able to accept your certificate if they are running High security, because the certificate does not have a high enough security level to authenticate who you are. Only a certificate issued by a certificate authority can be used to provide a distributable certificate and signature to others and still pass through Medium and High security levels in Office.

There are limitations to the deployment of Selfcert.exe certificates applied to a macro when macro security is set to High:

Setting security to Low and then running the macro does not register the certificate in the trusted sources list.
Security must be set to Medium or High before any certificates are posted to the trusted Trust Publishers list. In cases where security is set to High on all computers, a Selfcert.exe-signed macro can be deployed, but it does not have a secure enough certificate for use by other users who are running with the High security level. Only a certificate issued by a certificate authority can be used to provide a distributable certificate and signature to others and still pass through Medium and High security levels in Office

Selfcert.exe-issued certificates are not managed by a certificate authority and do not provide for certificate revocation checking.
Selfcert.exe does not provide a certificate of trust with a traceable signature.


Hopelijk heb je hier wat aan.

P.S.: dit was de eerste hit in Google, http://www.google.com/search?q=high%20security%20macro%20signature ;)

[ Voor 3% gewijzigd door Lustucru op 07-12-2005 15:26 ]

iets met foto's...


Verwijderd

Topicstarter
Thnx....Even aandachtig doorgaan lezen..mn engels is uitermate slecht...:) ik post wel hoe en wat..

  • CoRrRan
  • Registratie: Juli 2000
  • Laatst online: 02-06 20:28

CoRrRan

Don't Panic!!!

Zoek eens in de help van MS Office op "Security" (of mogelijk "Beveiliging" in het Nederlands) en kijk of je de entry "About Macro Security" kunt vinden. Daar staat precies in wanneer macro's door de High Security setting heenkomen.

Ik weet er verder het fijne niet van, maar je moet dus de makers van de macros in de "Trusted Sources" lijst krijgen (ik geloof dat die te vinden is door "Internet Options" van IE te openen en naar het tabblad "Content" te gaan en op "Certificates..." te klikken). Daar zou je dan Certificaten van gebruikers (of instanties?) moeten kunnen importeren. Heb het zelf echter nog nooit gedaan, maar misschien iemand anders wel.

Plaats anders een vraag in de newsgroep microsoft.public.excel. Daar zitten een heleboel mensen met heel veel kennis over Excel, dus waarschijnlijk ook over macros en certificaten. (Of mogelijk microsoft.public.security(.homeusers))

-- == Alta Alatis Patent == --


Verwijderd

Topicstarter
Ik heb het nu wat duidelijker nog ontvangen,

Je kunt niet alle gebruikers af om een macro trusted te maken. Nu moet iedereen zijn security omlaag halen om het te laten werken. Erger is nog dat ze niet gewaarschuwd worden dat er een macor bestaat.

Dit is hier in het bedrijfsnetwerk, voor buiten af hoef dit niet.

  • F_J_K
  • Registratie: Juni 2001
  • Niet online

F_J_K

Moderator CSA/PB/AI

Front verplichte underscores

Waarom de security omlaag halen? Aangenomen dat je in een domein hangt: geef op de juiste server een certificaat uit en gebruik die om te signen. Binnen je netwerk kan je best een eigen - zoals het in je topicstart wordt genoemd - trusted source definieren.

offtopic:
Je doet de support voor engelstalige mensen maar kunt slecht engels lezen :? Ik zou gaan nadenken over of een cursus of ander werk ;)

'Multiple exclamation marks,' he went on, shaking his head, 'are a sure sign of a diseased mind' (Terry Pratchett, Eric)


  • Gulf_5
  • Registratie: Maart 2004
  • Laatst online: 20-10-2024

Gulf_5

Lucht-v/w-aardig

@ bartboerendans: hoe heet het bedrijf waar je werkt ? toevallig hadden we hier namelijk op precies dezelfde dag hetzelfde probleem, dus het zou zomaar kunnen dat je het probleem van een van mijn collega's zit op te lossen :+

iets met foto's...

Pagina: 1