Comodo Help
Find the desired product help
Comodo Dragon Web Browser

Comodo Dragon Web Browser

Version 80.0

English

Print Help Download Help
Privacy And Security > CertSentry
  • Comodo Dragon Web Browser - Introduction
  • System Requirements
  • Download And Install Comodo Dragon Web Browser
  • The Basics
    • Start Comodo Dragon Web Browser
    • Set Your Homepage
    • Search The Internet Using Comodo Dragon
    • Set Default Search Engine
    • Comodo Dragon Logging Policies
    • Prediction Service
    • Open Most Visited And Recently Closed Websites
    • Add Home Button To The Toolbar
    • Open Preset Pages On Startup
    • View Browsing History
    • Configure Pop-ups And Redirects
    • Set Browser Languages, Fonts And Encoding
    • Search For Important Browser Settings
    • Configure Dragon Updates
    • Manage Website Passwords
    • Import Settings From Another Browser
    • Set Dragon As Your Default Browser
  • Tabbed Browsing
    • Open A New Tab
    • Customize The Apps Page
    • Rearrange Tabs
    • Close Tabs, Windows And Comodo Dragon
    • Display / Hide Application Buttons On The Toolbar
  • Bookmarks
    • Create Bookmarks
    • Find And Edit Bookmarks
    • Manage Bookmarks
    • Import And Export Bookmarks
  • Privacy And Security
    • Delete Browsing History
    • Manage Cookies
    • Configure Site Settings In Comodo Dragon
    • Configure Advanced Settings
    • Use Comodo Dragon In Incognito Mode
    • Use Comodo Dragon In Virtual Mode
    • SSL Certificates And Secure Connections
    • SSL/HTTPS Security Settings
    • Block Insecure Content
    • Force Secure Connections
    • CertSentry
    • Manage Multiple Users
  • Downloads
    • Download A File
    • Change Download Location
    • Clear Download History
    • View Download History
  • Tools And Other Features
    • Manage Extensions
    • Zoom The Web-page
    • Form Autofill
    • Enable Or Disable Sync Settings
    • Protect Your Synced Passwords
    • Enable / Disable Malware Domain Filtering (Comodo Secure DNS)
    • Apply Themes
    • View Task Manager From Comodo Dragon
    • Search Within Page Content
    • Customize The Spell Checker
    • Manage Your Search Engines
    • View And Stop Background Pages And Applications
    • View, Save And Print PDFs
    • Keyboard And Mouse Shortcuts For Comodo Dragon
    • Website Security Indicators
    • The Share Page Button
    • Сonfigure Access Through A Web Proxy
    • Manage Protocol Handlers
    • Use The Address Bar (Omnibox)
    • Configure Media Settings
    • Configure Access To MIDI Devices
    • Configure Unsandboxed Plug-in Access Settings
    • Performance Settings
    • Use Media Downloader To Download Streaming Media
    • Cloud Print Settings
    • Set Automatic Downloads On Dragon
    • Protected Content
    • How To Add Accessibility Features To Dragon
    • Comodo Online Security Pro Extension
    • Perform Drive Search
    • Set The Distilled Page Contents
    • View The Global Media Controls On Toolbar
  • Troubleshooting
    • Errors And Crashes In Comodo Dragon
    • Display Problems In Comodo Dragon
    • Report A Bug
  • Portable Version
  • Uninstall Comodo Dragon Web Browser
  • About Comodo Dragon Web Browser

CertSentry



Introduction

Comodo CertSentry checks the revocation status of SSL certificates on websites in real-time.


Once installed, CertSentry is invoked whenever you run a application that uses the standard Microsoft CryptoAPI.


The ambitions of the application are two fold. Firstly, it is designed to implement effective, SSL revocation checking on popular Windows software such as Chrome, Internet Explorer, Dragon and Outlook. Secondly, CertSentry represents an effort to discover more information about the health of the current revocation checking infrastructure by collecting statistics about the response times of Online Certificate Status Protocol (OCSP) responders operated by Certificate Authorities (CA's). Sharing the data gathered by CertSentry with other CA's and major browser providers will, we hope, provide organizations like the Certificate Authority/Browser (CA/B) forum with the information they need to implement a viable, long term strategy regarding certificate revocation checks.


Key functionality and features:

  • Once installed, CertSentry will become the default SSL certificate revocation provider for Windows. The host application loads censentry.dll into its process space whenever the host application requests a certificate revocation check. Host applications include browsers such as Dragon, Chrome and Internet Explorer and mail applications such as Microsoft Outlook.
  • CertSentry will re-enable Online Certificate Status Protocol (OCSP) checking within Google's Chrome browser. OCSP checking was recently disabled by Google.
  • CertSentry is also designed to gather statistics on the health of the current revocation checking infrastructure. No personal or identifying data about you or your Internet usage is included in these statistics. All that is revealed is the issuing (root) CA certificate involved in the OCSP check – not the end-entity certificate of the website in question. In other words, it informs us that a revocation check was made for a certificate on an (unknown) website and that the certificate was issued by Certificate Authority X. It also tells us whether the request was answered, the speed of the response and the type of response. It does not inform us of the URL of the website on whose behalf the check was initiated. The data we receive will be enough to compare and contrast the performance and availability of each CA's revocation servers. CertSentry is designed to send it's logs to the CertSentry server every 24 hours and they can be found at the following locations:
         Windows XP 

         C:Documents and SettingsLocal SettingsApplication DataCertSentry

         Windows Vista/7 C:Windowssystem32configsystemprofileAppDataLocalLowComodoCertSentry

  • CertSentry also provides the option to 'hard fail' certificate revocation checks. Ordinarily, if a browser receives no answer to a revocation check then the browser        simply assumes the certificate is valid (not revoked) and allows the connection to proceed. This is known as a 'soft fail'. On the other hand,  browsers that are set up to 'hard fail' will treat this lack of response as meaning the certificate is invalid (revoked) and will block connections to the website. While soft fails obviously present a potential security issue, enabling a hard fail could lead to an increase in rejected connections if the OCSP responder operated by the CA cannot be contacted for technical reasons. By default, hard-fail is not enabled in CertSentry. To enable it, please add one of the following values to your Windows registry as as REG_DWORD type:

To enable "hard-fail" only for certificates issued by Comodo's CA system:

HKEY_LOCAL_MACHINE/SOFTWARE/COMODO/CertSentry/COMODOFailureMode  (value "2")

To enable "hard-fail" for all certificates from all CAs:


HKEY_LOCAL_MACHINE/SOFTWARE/COMODO/CertSentry/DefaultFailureMode  (value "2")

Please restart your system to apply your changes.
Our Products
  • Free Antivirus
  • Free Internet Security
  • Website Malware Removal
  • Free Anti-Malware
  • Anti-Spam (Free Trial)
  • Windows Antivirus
  • Antivirus for Windows 7
  • Antivirus for Windows 8
  • Antivirus for Windows 10
  • Antivirus for MAC
  • Antivirus for Linux
  • Free Endpoint Security
  • Free ModSecurity
  • Free RMM
  • Free Website Malware Scanner
  • Free Device Manager for Android
  • Free Demo
  • Network Security
  • Endpoint Protection
  • Antivirus for Android
  • Comodo Antivirus
  • Wordpress Security
Cheap CDN
  • Bootstrap CDN
  • Semantic UI CDN
  • Jquery CDN
  • CDN Plans
  • CDN
  • Free CDN
Enterprise
  • Patch Management Software
  • Patch Manager
  • Service Desk
  • Website Down
  • Endpoint Protection Solutions
  • Website Security Check
  • Remote Monitoring and Management
  • Website Security
  • Device Manager
  • ITSM
  • CRM
  • MSP
  • Android Device Manager
  • MDR Services
  • Managed IT Support Services
  • Free EDR
Free SSL Certificate
Support Partners Terms and Conditions Privacy Policy

© Comodo Group, Inc. 2025. All rights reserved.