Arise Software Arise Software Secure Access Portal
🛡

First-Time Setup

A one-off step on this computer so your remote sessions open with a single click — no warnings, no extra boxes to tick, every time after this.

⏳ Two minutes now. No more ticking boxes every time!

This is a once-on-this-computer setup. The 10 steps below install the certificate by hand — every step is a Windows dialog you see and approve, nothing runs in the background. (Want a one-click shortcut, or the full install your IT team would do? See the alternatives below the steps.)

Without this setup — every single session
  • “Unknown publisher” warning to dismiss
  • Tick Clipboard manually
  • Tick Printers manually
  • Type your username (ARISE\…) by hand
After this setup — every single session
  • Double-click the file, click Connect, enter password
  • You’re in. Clipboard works. Printer works.
  • Publisher recognized as Arise RDP Signing
  • (That’s the whole list.)
What you’re about to do: install a small certificate file (about 1 KB). It is not a program. It is a digital identity document that tells Windows: “connection files signed by Arise are safe to open.” No administrator password is required for this path.

To remove it later: download arise-rdp-untrust.cmd and double-click it — cleans the certificate and any RDP trust entries from your user account. Or contact your IT team or support@arisesoftware.co.nz and we’ll walk you through it.
1

Download the certificate file

Click the button below. Your browser saves a small file called arise-rdp-signing.cer to your Downloads folder.

⬇  Download arise-rdp-signing.cer

Your browser may show a generic “keep / discard” warning because .cer files are uncommon — choose Keep.

2

Open your Downloads folder and double-click the file

Press Win + E to open File Explorer, click Downloads in the sidebar, then double-click arise-rdp-signing.cer.

A small Windows dialog called Certificate opens, showing the publisher name and validity dates.

3

Click “Install Certificate…”

In the Certificate dialog, click the Install Certificate… button at the bottom-left.

Click the highlighted button:

🔒 Certificate ✕
📄
Certificate Information
Issued to:Arise RDP Signing
Issued by:Arise RDP Signing
Valid to:15 May 2036
4

Choose “Current User” and click Next

The Certificate Import Wizard opens. Make sure Current User is selected (this is the default), then click Next >.

No administrator password is required — the certificate is installed only for your user account.

Current User is already selected — click Next:

📄 Certificate Import Wizard ✕

Welcome to the Certificate Import Wizard

This wizard helps you copy certificates to a certificate store.

Store Location

5

Select “Place all certificates in the following store”, then click Browse

On the next screen, click the second radio button labelled Place all certificates in the following store. The text box underneath becomes editable. Click Browse….

Select the second radio, then click Browse:

📄 Certificate Import Wizard ✕

Certificate Store

Certificate stores are system areas where certificates are kept.

 
6

Pick “Trusted Root Certification Authorities” and click OK

A smaller Select Certificate Store window pops up with a list of folders. Click Trusted Root Certification Authorities so it is highlighted in blue, then click OK.

Click the highlighted folder, then OK:

📁 Select Certificate Store ✕

Select the certificate store you want to use.

📁 Personal
📁 Trusted Root Certification Authorities
📁 Enterprise Trust
📁 Intermediate Certification Authorities
📁 Active Directory User Object
📁 Trusted Publishers
7

Click Next, then Finish

The pop-up closes. You are back on the wizard with Trusted Root Certification Authorities filled into the text box. Click Next >.

The wizard shows a summary page (“Completing the Certificate Import Wizard”). Click Finish.

8

Click “Yes” on the yellow Security Warning

Windows shows a yellow-bordered warning asking if you want to install the certificate. This is expected for certificates from any internal publisher. Click Yes.

Click Yes — this is the most important click:

⚠ Security Warning ✕
⚠
You are about to install a certificate from a certification authority (CA) claiming to represent: Arise RDP Signing

Windows cannot validate that the certificate is actually from “Arise RDP Signing”. You should confirm its origin by contacting Arise. Do you want to install this certificate?

9

Click OK on “The import was successful”, then close the Certificate window

A small confirmation appears. Click OK. The wizard closes. You may also see the original Certificate window still open behind it — click OK on that too to close it.

Click OK — you’re done.

📄 Certificate Import Wizard ✕
✅ The import was successful.
10

On your next connection: tick “Remember my choices”, then Connect

Go back to the Access Portal, request a session, then open your email and double-click the AriseSecureAccess.rdp attachment. You will see a Verify the publisher of this remote connection dialog with Publisher: Arise RDP Signing.

Tick the Remember my choices for remote connections from this publisher box (below the Clipboard / Printers checkboxes), then click Connect. On most computers, ticking that box means you won’t see this dialog again — future sessions open straight to the password prompt.

Heads-up: on some office computers, your company’s settings stop Windows from remembering that tick, so the same dialog comes back every session. If that happens, just click Connect each time (your username, clipboard and printer are still ready) — or ask your IT team to do the full install below, which removes the dialog completely.

What you will see — tick the box highlighted in orange, then click Connect:

🛡 Remote Desktop Connection security warning ✕
🛡 Verify the publisher of this remote connection

This remote connection could harm your local or remote computer. Make sure that you trust the publisher before you connect.

Publisher:Arise RDP Signing
Type:Remote Desktop Connection
Remote computer:go.arisesoftware.co.nz
Gateway server:go.arisesoftware.co.nz
Allow the remote computer to access the following resources on my computer:

Changes to these options apply only to this connection launch.

Use the following credentials to connect:

arise\gdpro1235

If you forget to tick the box this time: the dialog will keep appearing each session. No harm done — just tick it next time you see it. Either way, the rest of the setup is already working from this very first session: no “Unknown publisher” warning, clipboard and printers pre-ticked, username pre-filled.

✅

You’re all set — you never need to do this again on this computer.

Future sessions open with a double-click and (on most machines) a single Connect click. No “Unknown publisher” warning. Your username is already filled in and your clipboard and printer are already enabled.

Two faster alternatives

Both install the same Arise certificate as the 10 steps above, just packaged as a small helper file that does the clicks for you. Pick whichever you prefer.

⚡

Shortcut — one-click installer

Same result as the 10-step wizard, in one click. No admin password needed. It only affects your own user account.

⬇  Download arise-rdp-trust.cmd

Windows may show a blue “Windows protected your PC” box — click More info → Run anyway. When the script finishes it prints SUCCESS in green.

⭐

Full install — removes every dialog (needs admin password)

Use this if your office computer keeps showing the “Verify the publisher” dialog every session even after one of the steps above. Installing with an admin password sets things up for the whole computer instead of just your user account — that’s the only way to fully remove the dialog on locked-down office computers.

How: download the same installer above, then right-click it in your Downloads folder and choose Run as administrator. Type the admin password if Windows asks. The script will say Mode: ADMIN at the top.

Safe to do: this only tells Windows to trust connection files from Arise. It does not trust anyone else’s files. Your IT team can see exactly what it does in the tab.

Need to undo this later? Download arise-rdp-untrust.cmd and double-click it. Removes the certificate and any settings from your user account. If you used the full admin install above, right-click the uninstaller and choose Run as administrator too — that cleans the computer-wide settings as well.

Short version: Your computer needs a familiar “stamp of approval” before it will open an RDP connection without complaining. This setup gives it that stamp — just once, for this user account, on this machine.

When you open a remote desktop file (.rdp), Windows checks whether the file has been signed by a publisher it already recognises — a bit like checking the sender’s name on a letter before you open it.

Arise signs every connection file we send you. But your computer has never heard of Arise before, so the first time it sees our signature it isn’t sure whether to trust it. That’s what causes the “Unknown publisher” warning, and why you have to tick boxes for clipboard and printers each time.

The certificate install on the Setup Guide tab tells Windows to recognise Arise as a trusted publisher. After that, Windows opens the connection file silently and correctly — your username is already filled in and your clipboard and printer are already enabled.

The setup does not give Arise any access to your computer. It only tells Windows that remote connection files signed by Arise are safe to open. If you ever want it removed, contact your IT team or email support@arisesoftware.co.nz — we’ll walk you through it in under a minute.

For sysadmins and security reviewers. Full technical detail on what is installed, why, how it works, the scope of trust it grants, how to remove it, and how to deploy it via GPO/Intune. If installing trust artefacts is prohibited entirely, the still works (extra clicks per session, no install).

What it is. A self-signed X.509 v3 certificate:

  • Subject: CN=Arise RDP Signing
  • SHA-1 thumbprint: 879BBF3F595E949E5F0AB977EE8F8C6724B9CFB0
  • Key: RSA 2048, SHA-256 signature, CAPI provider, non-exportable private key
  • Extensions: BasicConstraints = CA:TRUE, KeyUsage = DigitalSignature, KeyCertSign, EKU = 1.3.6.1.5.5.7.3.3 (Code Signing)
  • Validity: 2026-05-15 → 2036-05-15 (10 years)

Where the private key lives. Only in Cert:\LocalMachine\My on the Arise portal server (go.arisesoftware.co.nz, 103.96.110.15). The AriseGuard ASP.NET Core process invokes rdpsign.exe against the private key to sign each per-session .rdp file at request time. The private key never leaves that machine.

Why CA:TRUE. mstsc’s chain validation refuses to anchor on a non-CA certificate even when it’s in Trusted Root Certification Authorities. Without CA:TRUE, the “Verify the publisher” dialog appears forever and the “Remember my choices” tick fails to persist. With CA:TRUE, chain validation accepts the cert as a trust anchor and publisher trust can be established normally.

Why self-signed. A publicly trusted OV code-signing cert (e.g. ssl.com eSigner, Certum Cloud Signing) is on the roadmap and would remove client-side install entirely. Until that’s in place, the self-signed cert + this one-time per-machine install is the working path.

Two layers of trust govern whether mstsc shows the verify dialog for a signed .rdp file:

  1. Chain trust (certificate stores) decides whether the file’s publisher is recognised. Cert must validate via a trusted root and be trusted as a publisher. Without this you get the orange “Unknown publisher” warning. With it you get publisher name shown, Clipboard/Printers pre-ticked, username pre-filled.
  2. Bypass list (registry policy) decides whether the yellow “Verify the publisher” dialog appears at all. The publisher’s thumbprint must be listed in SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\TrustedCertThumbprints under either HKCU or HKLM, and AllowSignedFiles=1 (DWORD) must also be present in the same key.

The three install paths and what each touches:

10-step manual wizard — no admin
Cert stores: CurrentUser\Root
Registry: none. (mstsc’s “Remember my choices” tick later attempts to write the HKCU bypass entry on first session.)
arise-rdp-trust.cmd (user mode) — no admin
Cert stores: CurrentUser\Root + CurrentUser\TrustedPublisher
Registry key: HKCU\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
  • TrustedCertThumbprints = 879BBF3F…
  • AllowSignedFiles = 1 (DWORD)
arise-rdp-trust.cmd (Run as admin) — requires UAC
Cert stores: LocalMachine\Root + LocalMachine\TrustedPublisher
Registry key: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
  • TrustedCertThumbprints = 879BBF3F…
  • AllowSignedFiles = 1 (DWORD)

Why the script’s registry write sometimes fails. Many MDMs and AD GPOs lock the Policies subtree under HKCU with an ACL that denies user write — precisely because that key is meant to be set by management policy, not by user-mode software. On such machines:

  • Cert-store writes succeed (chain trust works → publisher recognised, redirects + username work)
  • HKCU registry write fails → bypass list not populated → verify dialog appears every session
  • The “Remember my choices” tick targets the same locked HKCU key and also silently fails
  • Running the script as admin writes to HKLM instead, which the same MDMs typically permit (since HKLM is intentionally writable by admins for org-managed apps), giving the “no dialog ever” result

The script detects admin via WindowsPrincipal.IsInRole(WindowsBuiltInRole.Administrator) and reports Mode: ADMIN or Mode: USER, then prints either SUCCESS, PARTIAL SUCCESS, or FAILED based on which writes actually persisted.

What it allows: mstsc honours signed-`.rdp` settings (redirect flags, pre-filled username, gateway settings) and skips the verify-publisher dialog — only for files whose signing-cert thumbprint matches the explicit allowlist value 879BBF3F…4B9CFB0.

What it does NOT allow:

  • Any other signed .rdp file from a different publisher → still prompts (their thumbprint isn’t in TrustedCertThumbprints)
  • Unsigned .rdp files → still get “Unknown publisher”
  • Anything outside mstsc — the bypass list only affects mstsc.exe’s dialog logic
  • The cert has EKU = Code Signing only — not Server Auth, Client Auth, S/MIME, or Document Signing. Windows will refuse to use it for those purposes even though it’s in Trusted Root

Theoretical concern with CA:TRUE. Because the cert has CA:TRUE and lives in Trusted Root, in principle Arise could issue further certs that chain off this root and have them trusted by your machines for whatever EKUs Arise puts on them. The mitigation is that the private key never leaves 103.96.110.15\Cert:\LocalMachine\My (non-exportable), and the only thing on that machine that uses the key is the AriseGuard portal’s rdpsign.exe invocation. If that’s an unacceptable risk in your environment, deploy only the cert (Trusted Root) and skip the bypass-list registry write — users get the verify dialog once and tick “Remember my choices”, no scripts run.

Goal: push the cert + bypass-list policy to all domain-joined or Intune-managed machines so users never see the install prompt or the verify dialog.

Group Policy (domain-joined):

  1. Computer Configuration → Windows Settings → Security Settings → Public Key Policies → Trusted Root Certification Authorities → Import → select arise-rdp-signing.cer
  2. Computer Configuration → Preferences → Windows Settings → Registry → New Registry Item:
    • Hive: HKEY_LOCAL_MACHINE
    • Key: SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services
    • Value name: TrustedCertThumbprints
    • Value type: REG_SZ
    • Value data: 879BBF3F595E949E5F0AB977EE8F8C6724B9CFB0
  3. Repeat: AllowSignedFiles = 1 (DWORD) in the same key

Intune (Endpoint Manager):

  • Devices → Configuration profiles → Trusted certificate profile, upload arise-rdp-signing.cer, destination Computer certificate store - Root
  • Devices → Configuration profiles → Settings catalog or Custom (OMA-URI) profile with two registry settings targeting the HKLM Terminal Services policy key shown above

After deployment, no per-user install is needed. Users get the same “no dialog ever” result as the admin install path described in the Setup Guide.

Contact support@arisesoftware.co.nz for the .cer file out-of-band, or fetch it directly from /AriseGuard/files/arise-rdp-signing.cer (797 bytes, SHA-1 thumbprint as above).

Scripted: arise-rdp-untrust.cmd detects admin and cleans accordingly:

  • User mode: removes the cert from CurrentUser\Root and CurrentUser\TrustedPublisher, deletes the HKCU policy values, clears any HKCU\SOFTWARE\Microsoft\Terminal Server Client\PublisherBypassList entries set by “Remember my choices”. Warns if LocalMachine entries are also present (won’t touch them without admin).
  • Admin mode: all of the above PLUS removes the cert from LocalMachine\Root + LocalMachine\TrustedPublisher and the HKLM policy values.

Manual:

  • Cert: certmgr.msc (user) or certlm.msc (machine) → Trusted Root + Trusted Publishers → find Arise RDP Signing → right-click → Delete
  • Registry: delete HKCU|HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\TrustedCertThumbprints and AllowSignedFiles. Delete the empty Terminal Services key if nothing else lives there.

After removal, the next .rdp session reverts to “Unknown publisher” warning + manual Clipboard/Printers ticks + manual username entry, but functionally works.

Short answer: on the roadmap. A publicly trusted OV code-signing certificate would chain to roots Windows already trusts, so no client-side cert install would be needed at all — users would just get the verify-publisher dialog once and tick “Remember my choices”.

Candidates evaluated:

  • SSL.com eSigner — OV code-signing cert with cloud HSM. Confirmed to work with the rdpsign.exe signing path.
  • Certum SimplySign — cloud HSM. Need to verify compatibility before purchase.
  • Azure Trusted Signing (formerly Code Signing) — not available to NZ-registered orgs as of 2026-05.

Switching the codebase is trivial: only the RdpSignCertificateThumbprint in appsettings.Production.json changes. Both rdpsign.exe and the cert-store lookup are identical regardless of cert origin.

Note: Without the setup you will need to follow these steps every single time you start a session. The eliminates all of this permanently.

After you open your email and double-click the AriseSecureAccess.rdp attachment, here is exactly what to do:

1

A warning appears: “The publisher of this remote connection can’t be identified.” This is expected — do not be alarmed.

2

Tick the Clipboard and Printers checkboxes so you can copy/paste and print during your session.

3

Click Connect.

What you will see — tick the boxes, then click Connect:

🛡 Remote Desktop Connection ✕
⚠
The publisher of this remote connection can’t be identified. Do you want to connect anyway? This remote connection could harm your local or remote computer. Do not connect unless you know where this connection came from or have used it before.
Publisher:Unknown publisher
Type:Remote Desktop Connection
Remote computer:go.arisesoftware.co.nz
Gateway server:go.arisesoftware.co.nz
Allow this remote connection to access the following resources on my computer:
4

If the username field is empty, type ARISE\ followed by your username (e.g. ARISE\gdpro1235), then enter the password from your email and click OK.

Type your username and password, then click OK:

🔐 Windows Security ✕

Enter your credentials

These credentials will be used to connect to go.arisesoftware.co.nz.

👤
ARISE\gdpro1235
🔒
••••••••••
5

You are connected. The password expires 15 minutes after it was issued, so connect promptly after receiving your email.

Changed your mind? You can do the one-time setup at any point — just click the Setup Guide tab above and follow the 10 steps.