First-Time Setup
A one-off step on this computer so your remote sessions open with a single click — no warnings, no extra boxes to tick, every time after this.
This is a once-on-this-computer setup. The 10 steps below install the certificate by hand — every step is a Windows dialog you see and approve, nothing runs in the background. (Want a one-click shortcut, or the full install your IT team would do? See the alternatives below the steps.)
- “Unknown publisher” warning to dismiss
- Tick Clipboard manually
- Tick Printers manually
- Type your username (
ARISE\…) by hand
- Double-click the file, click Connect, enter password
- You’re in. Clipboard works. Printer works.
- Publisher recognized as Arise RDP Signing
- (That’s the whole list.)
To remove it later: download arise-rdp-untrust.cmd and double-click it — cleans the certificate and any RDP trust entries from your user account. Or contact your IT team or support@arisesoftware.co.nz and we’ll walk you through it.
Download the certificate file
Click the button below. Your browser saves a small file called arise-rdp-signing.cer to your Downloads folder.
⬇ Download arise-rdp-signing.cerYour browser may show a generic “keep / discard” warning
because .cer files are uncommon — choose Keep.
Open your Downloads folder and double-click the file
Press Win + E to open File Explorer, click Downloads in the sidebar, then double-click arise-rdp-signing.cer.
A small Windows dialog called Certificate opens, showing the publisher name and validity dates.
Click “Install Certificate…”
In the Certificate dialog, click the Install Certificate… button at the bottom-left.
Click the highlighted button:
Choose “Current User” and click Next
The Certificate Import Wizard opens. Make sure Current User is selected (this is the default), then click Next >.
No administrator password is required — the certificate is installed only for your user account.
Current User is already selected — click Next:
Welcome to the Certificate Import Wizard
This wizard helps you copy certificates to a certificate store.
Store Location
Select “Place all certificates in the following store”, then click Browse
On the next screen, click the second radio button labelled Place all certificates in the following store. The text box underneath becomes editable. Click Browse….
Select the second radio, then click Browse:
Certificate Store
Certificate stores are system areas where certificates are kept.
Pick “Trusted Root Certification Authorities” and click OK
A smaller Select Certificate Store window pops up with a list of folders. Click Trusted Root Certification Authorities so it is highlighted in blue, then click OK.
Click the highlighted folder, then OK:
Select the certificate store you want to use.
Click Next, then Finish
The pop-up closes. You are back on the wizard with Trusted Root Certification Authorities filled into the text box. Click Next >.
The wizard shows a summary page (“Completing the Certificate Import Wizard”). Click Finish.
Click “Yes” on the yellow Security Warning
Windows shows a yellow-bordered warning asking if you want to install the certificate. This is expected for certificates from any internal publisher. Click Yes.
Click Yes — this is the most important click:
Windows cannot validate that the certificate is actually from “Arise RDP Signing”. You should confirm its origin by contacting Arise. Do you want to install this certificate?
Click OK on “The import was successful”, then close the Certificate window
A small confirmation appears. Click OK. The wizard closes. You may also see the original Certificate window still open behind it — click OK on that too to close it.
Click OK — you’re done.
On your next connection: tick “Remember my choices”, then Connect
Go back to the Access Portal,
request a session, then open your email and double-click the
AriseSecureAccess.rdp attachment.
You will see a Verify the publisher of this remote connection
dialog with Publisher: Arise RDP Signing.
Tick the Remember my choices for remote connections from this publisher box (below the Clipboard / Printers checkboxes), then click Connect. On most computers, ticking that box means you won’t see this dialog again — future sessions open straight to the password prompt.
Heads-up: on some office computers, your company’s settings stop Windows from remembering that tick, so the same dialog comes back every session. If that happens, just click Connect each time (your username, clipboard and printer are still ready) — or ask your IT team to do the full install below, which removes the dialog completely.
What you will see — tick the box highlighted in orange, then click Connect:
This remote connection could harm your local or remote computer. Make sure that you trust the publisher before you connect.
Changes to these options apply only to this connection launch.
Use the following credentials to connect:
arise\gdpro1235
If you forget to tick the box this time: the dialog will keep appearing each session. No harm done — just tick it next time you see it. Either way, the rest of the setup is already working from this very first session: no “Unknown publisher” warning, clipboard and printers pre-ticked, username pre-filled.
You’re all set — you never need to do this again on this computer.
Future sessions open with a double-click and (on most machines) a single Connect click. No “Unknown publisher” warning. Your username is already filled in and your clipboard and printer are already enabled.
Two faster alternatives
Both install the same Arise certificate as the 10 steps above, just packaged as a small helper file that does the clicks for you. Pick whichever you prefer.
Shortcut — one-click installer
Same result as the 10-step wizard, in one click. No admin password needed. It only affects your own user account.
⬇ Download arise-rdp-trust.cmdWindows may show a blue “Windows protected your PC” box — click More info → Run anyway. When the script finishes it prints SUCCESS in green.
Full install — removes every dialog (needs admin password)
Use this if your office computer keeps showing the “Verify the publisher” dialog every session even after one of the steps above. Installing with an admin password sets things up for the whole computer instead of just your user account — that’s the only way to fully remove the dialog on locked-down office computers.
How: download the same installer above, then right-click it in your Downloads folder and choose Run as administrator. Type the admin password if Windows asks. The script will say Mode: ADMIN at the top.
Safe to do: this only tells Windows to trust connection files from Arise. It does not trust anyone else’s files. Your IT team can see exactly what it does in the tab.
Need to undo this later? Download arise-rdp-untrust.cmd and double-click it. Removes the certificate and any settings from your user account. If you used the full admin install above, right-click the uninstaller and choose Run as administrator too — that cleans the computer-wide settings as well.
When you open a remote desktop file (.rdp),
Windows checks whether the file has been signed by a publisher it already recognises
— a bit like checking the sender’s name on a letter before you open it.
Arise signs every connection file we send you. But your computer has never heard of Arise before, so the first time it sees our signature it isn’t sure whether to trust it. That’s what causes the “Unknown publisher” warning, and why you have to tick boxes for clipboard and printers each time.
The certificate install on the Setup Guide tab tells Windows to recognise Arise as a trusted publisher. After that, Windows opens the connection file silently and correctly — your username is already filled in and your clipboard and printer are already enabled.
The setup does not give Arise any access to your computer. It only tells Windows that remote connection files signed by Arise are safe to open. If you ever want it removed, contact your IT team or email support@arisesoftware.co.nz — we’ll walk you through it in under a minute.
What it is. A self-signed X.509 v3 certificate:
- Subject:
CN=Arise RDP Signing - SHA-1 thumbprint:
879BBF3F595E949E5F0AB977EE8F8C6724B9CFB0 - Key: RSA 2048, SHA-256 signature, CAPI provider, non-exportable private key
- Extensions:
BasicConstraints = CA:TRUE,KeyUsage = DigitalSignature, KeyCertSign,EKU = 1.3.6.1.5.5.7.3.3(Code Signing) - Validity: 2026-05-15 → 2036-05-15 (10 years)
Where the private key lives. Only in
Cert:\LocalMachine\My on the Arise portal server
(go.arisesoftware.co.nz, 103.96.110.15).
The AriseGuard ASP.NET Core process invokes rdpsign.exe
against the private key to sign each per-session .rdp
file at request time. The private key never leaves that machine.
Why CA:TRUE. mstsc’s chain validation refuses to
anchor on a non-CA certificate even when it’s in
Trusted Root Certification Authorities. Without
CA:TRUE, the “Verify the publisher” dialog
appears forever and the “Remember my choices” tick fails
to persist. With CA:TRUE, chain validation accepts the cert
as a trust anchor and publisher trust can be established normally.
Why self-signed. A publicly trusted OV code-signing cert (e.g. ssl.com eSigner, Certum Cloud Signing) is on the roadmap and would remove client-side install entirely. Until that’s in place, the self-signed cert + this one-time per-machine install is the working path.
Two layers of trust govern whether mstsc shows the verify
dialog for a signed .rdp file:
- Chain trust (certificate stores) decides whether the file’s publisher is recognised. Cert must validate via a trusted root and be trusted as a publisher. Without this you get the orange “Unknown publisher” warning. With it you get publisher name shown, Clipboard/Printers pre-ticked, username pre-filled.
- Bypass list (registry policy) decides whether the
yellow “Verify the publisher” dialog appears at all.
The publisher’s thumbprint must be listed in
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\TrustedCertThumbprintsunder either HKCU or HKLM, andAllowSignedFiles=1 (DWORD)must also be present in the same key.
The three install paths and what each touches:
CurrentUser\RootRegistry: none. (mstsc’s “Remember my choices” tick later attempts to write the HKCU bypass entry on first session.)
arise-rdp-trust.cmd (user mode)
— no admin
CurrentUser\Root +
CurrentUser\TrustedPublisherRegistry key:
HKCU\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services•
TrustedCertThumbprints = 879BBF3F…•
AllowSignedFiles = 1 (DWORD)
arise-rdp-trust.cmd (Run as admin)
— requires UAC
LocalMachine\Root +
LocalMachine\TrustedPublisherRegistry key:
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services•
TrustedCertThumbprints = 879BBF3F…•
AllowSignedFiles = 1 (DWORD)
Why the script’s registry write
sometimes fails. Many MDMs and AD GPOs lock the
Policies subtree under HKCU with an ACL that denies user
write — precisely because that key is meant to be set by management
policy, not by user-mode software. On such machines:
- Cert-store writes succeed (chain trust works → publisher recognised, redirects + username work)
- HKCU registry write fails → bypass list not populated → verify dialog appears every session
- The “Remember my choices” tick targets the same locked HKCU key and also silently fails
- Running the script as admin writes to HKLM instead, which the same MDMs typically permit (since HKLM is intentionally writable by admins for org-managed apps), giving the “no dialog ever” result
The script detects admin via
WindowsPrincipal.IsInRole(WindowsBuiltInRole.Administrator)
and reports Mode: ADMIN or Mode: USER, then
prints either SUCCESS, PARTIAL SUCCESS, or
FAILED based on which writes actually persisted.
What it allows: mstsc honours signed-`.rdp` settings
(redirect flags, pre-filled username, gateway settings) and skips the
verify-publisher dialog — only for files whose
signing-cert thumbprint matches the explicit allowlist value
879BBF3F…4B9CFB0.
What it does NOT allow:
- Any other signed
.rdpfile from a different publisher → still prompts (their thumbprint isn’t inTrustedCertThumbprints) - Unsigned
.rdpfiles → still get “Unknown publisher” - Anything outside mstsc — the bypass list only affects
mstsc.exe’s dialog logic - The cert has
EKU = Code Signingonly — not Server Auth, Client Auth, S/MIME, or Document Signing. Windows will refuse to use it for those purposes even though it’s inTrusted Root
Theoretical concern with CA:TRUE. Because the cert has
CA:TRUE and lives in Trusted Root, in principle
Arise could issue further certs that chain off this root and have them
trusted by your machines for whatever EKUs Arise puts on them. The
mitigation is that the private key never leaves
103.96.110.15\Cert:\LocalMachine\My (non-exportable), and
the only thing on that machine that uses the key is the AriseGuard
portal’s rdpsign.exe invocation. If that’s an
unacceptable risk in your environment, deploy only the cert (Trusted Root)
and skip the bypass-list registry write — users get the verify
dialog once and tick “Remember my choices”, no scripts run.
Goal: push the cert + bypass-list policy to all domain-joined or Intune-managed machines so users never see the install prompt or the verify dialog.
Group Policy (domain-joined):
- Computer Configuration → Windows Settings → Security
Settings → Public Key Policies → Trusted Root Certification
Authorities → Import → select
arise-rdp-signing.cer - Computer Configuration → Preferences → Windows Settings
→ Registry → New Registry Item:
- Hive:
HKEY_LOCAL_MACHINE - Key:
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services - Value name:
TrustedCertThumbprints - Value type:
REG_SZ - Value data:
879BBF3F595E949E5F0AB977EE8F8C6724B9CFB0
- Hive:
- Repeat:
AllowSignedFiles = 1 (DWORD)in the same key
Intune (Endpoint Manager):
- Devices → Configuration profiles → Trusted certificate
profile, upload
arise-rdp-signing.cer, destination Computer certificate store - Root - Devices → Configuration profiles → Settings catalog or Custom (OMA-URI) profile with two registry settings targeting the HKLM Terminal Services policy key shown above
After deployment, no per-user install is needed. Users get the same “no dialog ever” result as the admin install path described in the Setup Guide.
Contact support@arisesoftware.co.nz
for the .cer file out-of-band, or fetch it directly from
/AriseGuard/files/arise-rdp-signing.cer
(797 bytes, SHA-1 thumbprint as above).
Scripted:
arise-rdp-untrust.cmd
detects admin and cleans accordingly:
- User mode: removes the cert from
CurrentUser\RootandCurrentUser\TrustedPublisher, deletes the HKCU policy values, clears anyHKCU\SOFTWARE\Microsoft\Terminal Server Client\PublisherBypassListentries set by “Remember my choices”. Warns if LocalMachine entries are also present (won’t touch them without admin). - Admin mode: all of the above PLUS removes the cert from
LocalMachine\Root+LocalMachine\TrustedPublisherand the HKLM policy values.
Manual:
- Cert:
certmgr.msc(user) orcertlm.msc(machine) → Trusted Root + Trusted Publishers → find Arise RDP Signing → right-click → Delete - Registry: delete
HKCU|HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\TrustedCertThumbprintsandAllowSignedFiles. Delete the emptyTerminal Serviceskey if nothing else lives there.
After removal, the next .rdp session reverts to
“Unknown publisher” warning + manual Clipboard/Printers
ticks + manual username entry, but functionally works.
Short answer: on the roadmap. A publicly trusted OV code-signing certificate would chain to roots Windows already trusts, so no client-side cert install would be needed at all — users would just get the verify-publisher dialog once and tick “Remember my choices”.
Candidates evaluated:
- SSL.com eSigner — OV code-signing cert with
cloud HSM. Confirmed to work with the
rdpsign.exesigning path. - Certum SimplySign — cloud HSM. Need to verify compatibility before purchase.
- Azure Trusted Signing (formerly Code Signing) — not available to NZ-registered orgs as of 2026-05.
Switching the codebase is trivial: only the
RdpSignCertificateThumbprint in
appsettings.Production.json changes. Both
rdpsign.exe and the cert-store lookup are identical
regardless of cert origin.
After you open
your email and double-click the
AriseSecureAccess.rdp
attachment, here is exactly what to do:
A warning appears: “The publisher of this remote connection can’t be identified.” This is expected — do not be alarmed.
Tick the Clipboard and Printers checkboxes so you can copy/paste and print during your session.
Click Connect.
What you will see — tick the boxes, then click Connect:
If the username field is empty, type ARISE\ followed by your username (e.g. ARISE\gdpro1235), then enter the password from your email and click OK.
Type your username and password, then click OK:
Enter your credentials
These credentials will be used to connect to go.arisesoftware.co.nz.
You are connected. The password expires 15 minutes after it was issued, so connect promptly after receiving your email.