If you go to IE -> Internet Options -> Content -> Certificates -> Trusted Root Certification Authorities.
Now Click on some CA certificates and click on Advanced
You can add properties to the certificate. What exactly is this for?
Does this mean that if a certificate doesn't have 'Server Authentication' property, the client can still authorize it for that purpose if he chooses to do so?
Is this a security issue - i.e. can you you write an ActiveX control or Applet on which if a user clicks, it will turn on this property?