Re: SSL - long, interesting question- I'm completely frustrated

From: Bernard (qbernard_at_hotmail.com)
Date: 07/18/03


Date: Fri, 18 Jul 2003 11:56:29 +0800


Do you have anything in the log ?

the problem here is that your cert work with IE
but not the rest, which is weird and hard to
troubleshoot.

-- 
Regards,
Bernard Cheah
http://support.microsoft.com/
Please respond to newsgroups only ...
"derik" <d_prid@yahoo.com> wrote in message
news:034e01c34cb4$d3e4fe50$a601280a@phx.gbl...
> Running IIS 5.0 on XP
>
> I originally installed a self-signed certificate (signed
> via OpenSSL since Certificate Services doesn't appear to
> be available to pro XP.)
>
> When I tried viewing the site using https with IE running
> on the server itself, got a message telling me the CA
> wasn't trusted, clicked through, and got to the web page
> perfectly.
>
> When I tried accessing from a test computer, the broswers
> (Mozilla, Netscape, and IE) all time out. ("There was no
> response. The server could be down or is not
> responding. ")
>
> The server log shows the requests from the browser
> running on the server. Served up on port 443 beautifully.
> No entries show up in the log from the test browsers
> trying to connect via https (though they do show up in
> the logs if i try regular http.)
>
> I ran SSL Diagnostics, and the only error was:
> Verifying server certificate, it might take a while...
> #WARNING:Error 0x800b0109 : A certificate chain
> processed, but terminated in a root certificate which is
> not trusted by the trust provider
> #WARNING:Error 0x80092013
>
> I didn't think this was causing the problem, but I
> removed the certificate and tried a trial certificate
> from VeriSign. (They use a weird demo CA that you have to
> add to your browser.) Without adding the weird CA to an
> IE browswer running on the server, I click through
> warnings and get to the web page. After adding the weird
> CA to the test computer's browser, I get the same "no
> response" error. (The trial VeriSign certificate also
> gives me the same SSL Diagnostics error.)
>
> Following some of the knowledge base articles, I used
> netstat to verify the server is listening on 443. I also
> used tracert to check the path from the server to the
> test machine. I'm at xx.xx.2.113, and its at xx.xx.0.118,
> with only xx.xx.0.1 intervening. Even though telneting to
> the xx.xx.0.1 on port 443 as instructed in the kb article
> failed, it also failed on port 80, and i know I can see
> regular http addresses on the server from the client.
> Furthermore, both client and server can see https sites
> elsewhere, leading me to think there isn't a firewall
> somewhere blocking port 443.
>
> I don't think the certificate is the problem, so it must
> be a setting somewhere, since i can see http sites on the
> server using the test machine, just not https. But, the
> fact that the test machine requests don't even show up in
> the logs makes me think otherwise.
>
> anyone have any ideas?? I apologize for posting this
> problem again, but I've tried a few new things and have
> run out of ideas.
>
> -Derik


Relevant Pages

  • Re: RWW with no https
    ... Speaking about MS IIS as a web server, in HTTP, one can run multiple ... "host headers" and run all sites on the default port 80. ... to workstations, runs on port 4125, which is dynamically opened by the SBS ... HTTP why cant you do the same with HTTPS? ...
    (microsoft.public.windows.server.sbs)
  • Re: Not able to connect to SBS using both domain mane or IP remote
    ... >>> connection using SBS. ... >>> Certificate but it's still not working. ... >>> but not to the server or any of the services. ... >> Your server is answering on port 25, ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW with no https
    ... Sorry for the confusion but someone did a port scan on me and found I ... The SBS server we would like to have RWW ... work without using HTTPS but it seems this is not possible and or I ... "Yes I use Kerio for the 75GB limitation ...
    (microsoft.public.windows.server.sbs)
  • Re: Switching from http to https
    ... The certificate was installed to change the site along with the ... When trying to connect to the https ... site, I get a page cannot be displayed, cannot connect to server or DNS ... Port 443 is being used by IIS. ...
    (microsoft.public.inetserver.iis.security)
  • Re: RWW with no https
    ... Change your ports for Kerio, using the instructions he provided, or get a different static IP for RWW ... Windows Small Business Server 2008 Unleashed ... running Https, I still have http open and free to use where ever. ... >> port but going to port 8080. ...
    (microsoft.public.windows.server.sbs)

Quantcast