Re: 2 SSL certs for 1 IIS site?

From: Jerry III (jerryiii_at_hotmail.com)
Date: 11/26/03


Date: Wed, 26 Nov 2003 12:07:07 -0800

Andrew, this is not completely accurate, not only each SSL certificate needs
its own IP but it actually needs its own web site. IIS does not allow you to
assign certificates on an IP basis, you can only have a single certificate
per web site, no matter how many IP addresses that web site has. So if you
want to create multiple SSL identities for your web site you actually have
to create two sites in IIS.

Jerry

""Andrew Davis [MS]"" <adavis@online.microsoft.com> wrote in message
news:MGBFl$EtDHA.2124@cpmsftngxa06.phx.gbl...
> Keith is right on. Each Certificate will need it's own IP address.
>
> Yes this will work for load balancing as well and you should be able use
> the same certificate on each of the servers. For example the "owa"
> certificate can be installed on Server A and Server B for each of the owa
> sites, and the "webmail" certificate can be installed on Server A and
> Server B for each of the webmail sites.
>
> DNS resolution will forward request for owa to the NLB IP address which
> will then forward to the Virtual IP of either the owa site on Server A or
> Server B.
>
> 219277 Load Balancing HTTP with WLBS
> http://support.microsoft.com/?id=219277
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> Thanks!
> ~Andrew Davis
> Microsoft PSS Security
>
> >From: "Keith W. McCammon" <km@km.com>
> >Subject: Re: 2 SSL certs for 1 IIS site?
> >Date: Tue, 25 Nov 2003 15:20:37 -0500
> >No, but you can create another site pointing to the same web root, with
the
> >same config, and apply the certificate for the other common name to that
> >site.
>
> >"J Yue" <jasperyue@msn.com> wrote in message
> >news:uUsrm74sDHA.2392@TK2MSFTNGP10.phx.gbl...
> > We have an IIS site with a SSL cert installed.
> > We are setting up a new extra URL and a new cert to access this site and
> > needed SSL for it.
> > Can we configure IIS to accept 2 certs for the same site? so you will
be
> > getting SSL no matter which URL you use to get to the site.
> >
> >Will this work if i take it to the next level: duplicate the same setup
to
> >another server and use windows network load balancing.
> >That is:
> >Both URL will deliver the request to either one of the servers and serve
> the
> >same content??
> >1. http://owa
> >2. http://webmail
> >Server A: OWA1
> >Site #1: header = owa, port 80/443
> >Site #2: header = webmail, port 80/443
> >Server B: OWA2
> >Site #1: header = owa, port 80/443
> >Site #2: header = webmail, port 80/443
> >
> > Thanks
> > -jas
>



Relevant Pages

  • RE: SSL MITM not on port 443
    ... Have you ever done what you're trying to do on a "normal" SSL web ... My recommendation would be to set up a web server in your lab ... hopes that the client will accept that certificate. ... SSL MITM not on port 443 ...
    (Pen-Test)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • RE: Publishing Companyweb for external access on SBS2003 R2 With I
    ... would like to show out the recommended steps to publish companyweb. ... To publish companyweb in ISA Server 2004, we can simply run the CEICW ... "Allow access to only the following Web site services from the internet" ... On the "Web Server Certificate" page, choose to create a new Web server ...
    (microsoft.public.windows.server.sbs)
  • Re: Page cannont be displayed ... Cannot find server or DNS error - I
    ... As long as IP:Port from the lookup of the server name is mapped to the ... This is because it is impossible to use host headers with SSL. ... need to select any particular server certificate -- but it also renders ... > Web site is 2nd Website and has Certificate from Enterprise Root CA. ...
    (microsoft.public.inetserver.iis)