Re: SSL on IIS6.0 Multi-Homed

From: Bernard (qbernard_at_hotmail.com.discuss)
Date: 03/26/04


Date: Fri, 26 Mar 2004 14:59:16 +0800

1) if you configure 2 host header in the secure site.
when you type https://www.multi.com, you should be prompt
to validate the cert as the common name does't match with the cert.

2) I'm not sure why you get redirected.. you might want to check
if you have configure custom error page to redirect to https://secure....

3) and SSL doesn't support host header.

-- 
Regards,
Bernard Cheah
http://support.microsoft.com/
http://www.msmvps.com/bernard/
"CQL User" <foo@cqlcorp.com> wrote in message
news:uknOZcnEEHA.2408@TK2MSFTNGP10.phx.gbl...
> I am having a problem on Windows 2003 Server.
>
> On 2000, I could have a multi-homed server, as long as I only had 1 SSL
per
> IP.  ie: port 443.
>
> If the certificate was assigned to https://secure.foo.com, it works fine.
>
> If I go to a multi-homed site, on the same IP, but NO SSL included, and I
> typed in the multi-homed SSL, ie: https://www.multi.com, I should get an
> error.  However, it actually redirects to https://secure.foo.com and
allows
> the lock to appear and work.  (even though the SSL is assigned to
> https://secure.foo.com.)
>
> Is this a bug?  Should I be able to do this?  I followed the instructions.
> Shouldn't the SSL still look at the host header, to realize I am not going
> to the valid address?
>
> Please advise!
>
>


Relevant Pages

  • Re: Wildcard SSL Implementation
    ... DNS A record '*' ... Create a site 'no host header' bind to 1 IP ... Verisign provide * - wildcard cert as well. ... > Each IP address can only have a single certificate for each port (eg one SSL ...
    (microsoft.public.inetserver.iis.security)
  • Re: Wildcard SSL Implementation
    ... > SSL cert then it'll work. ... likely works, no host header concept. ... >: Bernard Cheah ... >:> You can't use host headers with SSL ...
    (microsoft.public.inetserver.iis.security)
  • Re: SSL pages not found
    ... >> It will work, if you got one host header, one site and IP (one cert) ... >> b)two host headers in ONE site, ONE port + IP ... > Hmm probably I am wrong - I have configurations where there is a site> determined by host header using SSL but only one - others are not ssl> enabled. ...
    (microsoft.public.inetserver.iis.security)
  • Re: SSL pages not found
    ... > It will work, if you got one host header, one site and IP (one cert) ... > b)two host headers in ONE site, ONE port + IP ... determined by host header using SSL but only one - others are not ssl ...
    (microsoft.public.inetserver.iis.security)
  • Re: Microsoft Direct Push / Active Sync - cant get it working
    ... Great to hear that you got it all working on port 80! ... Sorry I'm not too familiar with the way SSL certificates are created and installed, so I can't be much help from here on out. ... I decided to see if I could get an SSL cert in place, ...
    (microsoft.public.pocketpc)

Quantcast