Re: Can't get SSL to work locally

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 06/28/04


Date: Sun, 27 Jun 2004 15:42:41 -0700

SelfSSL is the easiest way to enable SSL for your server (only works for
testing/private use -- real SSL sites still need to buy their own cert)

http://www.microsoft.com/downloads/details.aspx?FamilyID=56fc92ee-a71a-4c73-b628-ade629c89499&DisplayLang=en

SSLDiag is the easiest way to check for why SSL is not working on IIS.

http://microsoft.com/downloads/details.aspx?FamilyID=cabea1d0-5a10-41bc-83d4-06c814265282&DisplayLang=en

-- 
//David
IIS
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"Mark Rae" <mark@mark-N-O-S-P-A-M-rae.co.uk> wrote in message
news:eDiUoPEXEHA.4000@TK2MSFTNGP09.phx.gbl...
Hi,
I've recently acquired an SSL certificate on my live web site which I
maintain and develop in C# / ASP.NET with VS.NET 2003. That means I can use
https://www.markrae.co.uk just as well as http://www.markrae.co.uk.
Therefore, I need to be able to simulate this on my development machine.
I followed the MSKB article How To Set Up Client Certificates
(http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secmod/htm
l/secmod31.asp) to the letter, and am now experiencing the following
behaviour on my development machine:
1) If I browse to http://localhost/markrae, all is fine
2) If I browse to https://localhost/markrae, IIS pops the standard Security
Alert message (which I'd expect), saying that the Security Certificate was
issued by a company I have not chosen to trust etc. So I click Yes, and then
I get "Cannot find server or DNS Error", as if the site I'm trying to browse
to isn't there.
I'm running Windows XP Pro with all the latest security patches.
If I open MMC, expand Internet Information Services and right click on
Properties, C:\WINDOWS\System32\inetsrv\sspifilt.dll is showing as being
installed.
If I right click on Default Web Site and select Properties, the IP address
is set to (All Unassigned), the TCP port is 80 and the SSL port is 443 (not
dimmed).
If I run  netstat -an from a command prompt, it has a Local Address entry
for 0.0.0.0:443
I'm clearly missing something glaringly obvious here...
Any assistance gratefully received.
Regards,
Mark Rae


Relevant Pages

  • RE: SSL MITM not on port 443
    ... Have you ever done what you're trying to do on a "normal" SSL web ... My recommendation would be to set up a web server in your lab ... hopes that the client will accept that certificate. ... SSL MITM not on port 443 ...
    (Pen-Test)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Publish SSL Web Server behind SBS2003
    ... > How to configure a certificate for use with a Web publishing rule in ISA ... > Server 2004 ... > RWW/OWA for SSL encryption. ... Right click the SSL Web Site and click Properties. ...
    (microsoft.public.windows.server.sbs)
  • Re: "Could not connect to server" error when accessing Outlook 200
    ... Perhaps when you connect via RDP, you have to use SSL. ... The server you are connected to is using a security certificate ... A certificate chain processed, but terminated in a root certificate which is ... Settings on the Advanced tab. ...
    (microsoft.public.outlook.installation)