Re: IIS does not listen on ssl port

From: bear (ncointepoix_at_cfl.rr.com)
Date: 07/14/04


Date: 14 Jul 2004 07:10:54 -0700

Ken,

Thanks for the response. I don't believe the issue is in the cert
because i am not getting the error "the name of the site you are
connecting to does not match the one contained in the certificate." It
must have something to do with IIS and the website. Why does the https
site not come up. I have stopped and restarted the site and i still
have the same problem. Any help would be appreciated.

Thanks again

"Ken Schaefer" <kenREMOVE@THISadOpenStatic.com> wrote in message news:<#CYNCUUaEHA.3708@TK2MSFTNGP10.phx.gbl>...
> Hi,
>
> In answer to your questions:
> a) the "common name" on the cert needs to be whatever name you use to access
> the server. If you use https://accounting, then the common name should be
> "accounting". If you use https://www.abc.com then the common name should be
> www.abc.com. If you use anything else, then your browser will give you an
> error saying that the name of the site you are connecting to does not match
> the one contained in the certificate.
>
> b) you may wish to use the SSLDiag tool that Microsoft has to try and
> troubleshoot this issue (at least from the IIS side):
> http://www.microsoft.com/downloads/details.aspx?FamilyID=cabea1d0-5a10-41bc-83d4-06c814265282&DisplayLang=en
>
> Cheers
> Ken
>
>
> "bear" <ncointepoix@cfl.rr.com> wrote in message
> news:926255a.0407131354.24e2bdc1@posting.google.com...
> : Can someone please help me.
> :
> : I have purchased a certificate for verisign and installed on IIS 5.
> : when i attempt to goto the website http://servername I receive my
> : default web page. However when i type in https://servername. I
> : receieve the dreaded 'The page cannot be displayed' error. I have the
> : port set for 443 on the iis server. so why is it not listening? Is
> : there something i have to turn on. If the Common Name on the cert is
> : not correct would that keep the server from responding to https
> : requests?
> :
> : I have reviewed the steps on how to install the cert and then set the
> : website to require SSL but i do not want to do that until i know i
> : have the SSL working. I am a little worried that the Cert may not have
> : the correct information on it.
> :
> : Here is the exact scenario, When the original IT person installed the
> : network they named it accounting as the domain name. Well the problem
> : is that our company name is not accounting but let's say it is
> : abc.com. The only way to receive web requests from ABC.com was to
> : setup the DNs entry that pointed to the outside of the firewall and
> : then setup static port forwards that point all data sent to
> : https://abc.com to go to the cpr_Server (server name) on port 443. So
> : when i created the cert i had to give it a common name of cpr_server.
> : Since i could not name it abc.com. Was this correct? Should i name it
> : cpr_server@accounting.com?? or do i just have a setting incorrect on
> : the iis server?
> :
> : Thanks in advanced for any assistance you can offer!!!



Relevant Pages

  • Re: Deleted certificate request
    ... sent that in to get the cert (I still have the .txt file that was ... pending certificate request for this response file was not found. ...
    (microsoft.public.inetserver.iis.security)
  • Re: improved C1X security
    ... Response below: ... There will be a paper on these functions in the WG14 mailing, ... I wasn't planning on proposing these (as they were already being ... We have a short write up on these functions in The CERT C Secure Coding ...
    (comp.lang.c)
  • Re: "The signature or decryption was invalid"
    ... piece of these security headers? ... > We continue to have a problem with a simple signed response using WSE ... > We keep getting the following error message: ... > I'm using a Cert generated by our Cert Authority to generate a Client ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: IIS 5.0 SSL - Unable to Edit Certificate to enable SSL
    ... I still suspect that the cert was not ... This kb shows that button is enabled, but no response ... But I am not able to enable> it because the EDIT button under Directory Security for> Secure Communications is GRAYED out. ...
    (microsoft.public.inetserver.iis.security)
  • CERT Advisory CA-2001-19
    ... Subject: CERT Advisory CA-2001-19 ... Buffer Overflow In IIS Indexing Service DLL. ... IP addresses on port 80/TCP looking for other hosts to infect. ... Additional detailed analysis of this worm has been published by eEye ...
    (Cert)