Re: Muliple Websites on Mutliple IP address with certicles [SSL]



Jennifer wrote on Fri, 28 Apr 2006 13:48:02 -0700:

Should it make a difference that even though these are on different IP
addresses, they are still subdomains:

product1.sfwater.org
product2.sfwater.org

As opposed to different domains altogether (as in the above example)

BTW, Thanks for all the great help!

In that case, can you check with a different browser? I've had issues with
IE6 caching SSL information in the past, but only when using a different
port on the same hostname and IE would display the cert details for
whichever connection was made first eg. SSL on port 443 running IIS, and
RemotelyAnywhere running SSL on port 2001, if I connected IE to RA and then
without closing IE connected to https on IIS, I'd see the information for
the RA certificate in the SSL properties.

Different hostnames with the same domain shouldn't make a difference
compared to my current setup of 3 certs for completely different hostnames.
It might be something messed up in your metabase that is causing one of the
certs to be bound to all sites instead of just the one it should be. Have
you tried removing both certs and reattaching?

Dan


.



Relevant Pages

  • Re: LDAP authentication security ?
    ... I'm actually a big fan of external SSL certs for DCs simply because they are ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... Actually we don't have any PKI so we will buy a commercial SSL ... Simple bind is the authentication mechanism in the LDAP V3 spec and is ...
    (microsoft.public.windows.server.security)
  • Re: [opensuse] Help with Certs for Cyrus IMAP and TLS
    ... Ok, I changed the certs permissions to read/write by root only, no others can read. ... I re-made the certs again using a different how-to, making sure they did not require a pass phrase, but that did not fix the problem either. ... One, I had to start cyrus in runlevel editor and second, my IMAP SSL was and is now broken. ...
    (SuSE)
  • Re: enable LDAP-SSL without a root-CA
    ... DC's for secure SSL password changes from UNIX sources and we don't use MS ... something from verisign. ... I said we wouldn't do it, if they needed Certs for the DC's they ...
    (microsoft.public.win2000.security)
  • Re: AD SSL, what impact?
    ... We use external certs with our DCs and it isn't that big of a deal. ... running with SSL LDAP using a self-signed cert we generated with selfssl.exe ... SSL LDAP traffic will naturally be a little slower than unencrypted traffic, ... If your app uses Microsoft's LDAP APIs, then you ...
    (microsoft.public.windows.server.active_directory)