Disable or Control certificate auto-import?



I'm working with an IIS 6.0 website running on Windows 2003 Server.
It's normally used as an internal website, but we now have a small group
of geographically disperse external users that require access. VPN isn't
practical in this situation, so I though I'd try SSL.

I first tried using SelfSSL and then Requiring SSL connections. The idea
being
that I could export the certificate, and then get both internal and external
users to
manually add the pfx file using the password I used during the certificate
creation.

This worked like I wanted until I realized users can "Continue to this
website
(not recommended) and get to the site anyway. Can the IIS configuration be
setup
to disable auto-import for browsers (which I doubt), or is there a way a
"server"
certifcate can force a password prompt during the auto-imported? For
example,
certifcates from a real CA have more capabilities?

I'm obviously new to this, and have also read about requiring client
certificates
in IIS, but don't really understand how they could be easily implemented in
our
environment.

Any suggestion?

TIA,
Don




.



Relevant Pages

  • Re: Exchange 2003 ActiveSync, Sprint PPC-6700 and SSL: Giving me a
    ... > certificate, but once you've got it working it just continues to work. ... Both Exchange and the Exchange OMA virtual ... >>> My certification path was the same www.mydomain.com that my website uses ... When I look at IIS in Server Management, ...
    (microsoft.public.windows.server.sbs)
  • SSL certificates in SBS2003 SP1
    ... I have a website set up in IIS under the Default Website. ... SSL with the default SBS SSL certificate. ...
    (microsoft.public.windows.server.sbs)
  • Re: Installing Godaddy Certificate onto SBS 2003 SP1; ISA2004
    ... Do it through the default website on IIS. ... Just rename the godaddy .crt to ..cer and it will work fine - Assuming you created the CSR through the default website in the first place. ... the third party certificate, I get a message that no certificate was ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with SSL
    ... What you did was tell IIS to not accept traffic on HTTP in that folder. ... SSL has _NOTHING_ to do with JavaScript. ... > of the website root directory. ... > does that do to the SSL certificate? ...
    (microsoft.public.inetserver.iis.security)
  • Issue SSL cert for new webserver
    ... I have setup a 2003 R2 member server with IIS that will be used for an internal website on our domain. ... The SBS self-signed certificate is installed on all PCs into the "Trusted Root Certification Authorities" store. ... All PCs can access https on the SBS server without any certificate warnings - So all looks good. ... Now, on our new IIS server, I generated a self-signed certificate using the IIS wizards, using the SBS server as the CertSrv. ...
    (microsoft.public.windows.server.sbs)