Re: Separate SSL cert for each NLB server?



On 7/31/08 4:52 PM, in article ujO9S908IHA.1180@xxxxxxxxxxxxxxxxxxxx, "Mel
K" <M@xxxxx> wrote:

Hello:

I have a load-balanced (MS NLB) cluster of two OWA servers that both respond
to https://owa.myfirm.com. Do I need to get a separate SSL cert for each
server, or can I just install the same SSL cert on both since they are both
NAT'd to the external IP address for owa.myfirm.com?

On a sort of related note, does a HTTPS site encrypt the URL also? If I
browse to https://www.myfirm.com, are the URLs to various links from that
site encrypted? For example, would the actual URL for
https://www.myfirm.com/corporate-strategy/microsoft-takeover/plan.html be
passed in clear text, even though the contents are encrypted? Or are both
the URL and contents encrypted?

Thank you.
Licensing aside (commercial providers usually license certs per server), you
can use the same certificate on both servers. Just make the SSL cert request
on one server, install the certificate when it's been approved and assigned,
then export it from the one server and import it onto the other. There's an
option in IIS to export the cert directly to the other machine, but I've
ever got that to work right...

As a side-note, if you install your own Certificate Authority , you can
issue yourself perfectly working certificates lasting 10-20 years (leaving
you worry-free from remembering to renew...). The only downside is that end
users from home will receive a security warning when browsing to the site as
the CA is not recognized by their browsers. If the users are "friendly"
(CEO's, managers, and "government" higher ups are usually not that kind),
then all it takes is for them to import the cert into their computers *once*
and from then on no more security warning... It will be as if you were using
a commercial cert. Internally to your firm, you can add any certificate you
wish to the trusted list of certificates in Active Directory, which will
prevent any security popups in your internal workstations.
--
Roberto Franceschetti
LogSat Software
http://www.logsat.com

.



Relevant Pages

  • Re: New Event Log Errors!
    ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • RE: IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box)
    ... it prompts the user for what client cert they want to use to connect to the ... it issues client certificates to the end users. ... Step I - Installing the New Server ... Install NT SP 3 ONLY ...
    (Focus-Microsoft)
  • RE: Installing root certificate on PDA
    ... You can export the certificate from the server: ... Trusted Root Cert Auth tab> pick your server's cert from the list & click ... Install Cert on PDA: ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 certificate problem affecting Exchange
    ... And it needs to match the FQDN of the OWA server. ... They are fairly inexpensive, I personally prefer Go Daddy, and pay for themselves the first or second time you have to an manually install the private certs on each mobile device. ... certificate error, but the phones won't. ... a cert with SAN and installing it. ...
    (microsoft.public.exchange.admin)