Re: Problem processing SSL certificate response.



On Nov 22, 12:01 pm, Tyrven <Tyr...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
David,

"Download SSL Diagnostics 1.1 from Microsoft.com and use it to diagnose
and resolve your issue(s) with SSL."

I know why SSL isn't working: there isn't a private key.  What I don't know
is WHY the private key isn't being generated by the "Process pending request"
option.

Note that I am able to work around this by requesting/processing a request
on a separate machine (my local Vista workstation, for example), then
transfering the generated PFX into the certificate store on the IIS machine.  
I can still use the Certificate Authority on the IIS machine to issue a
self-signed certificate.  The issue is exclusively with the ability of IIS to
process a certificate response.

It is not clear to me whether you are saying:
1. It is not possible to use IIS to Request/Process a certificate
request to enable SSL on a website.
2. OR it used to work on this IIS server but not any more.

Both statements are true.  The Request/Process wizard works fine (no errors)
but the result is an "orphaned" public key (no private key generated).  This
process worked up to six months ago (roughly); keys generated via IIS before
that are functional (but many are expiring); key generated (either new or
renewed) are orphaned.

It is also not clear to me whether you installed the SSL Certificate
in the LocalMachine's Personal store or not, nor if you installed the
SSL Certificate with or without "export" capability.

When using the Request/Process wizard, these are not options.  The SSL
Certificate is automatically imported into the Local Machine ("My Computer")
Personal store with export capability.  I could manually import the
certifcate response from the Certificate Authority - but that wouldn't result
in processing a private key.

Hope this helps clarify the issue.

Tyrven



Then, it looks like you should contact Microsoft PSS and open a
support case to determine the underlying issue in your situation.

You say that it worked before but not now, and you are confident that
you are doing the same actions as before that should work, and you
want to know why. Those requirements pretty much mean that you should
contact Microsoft PSS to open a support case because you believe a bug
was introduced.

I usually assign SSL Certificates in IIS in the way that you say still
works -- I never bother with the IIS Wizard to create/process requests
because I always keep track of the PFX certificate and explicitly
install the certificate on the server(s) of my choice with the options
of my choice. Going through the wizard is opposite of what I want,
especially when dealing with multiple servers in a farm.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
.



Relevant Pages

  • Re: SSL broken after Windows 2003 upgrade
    ... The svchost.exe you reference is "IIS". ... routes them to the appropriate w3wp.exe based on configuration from WAS ... WFetch can make both a normal SSL request as well as a Client-Certificate ...
    (microsoft.public.inetserver.iis)
  • Re: Cant get SSL to work locally
    ... SelfSSL just lowers the bar to enabling SSL on IIS (many people mistake ... needing Certificate Server or is just not possible "for free" with IIS). ... does not attempt to address the issue of trust. ...
    (microsoft.public.inetserver.iis.security)
  • Re: 400 Bad Request Error
    ... Thanks for the reply,it does not look like the partner is using 2 different ... I have that cert imported into my trusted people certificate store for the ... use a SSL connection on a different certificate. ... am trying to receive a 0C1 Asynchronous Test Request from a partner. ...
    (microsoft.public.biztalk.server)
  • Re: Switching from http to https
    ... the default website with SSL not enabled (using port 443) in the IIS. ... a certificate to the program. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Cant create web applications
    ... I've managed to re create an autosigned certificate and assigned it to the web application from the IIS 7 manager (it was already created with SSL and has the link with https, I just modified the link to add the cert.), but when I try to access the site, after the certificate warning, I receive a 403-Forbidden error. ...
    (microsoft.public.sharepoint.windowsservices)