RE: SQL Server & SSL & Fully Qualified Domain Name

From: Kevin McDonnell [MSFT] (kevmc_at_online.microsoft.com)
Date: 07/22/04


Date: Thu, 22 Jul 2004 18:50:45 GMT

Prev Post.

However when I remove the server force and apply the force on the Client
Connection Utility - I get this : [DBNETLIB]SSL Security error.

I did some research and found that the client MUST trust the CA, and
Thawte's temp certs arent trusted, so I attempted to import the test CA
into my trust store, and see if that worked, and it did not. Although I am
not sure I did it correct. I am wondering if this is fact the problem, that
my client doenst fully trust the test cert, what do you think?

-- Yes. This is true. If you enable the Force Protocol Encryption option
on the client, then the client MUST trust the same root authority that
issued the cert. So, you need to update the Trusted Root Authorithy on the
client machine.

276553 HOW TO: Enable SSL Encryption for SQL Server 2000 with Certificate
Server
http://support.microsoft.com/?id=276553

Thanks,

Kevin McDonnell
Microsoft Corporation

This posting is provided AS IS with no warranties, and confers no rights.



Relevant Pages

  • Re: Append action query not working out.
    ... A trust is a "client" that consist of other clients, ... Things like Directors are actually related entities rather than ...
    (microsoft.public.access.queries)
  • Re: OWA, SSL and Certificate question.
    ... It is true that when you are using your own CA to publish the cert, ... will have to get your client to trust your root CA in order to avoid such ... all web browsers trust to certain Cert Authorities by default. ... using the exchange server itself as the certificate authority. ...
    (microsoft.public.exchange.clients)
  • Re: Append action query not working out.
    ... > Travis, could you just have one Client table, that contains all these kinds ... > a person, trust, company, or SMSF? ... I've got the database organised by client groups. ... the directors and shareholders, tax file number information, GST etc. ...
    (microsoft.public.access.queries)
  • Re: reestablish trust relationship
    ... I'm doing this for a client. ... Apparently the trust relationship is lost due to ... >> SID issues. ... Intra-forest trusts between DCs and/or member machines (joined ...
    (microsoft.public.windows.server.dns)
  • Re: For Rebecca Chen
    ... Planning to install AD client support on them. ... >>I believe when a trust is established between the old and new domain, ... REBC: Have you migrated the computer account? ... a new name as well as a new domain name for the win2k3 domain. ...
    (microsoft.public.windows.server.migration)