Re: Need help with HTTPS

From: Steve Riley [MSFT] (steriley_at_microsoft.com)
Date: 12/26/04

  • Next message: Burtsev Dmitry: "Enterprise CA"
    Date: Sun, 26 Dec 2004 14:25:54 -0800
    
    

    You need a certificate with the "server authentication" purpose. You also
    need to have a private key associated with the certificate. Since you're
    using .CER file, you are lacking the private key.

    What are you using to generate your certificate with?

    Steve Riley
    steriley@microsoft.com

    > Hey all
    >
    > I'm new at this, so please bear with me.
    >
    > Basically, I'm trying to set things up so that clients would connect
    > to my
    > asp.net web site (.aspx) vias https.
    > I have been following the following links closely to accomplish this:
    > http://support.microsoft.com/kb/816794
    > http://support.microsoft.com/default.aspx?scid=kb;en-us;324069
    > My problem (as far as I know) is two-fold:
    > i) I am unable to select the 'Server Certificate' (it is shaded out)
    > when I
    > follow the steps below as outlined in one of the links above:
    > Assign the Imported Certificate to the Web Site
    > 1. Click Start, point to Administrative Tools, and then click
    > Internet
    > Information Services (IIS) Manager.
    > 2. In the left pane, click your server.
    > 3. In the right pane, double-click Web Sites.
    > 4. In the right pane, right-click the Web site you want to
    > assign the
    > certificate to, and then click Properties.
    > 5. Click Directory Security, and then click Server Certificate.
    > 6. On the Welcome to the Web Certificate Wizard page, click
    > Next.
    > 7. On the Server Certificate page, click Assign an existing
    > certificate, and then click Next.
    > 8. On the Available Certificates page, click the installed
    > certificate
    > you want to assign to this Web site, and then click Next.
    > 9. On the SSL Port page, configure the SSL port number. The
    > default
    > port of 443 is appropriate for most situations.
    > 10. Click Next.
    > 11. On the Certificate Summary page, review the information
    > about the
    > certificate, and then click Next.
    > 12. On the Completing the Web Server Certificate Wizard page,
    > click
    > Finish, and then click OK.
    > Anybody know why this is the case?
    >
    > ii) I suspect (possibly incorrectly) that I might not have a
    > certificate installed in the Windows 2003 certificate store. I was
    > able to generate, issue, and store a certificate in a .cer file.
    > However, what oid (i.e. usage) should I use for the certificate
    > generation? Currently I'm using 1.3.6.1.4.1.311.2.1.21, which
    > represents a client-browser certificate. Is this correct for what I'm
    > trying to do? Also, once the certificate is generated, should I store
    > it under the 'personal' folder?
    >
    > Any feedbacks that you guys can give me would be awesome and highly
    > appreciated!
    >
    > Thanks,
    > Paul


  • Next message: Burtsev Dmitry: "Enterprise CA"

    Relevant Pages

    • RE: Publishing Companyweb for external access on SBS2003 R2 With I
      ... would like to show out the recommended steps to publish companyweb. ... To publish companyweb in ISA Server 2004, we can simply run the CEICW ... "Allow access to only the following Web site services from the internet" ... On the "Web Server Certificate" page, choose to create a new Web server ...
      (microsoft.public.windows.server.sbs)
    • RE: Getting rid of a rogue SSl certificate
      ... > Please follow the steps below to check the certificate on ISA. ... > server name, select prop. ... network, firewall, secure Web site, and e-mail. ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA2004 RWW/OWA doesnt work
      ... in ISA server 2004 web publishing rules. ... Click the "Connect to the Internet" link. ... entire Web site from the Internet" is selected. ... On the "Web Server Certificate" page, choose to create a new Web server ...
      (microsoft.public.windows.server.sbs)
    • Re: RPC-OVER-HTTP
      ... The easiest way to verify this is open IE and connect to your web site with ... Certificate does not match the Web Site ... using RPC over HTTP and must be corrected before proceeding further. ... > server and RPC proxy has been enabled on the server. ...
      (microsoft.public.exchange.connectivity)
    • Re: OWA logon screen
      ... I have believe in have installed a CA on my Windows 2003 Server and i can ... view the certificate under default web site. ... All issuance policies ... you have a private key that corresponds to this certificate. ...
      (microsoft.public.exchange.admin)