Question about using pre-signed certificates

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: RobbieK (rknierim_at_optonline.net)
Date: 01/09/05


Date: 8 Jan 2005 17:20:54 -0800

I am hoping someone can help with a strange problem - I am not very
savvy with certificates, so bear with my ignorance in that area. I
have an ASP.NET (1.1) application that calls a web service (non .net)
over SSL. The owner of the web service asked for a certificate request
that he would sign and return back (I used OpenSSL to create the CR).
He provided the certificate and I imported it into my Local
Machine\Personal certs.

Things weren't working, so to ease troubleshooting, I moved to my local
laptop (imported the cert there) and created a quick Windows app with
VB.NET. After fixing the issue (was proxy server related), everything
was working perfectly. When I went back to the web server to implement
the working code, I received an error (see below). I copied my working
VB application directly onto the web server and also received the error
message.

System.Net.WebException: The underlying connection was closed: Could
not establish secure channel for SSL/TLS. --->
System.ComponentModel.Win32Exception: The message received was
unexpected or badly formatted

The owner of the web service is telling me that he doesn't even see the
request coming to his server (at least at the point of SSL
handshaking... his log shows handshake errors if the server is
reached). I would guess a problem with the cert, but it works great
from my laptop. Weird thing is that the server where the CR was
created does not work, but fine from my laptop. I also tried copying
the application/importing cert to a 3rd computer... doesn't work. With
such little information reported in the error message, is there a way I
can tell more specifically what the problem is (and don't say to write
a SOAP extension :-) unless that's my only hope).

Thanks!!



Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)