Re: Problems with SSL on OWA

Tech-Archive recommends: Speed Up your PC by fixing your registry



Brian,

I removed the previous cert and followed the directions in the first article
you linked to create a new one (same result). The certificate is issued to
webaccess.domain.com - the url used to access the site is
https://webaccess.domain.com. The certificate was issued by our internal CA
server (again following the article step by step).

I've attempted accessing OWA from outside the network then choosing to view
certificate and install certificate. I've attempted installing in under
every option without any success in making the warning message go away.

Even if I could stop the message by installing the certificate, this still
causes end user problems whenever they see the warning. Short of spending
$400 for a cert, is there a better way to do this?



"Brian Kronberg" wrote:

Did you create the certificate with your external DNS name? What
company did you get your cert from? Is that company already trusted on
your client computers? If they are accessing OWA from outside
non-domain computers, they will have to manually add your cert
company's root certificate to their certificate store.

Read these:
http://www.petri.co.il/configure_ssl_on_owa.htm
http://www.petri.co.il/configuring_forms_based_authentication_in_exchange_2003.htm

BK

On Jan 5, 2:05 pm, mtstream <mtstr...@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:
The SSL Cert being used for OWA expired - the Cert that was being used had
been issued by a company I'd never heard of. So I backed it up then removed
it.

I went through the IIS process to request a new Cert. Our CA server kept
having errors when attempting to use the web interface. By choosing "Send
request immediately to an online . . . " and selecting my CA server I was
able to generate and apply a certificate. The new certificate appears fine
and we no longer receive the Expired warning.

However - Users outside the network now receive a warning that the
certificate was not issued by a trusted authority. IE7 makes users think the
world is going to die if they attempt to continue.

I've attempted to install the certificate to every possible store including
Trusted Root Cert Auth; Ent Trust; Trusted Publishers; etc and cannot get
past the message.

Help!

Note: when inside the network I connect https without any issues - this only
exists outside.


.



Relevant Pages

  • Re: Certificate Services and Synching with Exchange
    ... Yes, installing the cert and self-signing worked, but only because ... Yes, I had to manually export and install it, but it was trivially ... You export the cert from the MMC to a .cer file. ... Will installing Certificate Services and self-signing a certificate ...
    (microsoft.public.pocketpc.activesync)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)
  • Re: CertSrv Question
    ... In my case as posted earlier I didn't install a stand alone CA, ... In effect I want to revert everything on the domain to just before the root ... it replicated a certificate to the ... >>>The reason most likely is that the CA cert is still there in the NTAuth ...
    (microsoft.public.win2000.security)
  • Re: Require SSL certificate
    ... This will be true if running under SSL. ... Once a web cert is associated with a site, it doesn't need to be installed ... > I have a website and a security certificate, i install the security> certificate for the site. ...
    (microsoft.public.dotnet.framework.aspnet.security)