Publishing issues with SubjectAltName SSL certs?



We recently provisioned new SSL certs and our cert provider supports the
SubjectAltName extension, which allows you to have two DNS FQDN's associated
with the cert versus only one. For example if you have an internal IIS web
site internal.internet.com and an external IIS web site
external.internet.com, you would have to have a cert for each name...with
SubjectAltName you can add both names to the one cert and use the same cert
on both web sites for SSl connections.

Although these certs work fine internally with IIS as above, when I try to
publish server external.internet.com using the cert internal.internet.com
(which has a SubjectAltName of external.internet.com), I get an error 23403
in the Event Log:

ISA server could not establish an SSL connection with published server
external.internet.com because the name on the SSL certificate used by the
published server does not match the name of the server
internal.internet.com, specified in the publishing rule.

Basically, it seems like ISA only looks at the name of the cert, which in
this case does not match published server name, and does not recognize that
the cert does have a SubjectAltName value that *does* match the published
server name.

Has anyone run into this that can help me???



--
Posted via a free Usenet account from http://www.teranews.com

.



Relevant Pages

  • Re: Loss of Webmail after renewing our Certificate
    ... Nothing to abnormal in the event logs. ... If you deselect the "require SSL" box, ... there a method to uninstall a cert and reinstall or anything like ... I'd take a look at the server and make sure that the cert was ...
    (microsoft.public.exchange.admin)
  • RE: IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box)
    ... it prompts the user for what client cert they want to use to connect to the ... it issues client certificates to the end users. ... Step I - Installing the New Server ... Install NT SP 3 ONLY ...
    (Focus-Microsoft)
  • Re: http_403 error, but not for everyone
    ... As far as the SSL cert is concerned, as I stated I can login successfully ... > - if the server you connect to is not a frontend exchange server see this ... The server is setup SSL, ...
    (microsoft.public.pocketpc.phone_edition)
  • SSL Cert and EAS
    ... I have just purchased a godaddy SSL cert for my WM5.0 AKU2 device and I ... The security certifcate on the server is invalid. ... Administrator or ISP to install a valid certificate on the server. ...
    (microsoft.public.exchange.admin)
  • Re: Windows 2003 sbs : multiple webs & SSL
    ... You can get them to install the cert though. ... > instance) and install it on the server. ... Forgetting about SSL for a moment, you CAN have different websites on ...
    (microsoft.public.windows.server.sbs)