Re: Apache 2.x for Windows running behind ISA 2004 - intermediate certificate not trusted

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I assume you are publishing the Apache web site via web publishing in ISA
2004.

If that is the case and you want to use SSL bridging (people connect to ISA
via https, then ISA decrypts the request, inspect the content, and forwards
it to Apache), you need to perform the following steps:

1. Install the Apache certificate on the ISA Server machine, in the
"Personal" folder of the "Local Computer" store, and create a SSL listener
on ISA using that certificate. You will need to import a PFX file containing
both the certificate and the corresponding private key.

2. Install goDaddy's own certificate (the certificate of the certification
authority that issued your Apache cert) into the "Trusted Root Certification
Authorities" folder of the "Local Computer" store.

You may want to reboot after you perform 1) and 2) above. After that your
SSL bridging should work. If the instructions above are not clear, take a
look at the following article:

Publishing Web Servers with ISA 2004:
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/publishingwebservers.mspx
(See the "SSL bridging" section as well as the rest of the document - it is
a very good one indeed.)

Note: a simpler way to publish your Apache server is to just use HTTPS
server publishing instead of web publishing. This however does not offer the
same degree of security - requests are simply forwarded to the Apache server
without being decrypted and inspected by ISA. You could use this as an
intermediate step until you figure out the proper procedures for SSL
bridging.

Virgil



<verticalrabbit@xxxxxxxxx> wrote in message
news:1154655477.930968.49200@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I'm new to ISA 2004 but as I thought it would be intuitive, I dove
right in and have been losing sleep ever since. To be brief - Windows
2003 with Apache for Windows 2.x running with SSL v3 certificate
installed, downloaded from GoDaddy.com. They use an intermediate
certificate and this seems to be causing all the trouble.

I generated my csr, obtained my certificate and installed the server
and intermediate keys along with the private key on apache (pointed the
ssl.conf file to the cert location). The problem is that when I attempt
to roll over or redirect the apache server to the application server,
or try to use the java based help from within, the "security
certificate was issued by a company that's not valid" and "The security
certificate has not expired and is still valid."

I only get this problem when trying to put the firewall between the
server and the client - which is the goal of a firewall, of course.

The certificate just seems to not be coming accross correctly - or is
not showing the root CA - although all three have been installed
(including using openssl on apache to create a p12 certificate that
includes the private key.

Please help - I'm under a deadline.



.



Relevant Pages

  • Re: SharePoint 3.0: problems with external access
    ... Here are the steps to publish a WSS 3.0 application behind ISA Server. ... Let's assume that you created a new WSS 3.0 application, that listens to port 80, and the host header is 'Intranet'. ... Go to IIS Manager and make sure that the IP address of the site is set to the IP address of the server. ... Run the wizard to create a new SSL certificate for the site. ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... If the Exchange 2007 box is hosting mailboxes, it won't work as a front-end equivalent. ... We are making this a virtual server and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA Form Resetting
    ... It seems that I had FBA turned on on both the ISA & Exchange server. ... I was issued a new SSL certificate from InstantSSL.com. ... After installing the new cert and REBOOTING, ...
    (microsoft.public.isa)