Re: SSL and OWA

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Raven (Raven_at_discussions.microsoft.com)
Date: 01/20/05

  • Next message: Raven: "Re: SSL and OWA"
    Date: Thu, 20 Jan 2005 05:53:06 -0800
    
    

    Well I looked in the IIS log file but there was nothing that seemed even to
    relate to SSL in there. I did a simulated handshake using SSL diagnostics and
    got the following (is there no way to attach files to these messages?)

    System time: Thu, 20 Jan 2005 13:42:33 GMT
    Connecting to 127.0.0.1:443
    Connected
    Handshake: 108 bytes sent
    Handshake: 1415 bytes received
    Handshake: 182 bytes sent
    Handshake: 43 bytes received
    Handshake succeeded
    Verifying server certificate, it might take a while...
    Server certificate name: mail.macleandata.co.uk
    Server certificate subject: C=GB, S=Midlands, L=Leicestershire, O=Maclean
    Data, OU=IT, CN=mail.macleandata.co.uk
    Server certificate issuer: C=US, CN=mail.macleandata.co.uk
    Server certificate validity: From 1/19/2005 8:52:59 AM To 1/19/2007 8:52:59 AM
    HTTPS request:
    GET / HTTP/1.0
    User-Agent: SSLDiag
    Accept:*/*
    HTTPS: 72 bytes of encrypted data sent
    HTTPS: 301 bytes of encrypted data received
    Status:
    HTTP/1.1 401 Access Denied
    HTTP/1.1 401 Access Denied
    Server: Microsoft-IIS/5.0
    Date: Thu, 20 Jan 2005 13:42:33 GMT
    WWW-Authenticate: Negotiate
    WWW-Authenticate: NTLM
    WWW-Authenticate: Basic realm="127.0.0.1"
    Content-Length: 24
    Content-Type: text/html
    HTTPS: server disconnected
    Error: Access is Denied.
    Final handshake: 23 bytes sent successfully

    - - - - - - - - END - - - - - - - - -
     
    "Ken Schaefer" wrote:

    > Using the IIS Logfiles, verify that the requests are going to the correct
    > site.
    > Also, if you are using IIS6, you should be able to see the HTTP substatus
    > code in the logfile entry. Please post that so we can see why you are
    > getting an Access Denied.
    >
    > Lastly, you can use SSLDiag to troubleshoot the SSL issues:
    > http://www.microsoft.com/downloads/details.aspx?FamilyId=CABEA1D0-5A10-41BC-83D4-06C814265282&displaylang=en
    >
    > Cheers
    > Ken
    >
    >
    > "Raven" <Raven@discussions.microsoft.com> wrote in message
    > news:3BB267E8-A2B7-4169-A680-01A240E6064E@microsoft.com...
    > > Ok - managed to get a little bit further. Having added the FQDN to my
    > > hosts
    > > file I can now access it using the full name. However, I still get the
    > > same
    > > errors. 403 forbidden without HTTPS and cannot find server or DNS error
    > > with
    > > HTTPS. Take out the cert and it all works fine, put in the cert and it all
    > > stops etc etc etc
    > >
    > > "Raven" wrote:
    > >
    > >> I have decided to secure my OWA site using SSL. I have followd the
    > >> instructions for installing certificate services, creating a server
    > >> certificate and used the external domain name as the common name for the
    > >> server.
    > >>
    > >> Having applied the certificate I can now no longer access OWA internally
    > >> (can't check it externally). I used to be able to do this but only by
    > >> using
    > >> the server name and not the FQDN. I am assuming this is something to do
    > >> with
    > >> having told the certificate server that the common name is the FQDN.
    > >>
    > >> Any suggestions as to why I can't access the server. If I use HTTP and
    > >> the
    > >> internal server name I get Error 403 forbidden. If I use HTTPS I get the
    > >> page
    > >> you are looking for cannot be displayed.
    >
    >
    >


  • Next message: Raven: "Re: SSL and OWA"

    Relevant Pages

    • Re: SSL and OWA
      ... cs-uri-query sc-status cs ... I then ran the SSL diagnostics and went for a simulated handshake. ... Verifying server certificate, ... HTTPS: 72 bytes of encrypted data sent ...
      (microsoft.public.inetserver.iis.smtp_nntp)
    • Re: IIS SSL Site Page Not Found - have tried everything
      ... >I have a default web site on IIS 5 set up with a SSL Certificate ... > when the protocal is set to HTTPS but not when set to HTTP. ... > server and root authority in browser. ... > Handshake: 2097 bytes received ...
      (microsoft.public.inetserver.iis.security)
    • yet another problem update - tried SSL Diagnostics
      ... SSL Diagnostics as was recommended there. ... SSL handshake with a replaced certificate and it worked, ... Verifying server certificate, ...
      (microsoft.public.inetserver.iis.security)
    • RE: Page cannont be displayed ... Cannot find server or DNS error - I
      ... I use https to my login screen. ... > Web site is 2nd Website and has Certificate from Enterprise Root CA. ... > I ran both SSLDiag/Simulate SSL Handshake and wfetch. ...
      (microsoft.public.inetserver.iis)
    • RE: Page cannont be displayed ... Cannot find server or DNS error - I
      ... I use https to my login screen. ... > Web site is 2nd Website and has Certificate from Enterprise Root CA. ... > I ran both SSLDiag/Simulate SSL Handshake and wfetch. ...
      (microsoft.public.inetserver.iis.security)