Re: ADAM - Self SSL?



I'm not sure, but there are other newsgroups that specialize in the MS CA
stuff (ms.pub.security.crypto for example). I've never actually used the MS
CA personally, so I don't know the exact steps.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"Thorsten Schmitt" <ThorstenSchmitt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:60B8B674-B9F5-4090-8FF6-8FFF98232FFF@xxxxxxxxxxxxxxxx
Hi,

thanks for information.
Is there any guidline for this or any guidline for this task with a (MS)
CA?
I am currently testing it with a Windows CA (just installed because the
requst is easier) but I am not able to get it working, neither in ADAM,
nor
in IIS.
I did the following after installing the CA:
requestet the certificate over the CA's website as a server authentication
certificate, issued this and installed it. I also copied it to the
personal
store of the ADAM Service.

After installing, I also installed the certificate of the CA into my store
(export the cert and installing it). Then I have restartet IIS and ADAM,
but
in none I can get a SSL connection. I try all of this on one W2K3 server
and
I have no idea how to continue.

Thanks and Kind Regards
Thorsten



"Joe Kaplan" wrote:

Sure, this works fine. SelfSSL from IIS reskit will work if you already
have IIS installed.

The issue with all self issued certs is that no one trusts them by
default,
so they are painful to use outside of small test lab scenarios because
you
always have to add the cert to the client's trusted root store in order
to
get any remote client to connect.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services
Programming"
http://www.directoryprogramming.net
--
"Thorsten Schmitt" <schmitt_thorsten@xxxxxxxxxxx> wrote in message
news:%23oo9TDltHHA.3356@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

reading MS documents I read some hints about how to enable ADAM using
SSL
with a CA.
Is it possible to use a self issued SSL certificate (maybe with
self-ssl
from the IIS Reskit?) or any other tool to issue SSL Certificates
without
the need of a CA?

Thanks and Kind Regards,
Thorsten





.



Relevant Pages

  • Re: Trusted connection problem
    ... whether a given site's certificate will be trusted by a given client machine ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.dotnet.security)
  • Re: LDAPS
    ... Are you sure the DNS name of the DC matches the DNS name of the certificate ... should show up as an schannel error in the event log, ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)
  • Re: Do i need to got Https:// throught the website ???
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I believe that one of these Certification's (SEI-CMM Level 5 Certificate, ... more then 20 website which are dynamic and used by the same users. ...
    (microsoft.public.dotnet.security)
  • RE: Not able to connect to SBS using both domain mane or IP remote
    ... > Thank you for posting in SBS newsgroup. ... you can right click the Certificate Authority ... > | After Installing the CA the wizard prompted me with a message stating ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync support codes 85020010 and 80070002
    ... Since the host name is the same it uses the same digital certificate. ... you try installing it? ... As I said earlier I find it strange that OMA says the device doesn't ... Exchange 2003 SP2 server. ...
    (microsoft.public.pocketpc.activesync)