RE: Multiple Certificates On SBS



Hello Jenny and thank you for the info!

I tried to follow your instructions but I was derailed. Here's what happens:

This is how it's setup before I run CEICW:

1. The default website/directory security/view cert in IIS shows a cert
installed by the name of publishing.domain.local (self created)

2. When you access the RWW web page and click on the golden lock in the
bottom right hand side of the browser window shows the cert being used as
"mail.company.com" (pur purchased cert)

Then I tried to create a new cert by the name of Intra.company.com. (that
worked)
I assigned it to the appropriate site but then I could not get the original
(purchased) cert back as the "default" cert used by the server. It caused all
the people that use pocket PC's for email to stop functioning.

Also, can you make SBS stop sending email to every user every time the
wizard is run?

Lastly, if you could recommend a good document that will set me straight on
all this CERT talk I would greatly appreciate it!



I don't see anywhere in IIS where that cert is installed. Is there another
place to install a cert for use by ISA?





""Jenny wu [MSFT]"" wrote:

Hi,

Thanks for using the SBS newsgroup.

From your description, I understand that you want to know if you can create
two private certificates for two different sites in SBS 2003 environment.
If I am off base, please don’t hesitate to let me know.

Yes, we can. When we run CEICW (server Management console -> Configuration
E-mail and Internet connection wizard -> connect to the internet), there is
1 certificate created that is located in default website. If you want to
create an additional certificate yourself for using on a different site,
you can run CEICW to create cert named CertA, then export the cert. Next,
run CEICW to create cert name CertB, next, import the cert CertA to
anywhere you want. After CEICW created the cert, it is located in default
website and you can then export the certificate in the ''Directory
Security'' tab, ''Server Certificate'' and ''Export the current certificate
to a .pfx file''. Then, you can import the certificate to desired Websites
by following the steps outlined in the following KB Q816794.

HOW TO: Install Imported Certificates on a Web Server in Windows Server 2003
http://support.microsoft.com/?id=816794

However, please note that if you are using ISA to web publishing out your
websites, only 1 certificate can be bound to 1 ISA Incoming Listener,
that''s to say, if you only have external interface which the Incoming
Listener is listening on, you only can use 1 certificate for all of your
web published sites.

The sub-directories under the same IIS WebSite will use the same
certificate. For example, OWA and RWW will use the same certificate and
there''s no way to configure them to use different certificates since
they''re both under ''Default Website''.

Hope above information helps! I am happy to be of assistance to you and
look forward to your reply.

Have a nice day!

Sincerely,

Jenny Wu
Microsoft CSS Online Newsgroup Support
Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
Thread-Topic: Multiple Certificates On SBS
thread-index: AcY+DdDtGgJvB5bFQf2hG6jBQQHhuw==
X-WBNR-Posting-Host: 129.9.163.105
From: "=?Utf-8?B?SG90U2l6emF1Y2U=?="
<HotSizzauce@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Multiple Certificates On SBS
Date: Thu, 2 Mar 2006 07:27:28 -0800
Lines: 9
Message-ID: <EBD3D029-8C9A-4EF7-AE80-6728660753A0@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
Newsgroups: microsoft.public.windows.server.sbs
Path: TK2MSFTNGXA03.phx.gbl
Xref: TK2MSFTNGXA03.phx.gbl microsoft.public.windows.server.sbs:248773
NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.sbs

Hello,

Is it possible to have more than one self created cert on one server? We
are
running 2 separate sites that are accessable only by our employees and it
seems a waste to use a trusted authority to issue the cert for this
function
but i can only seem to have one self made cert at a time. (one over writes
the other when you run the wizard)

Thanks all!



.



Relevant Pages

  • Re: Troubles with Microsoft Sharepoint Administration
    ... the CEICW cannot import the godaddy cert. ... The CEICW wizard is designed to generate a self-signed cert which (and if I ... allowing it to create the publishing.mydomain.com certificate. ...
    (microsoft.public.windows.server.sbs)
  • RE: CEICW after loading third party certificate
    ... Organization on Cert is www.mydomain.com" ... The name of the certificate attached to the SBS Outlook via the Internet Web ... "Error Code: 500 Internal Server Error. ... The purchased certificate has an OU name "www.mydomain.com" and the CEICW ...
    (microsoft.public.windows.server.sbs)
  • Re: Self-signed security certificates.. (oh, the evil)
    ... Think "What is a certificate from Thawte for?". ... Let us say I am too cheap or poor to buy a cert and use a self signed ... person who created the CMP website. ...
    (comp.lang.java.programmer)
  • Re: Trust a cert and cert purpose
    ... > Is there anyway that I can bypass the security alert and go to the website ... This Security Certificate Was Issued by a Company that You ... > CA created by myself (through MS Cert Server). ...
    (microsoft.public.inetserver.iis.security)
  • Re: SBS 2003 certificate problem affecting Exchange
    ... There was internet website except for the ... Email has worked fine, even OWA, as ... certificate errors. ... so tomorrow I'll try to create a cert issued to ...
    (microsoft.public.exchange.admin)