Re: Failure installing SSL certificate on SBS2003PremSP1 (incl. IS



Hi,

I've had a similar problem which started with activesync 4.1 not accepting
my wm5 pda. I decided to purchase a CA SSL key and replace the self cert on
my sbs 2003 server. This is where the problems have started.

I followed the same route as posted by Alex. Removed the self cert and
requested a CSR. Purchased a third party Cert and installed it on the default
web site. However when I go and run the Internet and Email wizard it won't
accept the 3rd party SSL cert. I imported the cert into the personal section
using the Certificates snap-in. However under ISA 2004 sbs web listener, it
doesn't show up in the SSL list to choose from. What do I need to do?

When I go to https://mail.servername.com/exchange it brings up an error
code: 403 forbidden. Also the security ssl cert still shows up as the self
cert.

I have googled for 3 days looking for a solution or instructions to what
seemed like a common straight forward task. Please help!

Lyj





"Steve Foster [SBS MVP]" wrote:

Alex wrote:

I have spent most of Friday, all Monday and two days previously trying to
get
a CA generated SSL cert to import into the ConnectToInternet wizard. It is
a
nightmare. All Friday and Monday and two chaps at MS Partnet support (in
India I think) have been trying to help.

Basically I generate the certreq.txt as per CtoI wizard help instructions,
send it off to my CA, I get back a .crt file or a .cer file. This will

Which CA?


manually import into IIS6 but never into the CtoI wizard. I also think that
it is critical to get it working through the SBS wizard and not manually in
the IIS wizard because clearly ISA2004 needs some configuring done as well
or
even instead of IIS. Basically I think the SBS web listener needs to be
changed, but if I try, my newly manually imported cert does not appear in
the
list of available certs to change to so I am stuck.

If the certificate is properly installed in IIS, it should be available to
ISA, since both are working off the same certificate store.

You did complete the IIS certificate request process, right? It knows that
the request is pending, and the import should complete that process.

You can also look at the Certificate store directly, by running MMC, and
adding the Certificates snap-in pointing it to the Local Computer account.
You should find the SBS self-signed certificates, and the IIS imported
real certificate under Personal Certificates.

You can also, if necessary, import the certificate directly from this
snap-in too.

Could someone definitively say whether the Connect To Internet wizard for
SBS2003PremiumSP1/ISA2004 works properly when importing a .cer file back
from
my CA, and what kind of .cer file should I be asking for from my CA?
Should I
ask for IIS6 compatible or SBS2003 or ISA2004 or something else?
And if, as I suspect, actually the ConnectToInternet wizard does not
correctly deal with ISA2004, could someone tell me what I do next?

The only change in ISA is to associate the two SBS web listeners to the
new external certificate. It's easy enough to do this directly in the ISA
Management MMC.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.

.



Relevant Pages

  • Re: 400 Bad Request Error
    ... Thanks for the reply,it does not look like the partner is using 2 different ... I have that cert imported into my trusted people certificate store for the ... I tried adding a client cert and without one and it is the same result.I do ... use a SSL connection on a different certificate. ...
    (microsoft.public.biztalk.server)
  • Heads Up: SSL defeated in IE and Konqueror
    ... SSL defeated in IE and Konqueror ... VeriSign SSL site certificate to forge any other VeriSign SSL site certificate, ... tricky site owner signs an intermediate cert with another valid cert, ...
    (comp.os.linux.security)
  • Re: Publishing SSL WebSite....Arghhhh
    ... "Revocation Information for the Security Certificate is not ... (yes/no/view cert). ... The SSL cert appears to be working fine now. ... he mentioned he saw an SSL session and no error message - go figure? ...
    (microsoft.public.isa)
  • Re: Publishing SSL WebSite....Arghhhh
    ... to web publishing that site and SSL so I entered my site's name in the ... certificate; when you export the web server certificate, ... I tried to re-export the cert from the web server but the options it ... How to export a certificate with the private key: ...
    (microsoft.public.isa)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... > Then the world would have no problem trusting your domain level PKI ... coined the term "certificate manufacturing" to distinquish from actual ... it turns out that one of the reasons for the SSL server domain name ...
    (sci.crypt)