Re: SBS 2k3 CA - How can I issue a *.ourdomain.com certificate ?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Jacky

thank your for the follow up.
I heavn't checked your last insrtuctions as i am still lost in these
matters, but thank you for the update request i got yesterday. not forgotten

well, sbs premium, sp1
i got a messagen saying that i can't issue a wildcard certificate.

i will ( dunno when ) follow your instructions and post back.

thank you in advance and best regards and have a nice weekend.

Pedro
----------------------------------------------------
""Jacky Luo [MSFT]"" <v-jaluo@xxxxxxxxxxxxxxxxxxxx> escreveu na mensagem
news:AyucwgUmHHA.3352@xxxxxxxxxxxxxxxxxxxxxxxxx
Hi Pedro,

Thanks for posting here.

From the description, I understand the issue is that you get hung when
going through the Firewall configuration and you want to issue
*.ourdomain.com certificate. If I am off base, please don't hesitate to
let
me know.

Before we go any further, may I know if you are using the Standard or
Premium Edition (with or without SP1 installed)? For the Premium Edition,
if we don't properly configure the ISA Server 2000 or 2004, the outbound
traffic will be denied by the ISA. If you are using the Standard Edition,
the CEICW Wizard will configure the RRAS component to be the basic
firewall.

Let us refer to the following steps to troubleshoot the issue:

I.How many NIC are installed on the SBS 2003 server box? If this is a
server with single NIC and the ISA is installed in integrated mode
(firewall and caching), please uninstall the ISA and reinstall it in
caching mode only. Rerun CEICW to see if the problem will be resolved.

II.I have seen a similar issue being resolved by reinstalling the
Administration tools. Please try the following steps:

1. Click Start, point to Control Panel and click Add or Remove Programs.

2. Click Windows Small Business Server 2003 and click Change/Remove.

3. Go through the wizards until the Component Selection dialog box is
displayed.

4. Select Reinstall for Server Tools, and follow the wizard to finish
reinstallation.

5. Then run again CEICW.

III.Please take your time to rerun CEICW wizard. This wizard helps to
configure network and publish website correctly.

To do this:

1. Click Start, click Server Management. Click To Do List and then click
"Connect to the Internet".? Click Next, and go through the Internet
option.

2. Select Enable firewall and click Next.

3. On the Web Services Configuration page shows, select item according to
your enviroment. Click Next.

4. On the Web Server Certificate page shows. Select "Create a new Web
server certificate", and type your FQDN (mail.ourdomain.com) in the "Web
server name" text box. Click Next.

NOTE: If you choose to create a new Web server certificate (private
certificate), you should type the public FQDN that you will use to access
the sites (for example, if your public FQDN that you use to access the
sites is mail.ourdomain.com, you should type mail.ourdomain.com as the new
certificate name).

5. Go through the steps to finish the wizard.

Note:you cannot issue *.ourdomain.com certificate,Please issue the actual
domain name as certificate name,such as webmail.ourdomain.com

For more information, please refer to:

825763 How to configure Internet access in Windows Small Business Server
2003

http://support.microsoft.com/?id=825763


If the issue persists, please help me collect the following information
for
analysis:

1. Make a screen capture of the error message in the CEICW:

A. Press Alt + Pr Scrn to capture a screen shot.

B. From Start, go to Run, enter pbrush in the Open box, and then click OK.

C. Use Ctrl + V to paste the screen shot to the canvas.

D. From the File menu, go to Save and save as a JPG file and send it to me
at v-jaluo@xxxxxxxxxxxxx


2.%sbsprogramdir%\Support\icwlog.txt.

3.%sbsprogramdir%\networking\icw\icwdetails.htm

%sbsprogramdir%\networking\icw\icwdetails*.htm


Note: each time the Configure E-mail and Internet Connection Wizard is
run,

a new .htm file is automatically generated to preserve the previous
settings.

For example, Icwdetails1.htm, Icwdetails2.htm, and so on.


Please zip all files and send to me at v-jaluo@xxxxxxxxxxxxx


I appreciate your time. I am happy to be of assistance and look forward to
your reply.


Have a nice day!

Best regards,

Jacky Luo (MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

====================================================

PLEASE NOTE: The partner managed newsgroups are provided to

assist with break/fix issues and simple how to questions.

We also love to hear your product feedback! Let us know what you think by

posting

from the web interface: Partner Feedback

from your newsreader: microsoft.private.directaccess.partnerfeedback.

We look forward to hearing from you!

====================================================

When responding to posts, please "Reply to Group" via your newsreader

so that others may learn and benefit from this issue.

====================================================

This posting is provided "AS IS" with no warranties, and confers no
rights.

====================================================



.



Relevant Pages

  • RE: CEICW fails on create on create secure web site configuration
    ... In the "Component Selection" page, change Action to Reinstall for Server ... Restart SBS and rerun CEICW. ... Delete SBS CompanyWeb Listener and SBS Web Listener ... On the "Web Server Certificate" page, choose to create a new Web server ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and self signed SSL certificate
    ... In CEICW, what did the Web server certificate page show: ... then when I click on the RWW I get a security warning about ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW and certificate FQDN
    ... CEICW still produced errors. ... CEICW was able to run and create the certificate ... Downloading and Installing Windows Small Business Server 2003 Service Pack ... Make sure your SBS internal and external network interface DNS is ...
    (microsoft.public.windows.server.sbs)
  • RE: 500 Internal Server Error
    ... I rerun CEICW according to your suggestion and everything works again great. ... Do you use self-singed certificate or commercial certificate? ... Please open SBS 2003 Server Management, ... List, click "Connect to the Internet" to bring up CEICW, click Next, select ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2k3 CA - How can I issue a *.ourdomain.com certificate ?
    ... the CEICW Wizard will configure the RRAS component to be the basic firewall. ... I.How many NIC are installed on the SBS 2003 server box? ... On the Web Server Certificate page shows. ...
    (microsoft.public.windows.server.sbs)