Groups | Blog | Home
all groups > iis security > october 2004 >

iis security : HTTPS not working from some clients


Dom
10/20/2004 11:07:04 AM
Hello !

I use Windows Server Certificates. Enabled the "require secure channel"
option for a virtual directory.
From some clients i can access the directory. A message pops up in IE, saying
that the certificate wasn't issued by a trusted ca.
Then I click yes and it works fine. O.K. so far.

But from some clients i cannot access the directory. The message doesn't
show up.
I compared almost every setting in IE, they're the same.

No Firewall issue. I see the client connect to 443.

Any ideas, why some clients can't access the dir ? Same IE Version, same
settings.

Dom
10/20/2004 11:51:52 AM

sorry, forgot to mention, that I use IIS 6.0 on a Win2k3 server.
ssldiag shows no errors....


[quoted text, click to view]
Miha Pihler
10/20/2004 8:49:33 PM
Hi,

are these client on LAN? How long did you wait -- this can take a while if
the client doesn't not trust the certificate -- it also depends on
connection speed...? What was the error on screen?

Install CA certificate on the client (this will make computer trust the
certificate) and try again. See if there is any difference.

Mike

[quoted text, click to view]

Dom
10/20/2004 11:53:03 PM

Hi, thanks for the answer.

All clients on LAN can access the directory (OWA virt. Directory).
Also some public clients can, but not all of them.

The error message is "the page contains no data" in mozilla.
If I turn off friendly http error messages in IE, it just says "Done"
and the page is all blank. If i turn on friendly messages, "I get a Page
cannot be displayed" error.

I'll try to install the cert on the client, to see what happens.

[quoted text, click to view]
Bernard
10/21/2004 11:50:58 AM
"But from some clients i cannot access the directory. The message doesn't
show up."

so ? what info is displayed ?
check IIS log file too.


--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

Jason Rowley
10/27/2004 10:02:23 AM
We had a similar problem with SSL pages not loading, we tracked down the
issue to a third party ISAPI Filter we had, when we disabled that filter SSL
was working fine. Check to see if you have any Third Party ISAPI Filter
(running either on the inidividual site or globally) and test disabling them
to see if that corrects your problem.

Jason Rowley

[quoted text, click to view]

Dom
11/10/2004 12:19:02 AM

thanks for the hint. I checked for that, unfortunately we have no
3. part. ISAPI Filters.

I figured out, that it isn't a client problem. If I take the same computer,
I can connect
from location A but not from location B.
Both behind ADSL lines....
This means, that some of our employes can connect and some can't. I can't
get to figure
out on what it depends whether they can connect or not.....
No banned IP's or such things. I see the https connection in the firewall
logs.....

Any ideas ?

[quoted text, click to view]
Bernard
11/10/2004 4:33:49 PM
[quoted text, click to view]

from both location A and B ?

can you do a 'telnet yourip 443' from both site ?
you should get a black screen if the port is open.



--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

AddThis Social Bookmark Button