Groups | Blog | Home
all groups > iis security > february 2004 >

iis security : SSL questions


Mike
2/12/2004 10:24:42 AM
Please help

I am looking to get a SSL Cert from Verisign and I have a domain name
question/issue.

I have a public FQDN for my domain and I want to run MS Outlook Web Access
on my Windows 2003 Server running IIS 6.0. The issue I have is that the
local domain name varies from the public domain.

Public is Enviro-Asmnt.com
Local Private: Office.Enviro-Asmnt.
I create a Cert key from IISM 6.0 to have a trial key with a common name of
mail.enviro-asmnt.com
I installed the key and attempted to access the page from an out souce and I
get a security alert. It does not ask if I would access the Cert like I
have seen before.

If I do it locally I do not have the problem.

I did create a DNS record (A) for mail.enviro-asmnt.com
Maybe that is way locally it works.

Can anyone give some advice on how I can get around this security alert pop
up.

Thank you

Kylet NO[at]SPAM online.microsoft.com
2/15/2004 1:06:01 AM
Hi Mike,

You can only choose one common name for your certificate so the popup will
only not show up when you use the URL that matches it to access the site.
I'd suggest using the external URL as the common name and then letting your
internal users know they will have to hit OK to the popup. The other way
around this would be to create another site that points to the same content
that has a different certificate installed with the other common name.

Hope this helps!

Kyle Terns, MCSD [MSFT]

***********************
[quoted text, click to view]
account name for newsgroup participation only.<<

This posting is provided "AS IS" with no warranties, and confers no rights.
You assume all risk for your use.
© 2003 Microsoft Corporation. All rights reserved.
***********************


--------------------
| From: "Mike" <thisisafakeaddress@yahoo.com>
| Subject: SSL questions
| Date: Thu, 12 Feb 2004 10:24:42 -0500
| Lines: 28
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
| Message-ID: <u9e47wX8DHA.2116@TK2MSFTNGP10.phx.gbl>
| Newsgroups: microsoft.public.inetserver.iis.security
| NNTP-Posting-Host: ool-18bf8b12.dyn.optonline.net 24.191.139.18
| Path:
cpmsftngxa07.phx.gbl!cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.
phx.gbl
| Xref: cpmsftngxa07.phx.gbl microsoft.public.inetserver.iis.security:9426
| X-Tomcat-NG: microsoft.public.inetserver.iis.security
|
| Please help
|
| I am looking to get a SSL Cert from Verisign and I have a domain name
| question/issue.
|
| I have a public FQDN for my domain and I want to run MS Outlook Web Access
| on my Windows 2003 Server running IIS 6.0. The issue I have is that the
| local domain name varies from the public domain.
|
| Public is Enviro-Asmnt.com
| Local Private: Office.Enviro-Asmnt.
| I create a Cert key from IISM 6.0 to have a trial key with a common name
of
| mail.enviro-asmnt.com
| I installed the key and attempted to access the page from an out souce
and I
| get a security alert. It does not ask if I would access the Cert like I
| have seen before.
|
| If I do it locally I do not have the problem.
|
| I did create a DNS record (A) for mail.enviro-asmnt.com
| Maybe that is way locally it works.
|
| Can anyone give some advice on how I can get around this security alert
pop
| up.
|
| Thank you
|
|
|
AddThis Social Bookmark Button