all groups > iis security > april 2006 >
You're in the

iis security

group:

Certificates on .local domain


Certificates on .local domain Juha Kalliola
4/18/2006 9:05:03 AM
iis security:
Hi,

we are using SBS2003 with outlook web access and active sync.
I have been trying to make working certificate with more or less success.

How should it be made.
Our sbs domain is with suffix .local. We have a public IP address for our
server.
I can connect to OWA with public IP address. But how should the certificate
Re: Certificates on .local domain Juha Kalliola
4/18/2006 10:34:01 AM
I got it working once. After I madeome changes but haven't got it working
anymore.
I can accept and install certificates to my phone and that is not the problem.
The problem is on the server and with the certificate. And as I mentioned I
got it working once but not anymore.

[quoted text, click to view]
Re: Certificates on .local domain Miha Pihler [MVP]
4/18/2006 7:10:23 PM
Hi,

Are you connecting to OWA over HTTPS (SSL)?

The problem with some phones is that they will not allow (at least by
default) to see the pages protected with certificates that they do not
trust. So the simple solution is to buy a certificate from commercial CA
server like Thawte or VeriSign.

--
Mike
Microsoft MVP - Windows Security

[quoted text, click to view]

Re: Certificates on .local domain Juha Kalliola
4/19/2006 4:37:01 AM
Thanks Ken,

Could you tell me also how can I configure FQDN like yours to my SBS server?
Where I configure it?

Best,
Juha

[quoted text, click to view]
Re: Certificates on .local domain Juha Kalliola
4/19/2006 6:31:02 AM
Thanks Bernard,

I have registered domain name. The article you included is about FTP. How
does it help me in this case?

Best,
Juha

[quoted text, click to view]
Re: Certificates on .local domain Juha Kalliola
4/19/2006 7:53:01 AM
I'm sorry but I don't understand. If I give you details could you help me out.

Our server is "serveri.itadmina.local", it has a public IP address.
Our mailboxes and web server is on ISP. We use POP3 connector to collect
email from ISP to Exchange.

Our registered domain is "itadmina.fi".
Where and what changes I must do on our internal server to have this FQDN
recorded there?

[quoted text, click to view]
Re: Certificates on .local domain Ken Schaefer
4/19/2006 9:17:11 PM
Hi,

The "common name" of the certificate should match whatever DNS name you are
using in your phone to connect to the Server ActiveSync or OMA website.

For example, my SBS server has in the .local domain (and that's how we
access it internally).

However, for external access it has a host.adopenstatic.com FQDN. The
certificate that I installed has a common name that matches
host.adopenstatic.com

Cheers
Ken

--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken


[quoted text, click to view]

Re: Certificates on .local domain Bernard Cheah [MVP]
4/19/2006 9:23:54 PM
First, you need to register a domain...... then ......
Read http://support.microsoft.com/?id=816525

--
Regards,
Bernard Cheah
http://www.iis-resources.com/
http://www.iiswebcastseries.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: Certificates on .local domain Bernard Cheah [MVP]
4/19/2006 9:36:29 PM
The FQDN concept apply, so you need to create a Host record that match your
cert common name and point it to your server.

--
Regards,
Bernard Cheah
http://www.iis-resources.com/
http://www.iiswebcastseries.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: Certificates on .local domain Ken Schaefer
4/20/2006 12:00:00 AM
Hi,

Your public domain (itadmin.fi) needs public DNS servers. This allows remote
users to lookup hosts in the itadmin.fi domain, and find the associated IP
addresses.

When you registered the domain, you need to specify authorative DNS servers
for the domain. Those are the public DNS servers for the domain. On those
DNS servers you need to create an appropriate A (Alias) or CNAME (canonical
name) record that points somehostname.itadmin.fi -> your public IP address.

Cheers
Ken

[quoted text, click to view]

Re: Certificates on .local domain Juha Kalliola
4/20/2006 2:31:01 AM
Thanks Ken,

this was the answer I was looking for.

[quoted text, click to view]
Re: Certificates on .local domain Juha Kalliola
4/21/2006 8:10:02 AM
Hi Ken,

I hope you still read this post.

I made a record on DNS somehost.itadmina.fi. (not actually that name) I made
a new certificate on DefaultWeb. Everything seems to be fine. When I go to
https://somehost.itadmina.fi from my home (for example) I can install the
certificate and it says issuer is somehost.itadmina.fi.

When I export the certificate for using in my phone, it says the issuer is
somehost.itadmina.local. When I install it to phone at set it trusted it is
not trusted. So this is my problem now. Why in my phone the same certificate
says that issuer is .local and in my desktop .fi?? I don't undertand.

Please help me if you can.

Best,
Juha

[quoted text, click to view]
AddThis Social Bookmark Button