Windows Thread, ISA 2004 and SSL certs in Technical; I have recently bought an SSL cert from Thawte file extension .crt however having put it in trusted certificates and ...
-
13th November 2008, 12:12 PM #1 ISA 2004 and SSL certs
I have recently bought an SSL cert from Thawte file extension .crt however having put it in trusted certificates and in personal certificates via the MMC snap-in however when I go to add the cert to a SharePoint weblistener in isa and go to the certificates tab and click to change it, it does not show up!?
Wes
-
-
IDG Tech News
-
13th November 2008, 12:50 PM #2 
Originally Posted by
wesleyw
I have recently bought an SSL cert from Thawte file extension .crt however having put it in trusted certificates and in personal certificates via the MMC snap-in however when I go to add the cert to a SharePoint weblistener in isa and go to the certificates tab and click to change it, it does not show up!?
Wes
Hi you need to refresh the isa console after installing the certificate or alternatively come out of the isa management console and re-launch it and try again.
I think you only need to place the certificate in the personal store. You would need to install the thawte root cert in the Trusted Root Certification Authority if its not already there.
HTH,
Ash.
-
-
13th November 2008, 01:01 PM #3 I used IIS SSL wizard to import our certifcate, thats the only way i could get it to show up in isa, then just remove the cert from the virtual folder in iis..
shoddy work around but it worked for me
-
-
13th November 2008, 01:26 PM #4 Sadly Thawte is in the Trusted section still the cert doesn't show up!
Wes
-
-
13th November 2008, 01:26 PM #5 @PRicho how did you do that?
Wes
-
-
13th November 2008, 03:13 PM #6 Did you make sure to put it in the machine certificates store rather than the user one?
-
-
13th November 2008, 03:17 PM #7 Yes. However just realised my mistake if you export the cert via IIS it doesn't give you the option of exporting the private key along with it. If you use MMC and the snap in it does once I'd done that it worked fine. Now I have to sort out the problems I get when running the system via the external site url everytime I click on sections for SLG (SIMS web parts) it just states "unknown error" any thoughts?
Wes
-
-
13th November 2008, 03:34 PM #8 I think.. i just went onto the default website in IIS and ran through the web cert wizard, cant remember what format out cert was in though.
Are you trying to make your SLG ssl secure? we are going to attempt to do this, capita have sent me some very vague instructions for changes we need to make to some webparts.
-
-
13th November 2008, 03:39 PM #9 We're setting up our sharepoint server published through ISA to allow parents, staff, pupils and governors access to the range of information and editing (in the case of teachers) attendance, assessment and profiles.
How vague are they?
Wes
-
-
13th November 2008, 03:42 PM #10 Basically you need to make the cert for your IIS box's request not ISA's request. When you import the cert make sure its marked as exportable. Onces its imported then find the cert and export it with the private key (you will be asked to set a password)
Once exported remove the cert from being the IIS cert of choice and use one that has been issued from you internal CA. Import the cert on ISA and then you should be able to use it there.
I know isa-server.org has a guide on how to set this up for forms based auth using exchange and the procedure should be much the same I *think*.
-
-
13th November 2008, 03:56 PM #11 
Originally Posted by
wesleyw
Yes. However just realised my mistake if you export the cert via IIS it doesn't give you the option of exporting the private key along with it. If you use MMC and the snap in it does once I'd done that it worked fine. Now I have to sort out the problems I get when running the system via the external site url everytime I click on sections for SLG (SIMS web parts) it just states "unknown error" any thoughts?
Not sure on this one as the error is rather unspecific
. Could the webpart itself be pointing directly to an internal resource that it does not have access to when opened externally?
-
-
13th November 2008, 04:37 PM #12 My thoughts exactly I think that the SLG webparts aren't setup to allow the external access mapping I've created.
Wes
-
SHARE:
Similar Threads
-
Replies: 7
Last Post: 4th August 2008, 01:50 PM
-
By ICTNUT in forum Windows
Replies: 0
Last Post: 15th November 2007, 01:09 PM
-
By Gatt in forum How do you do....it?
Replies: 25
Last Post: 18th October 2007, 10:18 AM
-
By eejit in forum Windows
Replies: 2
Last Post: 29th January 2007, 02:20 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules