Jump to content

Recommended Posts

Posted

Hi Everyone,

 

Not been on here for a while but we had the same problem, I've renewed both of our certificates with ipsCA and I had to manually install the up-to-date root kit on the servers.

 

Followed their instructions for the Global CA and Intermediate CA, once these are installed teachers connecting to the OWA address were no longer getting the "This is not a trusted site" message however when I returned to work on the Monday morning everybody inside the network were getting the "this is not a trusted site" message even though WSUS had installed all its updates.

 

I went into the default domain GPO and added the Global CA to the Trusted intermediate certificates store This means upon a restart all the computers were picking this up.

 

One finale thing was to create a zone in DNS so that when users inside went to the https://our-domain.com it would automatically point to the internal address rather that going out and then back in.

 

Hope this will help you guys, let me know if i can assist you in anyway

 

Cheers

 

Matt Gibson

  • Thanks 1
Posted
Just to say I have had a new certificate from Ipsca and after following advice updating global and level 1 certs and installed cert update pack then certificate works fine internally and externally so worth it for anyone looking for free certificates.
  • 1 month later...
Posted

I installed the new root ca on our tmg box but till get the problem the cert has been revoked. This is a right bloody pain

 

any know were you can get cheap ssl wild card certs?

Posted
I installed the new root ca on our tmg box but till get the problem the cert has been revoked. This is a right bloody pain

 

any know were you can get cheap ssl wild card certs?

Go Daddy did mine was cheap enough :)

Posted
I installed the new root ca on our tmg box but till get the problem the cert has been revoked. This is a right bloody pain

 

any know were you can get cheap ssl wild card certs?

 

A server reboot fixed this for us. Now the ipsCA cert is recognised by IE with the latest updates installed. We're still waiting for other browsers to update. As we only use the cert for webmail this isn't really a problem for us; we just put an explanation about the warning on our homepage.

Posted
I installed the new root ca on our tmg box but till get the problem the cert has been revoked. This is a right bloody pain

 

any know were you can get cheap ssl wild card certs?

 

IPCSA cert working here too.

 

On exchange 2003 and Forefront UAG 2010 (TMG components), the cert is working on both of those.

 

Have you whitelisted the CRLs listed in the cert on your proxy??

Posted

I looked at GoDaddy and RapidSSL, after IpsCA revoked their cert. I went with rapidSSL in the end. They were quick, easy to install, and cheap.

 

The one month freeSSL was a bit harder to set up as it involved an automated telephone authentication stage.

 

Mmmm... I've just looked at RapidSSL again whilst typing this, and their prices are much higher than I paid (was about £15, now £49 per year). Either they've put their prices up, or I got an education discount. :confused:

Posted
I've got our certificate from ipsca but I asked for one for The Warwick School, should I have asked for one for https://webmail.warwick.surrey.sch.uk as its saying the cert is not valid?

 

You should get *.warwick.surrey.sch.uk

 

 

Exchange 2003 will accept this cert.

 

Exchange 2007/2010 will require a UC cert (cost about 150 a year), unless you protect it with something like UAG where you can ignore internal certs.

Posted

It looks like you have to pay for a wildcard. It didn't like webmail.warwick.surrey.sch.uk as it dodn't recognise it as our domian name, here was the response:

 

SSL Server Certificate Request Denied for: SERVER AND DOMAIN UNKNOWN

 

Dear Mr/Mrs Davis, Graham

 

Your SSL Certificate Request has been denied for the following reason:

 

Your CSR file information cannot be read.

 

Possible reasons are:

 

1.- You did not paste a correct formated Base64 CSR file.

 

2.- You did not paste the complete CSR Text or you did not include the full BEGIN and END lines with all dashes.

 

3.- You included characters not allowed in the request.

 

Please make sure that the COMMON NAME (CN) in your CSR is the Fully-Qualified Domain Name (example: IndexPortada ) of your OWN Server, or if it is an intranet server, use the network name of your server.

 

 

:confused: What now?

Posted

Right the wildcard works on the server, lets hope we don't get a sneaky bill through the post !!

Which certs do I need to roll out via gpo and how as I now have :

 

1. *.warwick.surrey.sch.uk

2. ipsCALEVEL1.cer

3. ipscaGlobal.cer

  • 2 months later...
Posted
I looked at GoDaddy and RapidSSL, after IpsCA revoked their cert. I went with rapidSSL in the end. They were quick, easy to install, and cheap.

 

The one month freeSSL was a bit harder to set up as it involved an automated telephone authentication stage.

 

Mmmm... I've just looked at RapidSSL again whilst typing this, and their prices are much higher than I paid (was about £15, now £49 per year). Either they've put their prices up, or I got an education discount. :confused:

 

Update: I've just remembered I bought the RapidSSL certs through trustico. They're much cheaper that way at £14.70 per year, with discounts for longer term. Fast efficient service too.

  • 11 months later...
Posted
Are these guys still a valid SSL Cert company? Does any info get sent to them data-wise? I'm not entirely sure how SSL works. I would like to secure the connection between my VLE and the clients accessing it. i would also like to secure the connection on my website and webmail system.
  • 3 weeks later...
Posted (edited)

Another +1 for IPSCA here. Installed the cert for Sharepoint 2010 on IIS and ISA 2006 and all works fine in IE.

 

They still haven't installed their root CA into Firefox's repository yet, well over a year since it was last discussed.

 

Frankly I think the other cert vendors ought to follow this lead and allow free certs for educational establishments. We are not using the cert to facilitate eCommerce to make money. We use it to secure student data for teaching. A non commerical, not for profit free educational cert should be mandatory.

 

I used to use StartCOM at home when using Exchange. However they need to send the validation email to your TLD. Which in my cast is either hostmaster/postmaster/administrator@bham.sch.uk. I did ask back at my old school whether they'd pass the emails on so I could a free one for portal.school.bham.sch.uk but they refused. I assume they believed I could then issue certs for all schools under the TLD.

 

I didn't realise you could get a wildcard cert from IPSCA. I just choose portal.schoolname.bham.sch.uk. Frankly with ISA you can push everything through on one address anyway.

 

Anyway no more cert errors!

 

I do miss the old days of self signing. It was frankly funny to hear a friend tell me about when she was scammed. She said that the website had the "Padlock" icon to say it was secure, so how did she get scammed? I told her that her credit card details were sent securely, just direct to the scammers! I assume thats why in IE7+ self signing certs give errors.

Edited by Trapper
Removed school name. Dang AUP.
  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...