Jump to content

Recommended Posts

Posted

I'm trying to put our (purchased) SSL cert onto our TMG server to secure access to OWA. I've installed the intermediate cert and the actual cert into the Computer certificates using the MMC plugin, and I can see both installed.

 

Problem is, when I try and assign the certificate to the listener, TMG shows the certificate as invalud - private key not installed.

 

Am I missing a step out? I though the intermediate cert identified the CA we bought it from, and the certificate itself was for us to secure our site?

Posted
Are you sure you've got the right type of certificate? You need a Unified Communications SSL certificate with all the subject alternative names (OWA url, autodiscover url and internal CAS server names).
Posted

Did you create the cert request on the same server as TMG?

 

If not then import the cert onto the server that you created the request on then right click and select export - you should have the option to include the private key and it will require you to select a password.

Then import this exported key onto your TMG server (again enter the password) and this should show as a valid key.

 

Even if you created the cert request on the TMG server try this anyway as any key that you get from a provider won't include the private key and so it needs to be mashed into the cert to make it work.

Posted (edited)

Ahh no I used an internal web server to create the CSR, I'll try importing and exporting it from there!

 

Edit - when I try this there is no option to export the private key? I requested a domain wildcard ssl for several sites/subsites that will be on our domain so the cert shows *.domain

Edited by Sheridan
Posted
Are you trying to export it from the MMC or the IIS, sometimes you can grab it out of IIS easier depending on the server version.
  • Thanks 1
Posted
Ahh no I used an internal web server to create the CSR, I'll try importing and exporting it from there!

 

Edit - when I try this there is no option to export the private key? I requested a domain wildcard ssl for several sites/subsites that will be on our domain so the cert shows *.domain

 

You might have the problem described here then - Certification Authority Maintenance

 

Give the repair store command a go (at the very bottom of the Microsoft part of the article) you can find the certs hex key by going into its properties.

  • Thanks 1
Posted
Finally got it to export with the private key - from the server where the CSR was created but using the IIS dialogue instead of the MMC - bit of a carry on but got there in the end. Cheers for the ideas!
Posted
Finally got it to export with the private key - from the server where the CSR was created but using the IIS dialogue instead of the MMC - bit of a carry on but got there in the end. Cheers for the ideas!

 

Good to hear it worked in the end! Personaly I hate all the messing around that needs to be done with SSLs and its why we get them on a 5 year basis!

Posted

I'm still messing about with this.Installed the cert onto the TMG and its now securing the OWA site I wanted to publish. Works fine generally with IE browsers and seems to still generate a warning on Firefox/Seamonkey.

 

So I merged the server certificate and intermediate certificate together, and imported that. Same problem. Oddly the TMG shows the certificate as valid all the way up the certification chain so it has no problem with the intermediate ca, so what is firefox's issue with the certificate? Even more odd, the same certificate is installed on our citrix access gateway and all the browsers I've tried so far (firefox,ie,seamonkey,safari) have been happy with it!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...