<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Security</title><link>http://forums.iis.net/1031.aspx</link><description>A forum aimed at helping understand IIS security such as Authentication, IP restrictions, and SSL</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Multiple SSL one server, multiple site or multiple virtual directories</title><link>http://forums.iis.net/thread/1925657.aspx</link><pubDate>Fri, 20 Nov 2009 20:01:31 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925657</guid><dc:creator>yanky999</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1925657.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925657</wfw:commentRss><description>&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;Ok, I have searched and could not find the exact scenario I may have.&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:10pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:10pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:10pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;Current configuration example setup:&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;&lt;/span&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;Host A record&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; External IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;NAT TbSrv Int IP:port&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;IISrvsite:ports&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;s&lt;/span&gt;ubdomain site&lt;/span&gt; 
&lt;p&gt;&lt;font size="2" face="Calibri"&gt;Client123&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.123 &lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:81&lt;span style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site123:81 no SSL&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; client&lt;/span&gt;t123.mysite.com&lt;/font&gt; &lt;/p&gt;
&lt;p&gt;&lt;font size="2" face="Calibri"&gt;Client456&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.456&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:82&lt;span style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site456:82 no SSL&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;client456.mysite.com&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client789&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.789&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:83&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site789:83&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;no SSL&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;client789.mysite.com&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client007&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.007&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:84&lt;span style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site007:84 no SSL&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;client007.mysite.com&lt;/font&gt;&lt;/p&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;I am looking to secure Client123,Client789, Client007 with a Multiple Domain SSL, although I am using just different subdomains at this time.&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2"&gt;&lt;font face="Calibri"&gt;I don’t believe I need to have a Host A record added by our ISP.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Do I add entries into my NAT table like this?&lt;/font&gt;&lt;/p&gt;&lt;span style="FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;FONT-SIZE:8pt;"&gt;Host A record&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; External IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;NAT Table Srv Int IP:port&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Srvsite&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client123&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.123:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:443&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site123:81 SSL port 443&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client789&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.789:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.201:444&amp;nbsp;&amp;nbsp; &lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site789:83 SSL port 444&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client007&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.007:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.202:445&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Site007:84 SSL port 445&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Note the change in the Int IP address for Client789 and Client007(I currently have only two NIC in the server, I would need to add a third?)&lt;/font&gt;&lt;/p&gt;&lt;font size="2" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Is there a better way to configure using just one SSL(443) site?&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;In the NAT table, can I have 3 entries for port 443 point to the same IIS site 443? Like below.&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client123&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.123:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:443&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;SiteSecure:85 SSL port 443&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client789&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.789:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:443&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;SiteSecure:85 SSL port 443&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Client007&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xx.xx.xx.007:443&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;yy.yy.yy.200:443&lt;span style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;SiteSecure:85 SSL port 443&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Then, within that one site(SiteSecure), use a virtual directory structure to access each individual client data.&lt;/font&gt;&lt;/p&gt;&lt;font size="2" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font size="2" face="Calibri"&gt;Sorry again for the length question. &lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Yanky999&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>SSL problem using 3rd party root certificate </title><link>http://forums.iis.net/thread/1925465.aspx</link><pubDate>Thu, 19 Nov 2009 20:48:42 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925465</guid><dc:creator>rppoor</dc:creator><slash:comments>3</slash:comments><comments>http://forums.iis.net/thread/1925465.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925465</wfw:commentRss><description>&lt;p&gt;We are using DoD and ECA certificates on one of our IIS 6.0 websites.&amp;nbsp; We are having a problem with IIS not providing the ECA Root CA 2 (2048 bit) certificate in the list of acceptable client certificate CA names when it is negotiating an SSL session.&amp;nbsp; We have &amp;#39;Require client certificates&amp;#39; enabled and we are not using a CTL.&amp;nbsp; The DoD Root CA 2 certificate works just fine.&amp;nbsp; Both certs are installed in the &amp;#39;Trusted Root Certificate Authorities&amp;#39; store.&amp;nbsp; I&amp;#39;m pulling my hair out on this.&amp;nbsp; Has anyone any idea what the problem and how to resolve it?&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Bob &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Mulitple sites at 443 - assign certificate problem</title><link>http://forums.iis.net/thread/1925249.aspx</link><pubDate>Wed, 18 Nov 2009 13:54:04 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925249</guid><dc:creator>wuwu</dc:creator><slash:comments>8</slash:comments><comments>http://forums.iis.net/thread/1925249.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925249</wfw:commentRss><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;i have two sites with ssl at the same port, 443 and to different certificates.&lt;/p&gt;
&lt;p&gt;I have installed the first WebApp, assign the first Certificate, Set Bindings for hostheather, assign ip-adress -&amp;gt; open the page, he shows me the page with the right certificate.&lt;/p&gt;
&lt;p&gt;I&amp;nbsp;configurate the secound WebApp with site. Assign secound Certificate (different to first one) to IIS Site, set bindings for hostheather, set ip-adress. When i open the page, he shows me the page with the right certificate (the secound one).&lt;/p&gt;
&lt;p&gt;After i make an IIS Reset and open the first page, he shows me the certificate from the secound page (secound certificate), why that?&lt;/p&gt;
&lt;p&gt;Windows Server 2003, IIS 6&lt;/p&gt;
&lt;p&gt;best regards,&lt;/p&gt;
&lt;p&gt;Horst&lt;/p&gt;</description></item><item><title>IIS Showing the user full connection string on deadlock?</title><link>http://forums.iis.net/thread/1925498.aspx</link><pubDate>Thu, 19 Nov 2009 22:48:17 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925498</guid><dc:creator>rusware</dc:creator><slash:comments>3</slash:comments><comments>http://forums.iis.net/thread/1925498.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925498</wfw:commentRss><description>&lt;p&gt;Sometimes on a website i built IIS will show&amp;nbsp;this error to the client&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;em&gt;&lt;font face="Times New Roman"&gt;Data Source=??????&lt;/font&gt;&lt;font face="Times New Roman"&gt;;Initial Catalog=????;Persist Security Info=True;User ID=????;Password=????&lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;br /&gt;&lt;span class="apple-style-span"&gt;&lt;font face="Times New Roman"&gt;&lt;em&gt;Transaction (Process ID 109) was deadlocked on lock resources with another process and has been chosen as the deadlock victim. Rerun the transaction.&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3" face="Times New Roman"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;font size="2"&gt;The server is Windows 2003 with debugging off and Web.config set to custom errors on.&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;font size="2"&gt;Anyone able to help me on this??&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="FONT-SIZE:13.5pt;mso-ansi-language:EN-US;"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;</description></item><item><title>ASPNET user Account got locked ..</title><link>http://forums.iis.net/thread/1925162.aspx</link><pubDate>Wed, 18 Nov 2009 01:59:11 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925162</guid><dc:creator>sasikumarg1983</dc:creator><slash:comments>7</slash:comments><comments>http://forums.iis.net/thread/1925162.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925162</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;We have lots of servers in the production environment&amp;nbsp;which has more than 300 applications hosted on the same. Some applications are also load balanced. Recently we are getting the issue like &amp;quot;ASPNET user is locked&amp;quot;. This is happening nowadays in all the servers. The OS installed is Windows server 2003 and IIS 6.0. Please help me&amp;nbsp;to find the issue. Thanks in advance.&lt;/p&gt;</description></item><item><title>Anonymous Access on IIS 6.0 error 401</title><link>http://forums.iis.net/thread/1925376.aspx</link><pubDate>Thu, 19 Nov 2009 09:10:44 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925376</guid><dc:creator>peteoc</dc:creator><slash:comments>3</slash:comments><comments>http://forums.iis.net/thread/1925376.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925376</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I&amp;#39;m having problems trying to configure an IIS website to work without requesting login credentials.&lt;br /&gt;I&amp;#39;ve setup anonymous access and unchecked the tick box for integrated access in the bottom section.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve even set the user for anonymous access to have full control of the directory to see if this helped but it doesn&amp;#39;t, I still get a 401 error.&lt;/p&gt;
&lt;p&gt;If I check the box for integrated security it them prompts for a password, if I enter my windows login details it works, if I click cancel I get error 401.&lt;/p&gt;
&lt;p&gt;Any help would be appreciated!!&lt;/p&gt;
&lt;p&gt;cheers&lt;/p&gt;
&lt;p&gt;Pete&lt;/p&gt;</description></item><item><title>Third-party Cryptographic Service Provider</title><link>http://forums.iis.net/thread/1925374.aspx</link><pubDate>Thu, 19 Nov 2009 09:04:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925374</guid><dc:creator>Ken Hui</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1925374.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925374</wfw:commentRss><description>Hi all,

I have tried ACOS5, which uses CSP, on Outlook for smart-card based digital ID. I would like to ask if third-part CSP product can be applied on IIS&amp;#39;s SSL web site too? My idea is: to store the SSL&amp;#39;s certificate inside the smart-card.

Thanks for advice.

Best regards,
Ken.</description></item><item><title>SSL Certificate Renewal, Windows Mobile Acess and iPhone Access</title><link>http://forums.iis.net/thread/1925304.aspx</link><pubDate>Wed, 18 Nov 2009 21:12:56 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925304</guid><dc:creator>edwardwagner</dc:creator><slash:comments>2</slash:comments><comments>http://forums.iis.net/thread/1925304.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925304</wfw:commentRss><description>&lt;p&gt;I recently renewed my Verisign SSL certificate and installed it successfully; however the two handheld devices - Samsung Windows Mobile device (with latest version of Windows Mobile) and iPhone (latest OS) - cannot communicate with the Exchange 2003 (Windows 2003 SP2) server once I check the &amp;quot;require SSL&amp;quot; box.&amp;nbsp; The Samsung gives a &amp;quot;0x85010014&amp;quot; error code, and the iPhone just states that it cannot communicate with the server.&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;I can still use OWA fine.  If I do not require SSL on the server end, while still requiring it on each handheld device, everything is happy (except, of course, you can login into the OWA with http:).  I spent a long time with the Verisign tech support and did not find anything to solve the problem.  We did solve a related issue, which was that the Samsung device could not communicate even without SSL - needed to download a new certifcate to that phone since some models did not have the latest security certificate version that Verisign started using (which has apparently been in use for several years and the iPhone had already).&lt;/p&gt;

&lt;p&gt;I did not change any settings on either device (they have always required SSL), nor the server - other than installing the certificate - but now the handheld devices won&amp;#39;t connect if SSL is selected on the server, so I have to have it turned off in the IIS for now. Also, SSL was on until I inserted the certificate, so I&amp;#39;m wondering if something else (besides the SSL was perhaps reset).  I have read that ActiveSync does not really use SSL, but it had no problems with the server requiring SSL until I installed the new certificate.&lt;/p&gt;</description></item><item><title>HTTP Error 401.3 - Unauthorized: Access is denied due to an ACL set on the requested resource.</title><link>http://forums.iis.net/thread/1925289.aspx</link><pubDate>Wed, 18 Nov 2009 19:34:17 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925289</guid><dc:creator>alexscript</dc:creator><slash:comments>2</slash:comments><comments>http://forums.iis.net/thread/1925289.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925289</wfw:commentRss><description>&lt;p&gt;My Server is running on Windows XP Professional IIS 5.1 and I am getting the HTTP Error 401.3 - Unauthorized: Access is denied due to an ACL set on the requested resource.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;All images stored in &amp;quot;C:\WebsiteRoot\Portal\Content\Library\Users\[username]\&amp;quot; cannot be viewed (These are user uploaded images). However, all images stored in &amp;quot;C:\WebsiteRoot\Portal\Content\Library\Groups\[groupname]\&amp;quot; can be viewed. So it only applies to the first folder example and subdirectories. &lt;/p&gt;
&lt;p&gt;It&amp;#39;s causing missing images on my site. &lt;/p&gt;
&lt;p&gt;I would like to add aswell, and I hope this may indicate something about the user roles that CAN and CAN&amp;#39;T access these images. I have server side methods that can access these files and return them to me. It is only when I use the link &amp;quot;[domain]/Content/Library/Users/[username]/[filename]&amp;quot; that I get the 401.3 error.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;I&amp;#39;ve done so much to try to allow access to these images, that I&amp;#39;d like to start fresh with recommendations from anybody here on the IIS community site.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thank you for any help, Alex&lt;/p&gt;</description></item><item><title>IIS 6.0 and Firefox issues</title><link>http://forums.iis.net/thread/1925171.aspx</link><pubDate>Wed, 18 Nov 2009 02:51:56 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925171</guid><dc:creator>Ireneabraham</dc:creator><slash:comments>5</slash:comments><comments>http://forums.iis.net/thread/1925171.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1925171</wfw:commentRss><description>Hi,

I am having a website published via IIS 6 and I have checked  &amp;#39;Digest Authentication Windows domain servers&amp;#39; to enable Active Directory security for logging on to the site. The users enter the user id and password when prompted and gets access to the site when they use Internet Explorer and have no problems in any way.

But When they use Mozilla Firefox the user credentials are prompted again and also when they click on different links within the website they will eventually get error messages when they try to login
and also wouldn&amp;#39;t accept the login credentials. The web page is developed using .Net(.aspx )

Please can anyone help me.I couldn&amp;#39;t find any solution on my web search so far.
Please throw your ideas on the forum so that I can try them.



</description></item><item><title>Multiple Webapplications - same Port - NLB</title><link>http://forums.iis.net/thread/1924313.aspx</link><pubDate>Wed, 11 Nov 2009 18:27:04 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1924313</guid><dc:creator>wuwu</dc:creator><slash:comments>2</slash:comments><comments>http://forums.iis.net/thread/1924313.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1924313</wfw:commentRss><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;i have configured Multiple Web Applications at the same Port - 443.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://forums.iis.net/t/1162225.aspx"&gt;http://forums.iis.net/t/1162225.aspx&lt;/a&gt;&amp;nbsp;-&amp;gt; with the option, different IP-adresses -&amp;gt; at one server.&lt;/p&gt;
&lt;p&gt;How can realise this case Multiple - Webapplications on Port 443 with servers in NLB.&lt;/p&gt;
&lt;p&gt;I do&amp;nbsp;not really know how can configure this with the DNS entry from NLB and set&amp;nbsp;ip-adresses for the detail web applications.&lt;/p&gt;
&lt;p&gt;We&amp;nbsp;need this for our different web applications at our SharePoint Farm with three&amp;nbsp;Webfrontend Server.&lt;/p&gt;
&lt;p&gt;I hope somebody understand my problem and can help me,&lt;/p&gt;
&lt;p&gt;thanks Horst&lt;/p&gt;</description></item><item><title>Login as different user in asp.net as in share point</title><link>http://forums.iis.net/thread/1924877.aspx</link><pubDate>Mon, 16 Nov 2009 08:12:13 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1924877</guid><dc:creator>dharam_hbtik</dc:creator><slash:comments>1</slash:comments><comments>http://forums.iis.net/thread/1924877.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1924877</wfw:commentRss><description>Hi everybody,

My request out here is Urgent, though i have passed through what I could access in this forum and others also, but cannot finding a working solution.

I have designed an ASP.NET application, at our organizational intranet, I have used Windows Authentication and it worked very efficiently. My problem is, I want my application to ask for re-entering of employee&amp;#39;s credential when he clicked on a log out control ( it could be anything - i didn&amp;#39;t decided what will trigger log out yet ). I want it to be like Sharepoint page where you can log as another user in the same machine.

I m using following code but not working properly

protected void Page_Load(object sender, EventArgs e)
    {
        if (!this.IsPostBack)
        {
            _User = User.Identity.Name.Replace(&amp;quot;Domain\\&amp;quot;, &amp;quot;&amp;quot;);
            Label1.Text = _User;
        }
    }
    protected void LinkButton1_Click(object sender, EventArgs e)
    {
       
            Response.StatusCode = 401;
            Response.StatusDescription = &amp;quot;Unauthorized&amp;quot;;
            Response.End();
            Response.Redirect(&amp;quot;Default.aspx&amp;quot;);       
    }

and HTML is


    Untitled Page


    
    &lt;div&gt;
        &lt;p&gt;Hello &lt;/p&gt;
        Sign in as Different user
    &lt;/div&gt;
    



I am waiting ...

Thanks.</description></item><item><title>Integrated Windows Authentication</title><link>http://forums.iis.net/thread/1924789.aspx</link><pubDate>Sun, 15 Nov 2009 02:36:22 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1924789</guid><dc:creator>altjx</dc:creator><slash:comments>5</slash:comments><comments>http://forums.iis.net/thread/1924789.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1924789</wfw:commentRss><description>&lt;p&gt;why does this not work? what am i doing wrong? i have NTFS permissions for people on a particular domain to have access to this web server... I enabled integrated windows authentication but even the people that have permission are still being prompted for usernames and passwords. what&amp;#39;s with this?&lt;/p&gt;</description></item><item><title>TLS renegotiation bug</title><link>http://forums.iis.net/thread/1924602.aspx</link><pubDate>Fri, 13 Nov 2009 09:42:19 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1924602</guid><dc:creator>Michael089</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1924602.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1924602</wfw:commentRss><description>&lt;p&gt;Hi all,&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;in the beginning of November, a TLS renegotiation bug has been published, which allows MITM attacks. (http://www.ietf.org/mail-archive/web/tls/current/msg03928.html) Since its a protocol flaw, IIS is affected as well. So my questions:&lt;/p&gt;&lt;p&gt;- is there an official statement from the MS IIS team concerning this bug?&lt;br /&gt;- are there any community-proofen workarounds?&lt;br /&gt;- how about setting &lt;b&gt;SSLAlwaysNegoClientCert ? - &lt;/b&gt;this would prevent renegotiation&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Cheers, &lt;/p&gt;&lt;p&gt;Michael&amp;nbsp; &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Anonymous authentication "inherently insecure" ?</title><link>http://forums.iis.net/thread/1922713.aspx</link><pubDate>Thu, 29 Oct 2009 22:53:14 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1922713</guid><dc:creator>mac12</dc:creator><slash:comments>9</slash:comments><comments>http://forums.iis.net/thread/1922713.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1922713</wfw:commentRss><description>&lt;p&gt;I have a client who is insisting they won&amp;#39;t allow anon access by policy.&amp;nbsp; We don&amp;#39;t authenticate at the web server - rather we use an isapi connector to Tomcat which does the (forms based) user password auth.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Of course this means we use Anonymous access on IIS.&amp;nbsp; My claim is that there&amp;#39;s nothing inherently insecure about using Anonymous auth in IIS give you follow best practices for limiting access/execute rights.&lt;/p&gt;&lt;p&gt;Does my client have a legitimate concern, or do they &amp;quot;just not get it&amp;quot;.&amp;nbsp; I guess they were hacked via the IIS Anon account in the past.&lt;/p&gt;&lt;p&gt;I&amp;#39;d be grateful for any authoritative statements on the matter. &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Generating certificates and enabling SSL in IIS 6.0</title><link>http://forums.iis.net/thread/1921938.aspx</link><pubDate>Fri, 23 Oct 2009 19:27:57 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1921938</guid><dc:creator>murali gopal</dc:creator><slash:comments>6</slash:comments><comments>http://forums.iis.net/thread/1921938.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1921938</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;I am pretty new (2 months old) to IIS.&lt;br /&gt;&lt;br /&gt;I have a site http://test.pharma.com after enabling SSL it should be https://test.pharma.com --&amp;gt; Thats what I need to do. &lt;/p&gt;&lt;p&gt;&amp;nbsp;I never enabled SSL. I dont know how to generate a certificate and enable it in IIS 6.0.&lt;br /&gt;&lt;br /&gt;Any help is appreciated.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Mulitple sites with 443</title><link>http://forums.iis.net/thread/1924083.aspx</link><pubDate>Tue, 10 Nov 2009 16:35:39 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1924083</guid><dc:creator>sheldondesouza</dc:creator><slash:comments>4</slash:comments><comments>http://forums.iis.net/thread/1924083.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1924083</wfw:commentRss><description>Hello,

Have 2 virtual directories in the IIS6, one of them is the default website with port 80 and then a test folder with port 81. The default website has 443 for SSL port. When i add 443 for the test website it tells me that 443 is already being used.

I added host header for the test website but that did not solve the issue. Both sites are using Unassigned IP address and the server has only one NIC.</description></item><item><title>URLScan with HTTPS</title><link>http://forums.iis.net/thread/1923384.aspx</link><pubDate>Wed, 04 Nov 2009 17:14:33 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923384</guid><dc:creator>Patrick12345</dc:creator><slash:comments>2</slash:comments><comments>http://forums.iis.net/thread/1923384.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923384</wfw:commentRss><description>&lt;p&gt;After much wailing and gnashing of teeth it would appear that the solution is this:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Problem: HTTPS stopped working once URL Scan 3.1 installed on XP machine running IIS5.1&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Solution: Move the URL Scan ISAPI filter to below the sspifilt ISAPI Filter&lt;/p&gt;
&lt;p&gt;Can anyone tell me if this is the *correct* solution to the problem, i.e. that there will be no unwanted side effects?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks,&lt;/p&gt;
&lt;p&gt;Patrick&lt;/p&gt;</description></item><item><title>NTFS Permissions Ignored when using FTP</title><link>http://forums.iis.net/thread/1923578.aspx</link><pubDate>Thu, 05 Nov 2009 23:08:47 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923578</guid><dc:creator>Gumby</dc:creator><slash:comments>4</slash:comments><comments>http://forums.iis.net/thread/1923578.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923578</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hi all.&amp;nbsp; &lt;/p&gt;&lt;p&gt;I am trying to setup an FTP server that has different permissions for each folder within the root folder of the site.&amp;nbsp; Whichever option(s) I choose (Read/Write) they get set site wide regardless of the NFTS/Active Directory permissions granted to a user or group on a given subfolder.&lt;/p&gt;&lt;p&gt;&amp;nbsp;I did not set any user isolation when creating the ftp site as I want all users to be able to read from the root directory.&amp;nbsp; &lt;/p&gt;&lt;p&gt;I simply want the FTP site to obey NTFS/Active Directory user and group permissions.&amp;nbsp; Is this possible?&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Thanks in advance for your response. &lt;br /&gt;&lt;/p&gt;</description></item><item><title>SSL on CLUSTER</title><link>http://forums.iis.net/thread/1922744.aspx</link><pubDate>Fri, 30 Oct 2009 05:18:18 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1922744</guid><dc:creator>tilak1980</dc:creator><slash:comments>8</slash:comments><comments>http://forums.iis.net/thread/1922744.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1922744</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Can you please tell me, Is it possible single SSL certificate to configure on multiple server&amp;#39;s.I have one cluster server i have configured SSL certificate on Active node and i want copy that SSL certificate and restore the same in passive node. Is it possible please tell me if possible then what are the steps. I have tried but it&amp;#39;s showing &amp;quot;x&amp;quot; this symbol it&amp;#39;s not valid. Please suggest how can we do this. waiting for your reply.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Tom Edward&lt;/p&gt;</description></item><item><title>Integrated windows authentication - Why am I getting login prompt?</title><link>http://forums.iis.net/thread/1923665.aspx</link><pubDate>Fri, 06 Nov 2009 15:23:46 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923665</guid><dc:creator>altjx</dc:creator><slash:comments>4</slash:comments><comments>http://forums.iis.net/thread/1923665.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923665</wfw:commentRss><description>&lt;p&gt;I have Integrated windows authentication enabled, and I have &amp;quot;enable anonymous authentication&amp;quot; DISABLED. On the NTFS permissions, I have myself granted full control. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;When I try to access the site from another computer using the same name that I granted access, it tells me:&lt;/p&gt;
&lt;p&gt;The website declined to show this webpage&lt;br /&gt;Most likely causes&lt;br /&gt;- This website requires you to login&lt;/p&gt;
&lt;p&gt;&amp;nbsp;When I removed myself from the NTFS permission, it prompts me for login credentials, and no credentials work. &lt;/p&gt;
&lt;p&gt;I am setting up an internal website and&amp;nbsp;I just would like to allow specific people on a domain, access to the internal website.&lt;/p&gt;
&lt;p&gt;Can someone tell me what I&amp;#39;m doing wrong?&lt;/p&gt;</description></item><item><title>Kerberos Authentication</title><link>http://forums.iis.net/thread/1923475.aspx</link><pubDate>Thu, 05 Nov 2009 08:58:19 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923475</guid><dc:creator>Kelvin.uk</dc:creator><slash:comments>3</slash:comments><comments>http://forums.iis.net/thread/1923475.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923475</wfw:commentRss><description>&lt;p&gt;When users try to connect to websites hosted on our intranet server they get the following authentication error in Internet Explorer:&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;quot;HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials&amp;quot; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;We get the error with all accounts; even aq\administrator (our domain admin account). This seems to be happening on only some computers. Interestingly if we use the intranet servers IP address rather than host name, authentication works. For example: http://192.168.0.16/website. We have not made any changes and have never had this problem in the past.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;strong&gt;Our Setup&lt;/strong&gt;&lt;br /&gt;Domain name: AQ and AQ.COMPANYNAME.CO.UK&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Domain Server:&lt;br /&gt;Host name: AQ-AD&lt;br /&gt;Windows Server 2003 R2&lt;br /&gt;Service Pack 2&lt;br /&gt;IIS 6 (anonymous access enabled)&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Intranet Server:&lt;br /&gt;Host name: AQWEB&lt;br /&gt;Windows Server 2003&lt;br /&gt;Service Pack 1 &lt;br /&gt;IIS 6 (anonymous access enabled)&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Clients:&lt;br /&gt;Windows XP SP2/3&lt;br /&gt;Tested on IE6/7/8 &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;strong&gt;The Errors&lt;/strong&gt;&lt;br /&gt;Client error (from the event viewer)&lt;br /&gt;The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/aqweb.aq.companyname.co.uk.&amp;nbsp; This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (AQ.COMPANYNAME.CO.UK), and the client realm.&amp;nbsp;&amp;nbsp; Please contact your system administrator.&lt;/p&gt;
&lt;p&gt;Domain server errors (3 errors that keep appearing in the event viewer)&lt;br /&gt;&amp;nbsp;&lt;br /&gt;1) There are multiple accounts with name HTTP/aqweb of type DS_SERVICE_PRINCIPAL_NAME.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2) A Kerberos Error Message was received:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on logon session &lt;br /&gt;&amp;nbsp;Client Time: &lt;br /&gt;&amp;nbsp;Server Time: 14:17:15.0000 11/4/2009 Z&lt;br /&gt;&amp;nbsp;Error Code: 0xd KDC_ERR_BADOPTION&lt;br /&gt;&amp;nbsp;Extended Error: 0xc00000bb KLIN(0)&lt;br /&gt;&amp;nbsp;Client Realm: &lt;br /&gt;&amp;nbsp;Client Name: &lt;br /&gt;&amp;nbsp;Server Realm: AQ.COMPANYNAME.CO.UK&lt;br /&gt;&amp;nbsp;Server Name: host/aq-ad.aq.companyname.co.uk&lt;br /&gt;&amp;nbsp;Target Name: host/aq-ad.aq.companyname.co.uk@AQ.COMPANYNAME.CO.UK&lt;/p&gt;
&lt;p&gt;3) A Kerberos Error Message was received:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on logon session &lt;br /&gt;&amp;nbsp;Client Time: &lt;br /&gt;&amp;nbsp;Server Time: 14:14:11.0000 11/4/2009 Z&lt;br /&gt;&amp;nbsp;Error Code: 0x7&amp;nbsp; KDC_ERR_S_PRINCIPAL_UNKNOWN&lt;br /&gt;&amp;nbsp;Extended Error: &lt;br /&gt;&amp;nbsp;Client Realm: &lt;br /&gt;&amp;nbsp;Client Name: &lt;br /&gt;&amp;nbsp;Server Realm: AQ.COMPANYNAME.CO.UK&lt;br /&gt;&amp;nbsp;Server Name: DNS/ns0.bt.net&lt;br /&gt;&amp;nbsp;Target Name: DNS/ns0.bt.net@AQ.COMPANYNAME.CO.UK&lt;/p&gt;
&lt;p&gt;No errors to report on the intranet server (AQWEB)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Authentication and Access Control Diagnostics&lt;/strong&gt; (Microsoft tool to diagnose IIS security)&lt;br /&gt;Kerberos configuration failures on AQ-AD:&lt;br /&gt;Wrong credentials for AppPoolIdentity (currently Network Service)&lt;br /&gt;Service principal name (SPN) for user &amp;#39;aq\admin&amp;#39; not found in Active Directory &lt;br /&gt;Service principal name (SPN) for user &amp;#39;aq\administrator&amp;#39; not found in Active Directory &lt;/p&gt;
&lt;p&gt;Kerberos configuration failures on AQWEB:&lt;br /&gt;Wrong credentials for AppPoolIdentity: (currently Network Service)&lt;br /&gt;Service principal name (SPN) for user &amp;#39;aq\administrator&amp;#39; not found in Active Directory &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;SPN Setups&lt;/strong&gt;&lt;br /&gt;using &amp;quot;setspn setspn -l &amp;lt;hostname&amp;gt;&amp;quot; in the console (Windows Resource tool kit needed) I can view our current SPN mappings:&lt;/p&gt;
&lt;p&gt;SPNs for AQWEB:&lt;br /&gt;http/AQWEB&lt;br /&gt;MSSQLSvc/AQWEB.AQ.COMPANYNAME.CO.UK:1433&lt;br /&gt;NtFrs-88f5d2bd-b646-11d2-a6d3-00c04fc9b232/AQWEB.AQ.COMPANYNAME.CO.UK&lt;br /&gt;HOST/AQWEB&lt;br /&gt;HOST/AQWEB.AQ.COMPANYNAME.CO.UK&lt;/p&gt;
&lt;p&gt;SPNs for AQ-AD:&lt;br /&gt;MSSQLSvc/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;ldap/aq-ad.AQ.COMPANYNAME.CO.UK/LimitLogin.AQ.COMPANYNAME.CO.UK&lt;br /&gt;Dfsr-12F9A27C-BF97-4787-9364-D31B6C55EB04/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;GC/aq-ad.AQ.COMPANYNAME.CO.UK/AQ.COMPANYNAME.CO.UK&lt;br /&gt;HOST/aq-ad.AQ.COMPANYNAME.CO.UK/AQ.COMPANYNAME.CO.UK&lt;br /&gt;HOST/aq-ad.AQ.COMPANYNAME.CO.UK/AQ&lt;br /&gt;ldap/80ad2477-baa1-4c58-b419-8df53c616709._msdcs.AQ.COMPANYNAME.CO.UK&lt;br /&gt;ldap/aq-ad.AQ.COMPANYNAME.CO.UK/AQ&lt;br /&gt;ldap/AQ-AD&lt;br /&gt;ldap/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;ldap/aq-ad.AQ.COMPANYNAME.CO.UK/AQ.COMPANYNAME.CO.UK&lt;br /&gt;DNS/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;E3514235-4B06-11D1-AB04-00C04FC2DCD2/80ad2477-baa1-4c58-b419-8df53c616709/AQ.COMPANYNAME.CO.UK&lt;br /&gt;NtFrs-88f5d2bd-b646-11d2-a6d3-00c04fc9b232/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;SMTPSVC/aq-ad.AQ.COMPANYNAME.CO.UK&lt;br /&gt;SMTPSVC/AQ-AD&lt;br /&gt;HOST/AQ-AD&lt;br /&gt;HOST/aq-ad.AQ.COMPANYNAME.CO.UK&lt;/p&gt;
&lt;p&gt;This sounds like we have a Kerberos authentication issues but I am not sure how to fix them, I have never come across this before. Any help would be great!&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Anonymous Authentication Problem</title><link>http://forums.iis.net/thread/1922961.aspx</link><pubDate>Sun, 01 Nov 2009 04:41:35 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1922961</guid><dc:creator>c0mpshades45</dc:creator><slash:comments>3</slash:comments><comments>http://forums.iis.net/thread/1922961.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1922961</wfw:commentRss><description>&lt;p&gt;I haven&amp;#39;t used IIS in a while and am having trouble adding security to my server&amp;#39;s directories.&amp;nbsp; I created a new username and pass for the use of security, however, when I go to apply this to anonymous authent with this new user and pass, it doesnt prompt me in the web browser.&amp;nbsp; I&amp;#39;ve restarted the server many times, refreshed, etc.. no luck... any hep/suggestions?&lt;/p&gt;</description></item><item><title>PHP 5.2 on IIS 6 Authentification issue</title><link>http://forums.iis.net/thread/1923407.aspx</link><pubDate>Wed, 04 Nov 2009 20:42:51 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923407</guid><dc:creator>openriver</dc:creator><slash:comments>1</slash:comments><comments>http://forums.iis.net/thread/1923407.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923407</wfw:commentRss><description>&lt;p&gt;i installed php 5.2 on an iis6.0 server but when i try to view http://preview.seismicmicro.com/php/phpinfo.php it is requiring a log in to see it. what am i missing?&lt;/p&gt;&lt;p&gt;liannemr@verizon.net &lt;br /&gt;&lt;/p&gt;</description></item><item><title>IISADMPWD , Security Issue:  any user can change other user password </title><link>http://forums.iis.net/thread/1923203.aspx</link><pubDate>Tue, 03 Nov 2009 10:50:44 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1923203</guid><dc:creator>aacable</dc:creator><slash:comments>5</slash:comments><comments>http://forums.iis.net/thread/1923203.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1923203</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;I am using IIS6 / iisadmpwd module&amp;nbsp; to give user option to change there password via web.&lt;/p&gt;&lt;p&gt;But the issue is that any user can change other user password , for example&lt;/p&gt;&lt;p&gt;John can change smith&amp;#39;s password if he knows his password. (In our orgnaization, we have one common password for all users) &lt;/p&gt;&lt;p&gt;How to restrict users to change there account password only ?&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Regard&amp;#39;s&lt;/p&gt;&lt;p&gt;Syed Jahanzaib&lt;br /&gt;N.A.E.i&lt;br /&gt;http://www.nae.com.pk&lt;br /&gt;&lt;/p&gt;</description></item></channel></rss>