<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'SSL Issues'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=SSL+Issues&amp;orTags=0</link><description>Search results matching tag 'SSL Issues'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Installing Multiple SSL in single IIS 6.0</title><link>http://forums.iis.net/p/1154668/1891285.aspx#1891285</link><pubDate>Wed, 28 Jan 2009 09:40:43 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1891285</guid><dc:creator>swamik</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Hi All: &lt;/p&gt;&lt;p&gt;We have a requirement of installing Multiple SSL certicates of 20 different websites which are all hosted in single&amp;nbsp; IIS 6.0(Windows Server 2003 is the OS)&lt;/p&gt;&lt;p&gt;Using host header, we were able to host these 20 sites in an single IIS. But like to know how to install and configure 20 SSL certificates for these 20 domains which are in single IIS 6.0.&lt;/p&gt;&lt;p&gt;Please help&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/p/1154109/1888980.aspx#1888980</link><pubDate>Mon, 05 Jan 2009 04:15:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1888980</guid><dc:creator>stamtarm</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;I&amp;nbsp;have tried several times, revoke and replace certificate, and asked&amp;nbsp;Verisign for help too. But at the end it still failed.&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Error message are shown as below:&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;- When installing the certificate: &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;font face="Arial" size="2"&gt;&amp;quot;Failed to install certificate, &lt;/font&gt;&lt;font face="Arial" size="2"&gt;keyset does not exists&amp;quot;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;/font&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;- When trying to export the private key using MMC function, the option for &amp;quot;Export private key&amp;quot; is disabled and it says &lt;/font&gt;&lt;font face="Arial" size="2"&gt;&amp;quot;Notes: The associated private key cannot be found.&amp;nbsp; Only the certificate can be exported.&amp;quot;&amp;nbsp;&amp;nbsp;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;I have changed the permission of the administrator and system&amp;nbsp;account to Full Control for the following folders and files already:&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;Folders&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;All files inside the following folder&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Please kindly assist!! Thank you very much!!&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;sta&lt;/div&gt;</description></item><item><title>403.7 64 on IIS 6 on both XP 64 and server 2003 R2 64</title><link>http://forums.iis.net/p/1152787/1883609.aspx#1883609</link><pubDate>Mon, 03 Nov 2008 15:01:01 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1883609</guid><dc:creator>Carrots</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;In the IIS logs, our client has found a bunch of 403.7 64 &amp;#39;s being
logged. Most of them are to /VirtualDirectoryName, for example:&lt;br /&gt;&lt;br /&gt;2008-10-30
06:41:00 W3SVC3 xxx.xxx.xxx.xxx GET /VirtualDirectoryName - 443 -
xxx.xxx.xxx.xxx
Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+5.1;+.NET+CLR+2.0.50727;+.NET+CLR+1.1.4322;+.NET+CLR+3.0.04506&lt;br /&gt;.30;+.NET+CLR+3.0.04506.648;+.NET+CLR+3.5.21022) 403 7 64&lt;br /&gt;&lt;br /&gt;These happen quite often, sometimes 4 or so requests in a row.&lt;br /&gt;Directory
browsing is disabled on the sites, and the default page is set to
default.htm which exists, so theoretically, there should be no requests
for the path.&lt;br /&gt;I have enabled schannel logging, but couldnt find one
matching the timestamp in IIS. For example, in IIS we have one for
2008-10-30 11:49:50, and in event viewer we have one for 11:49:52 and
one for 11:49:45. I also couldnt find a patter that makes it look like
the one is trailing the other by a couple of seconds.&lt;br /&gt;&lt;br /&gt;All the IIS requests are on port 443, none are on 80.&lt;br /&gt;&lt;br /&gt;Schannel logs information events, but no warnings.&lt;br /&gt;The client confirmed that the system logs and IIS logs were from the same server.&lt;br /&gt;&lt;br /&gt;They run Windows 2003 x64 R2 on a NLB cluster. The machines in the testing environment is a single machine only.&lt;br /&gt;I
am able to intermittently reproduce it on my own environment (XP 64).
One out of 20 times doing the exact same actions will give me the error
in the logs. The error does not affect the user at all.&lt;br /&gt;&lt;br /&gt;Testers
currently test on Windows XP 32, with IE6, IE7 and Firefox, using
software certs, or in some cases USB tokens. I replicated using a
software cert.&lt;br /&gt;&lt;br /&gt;Now this does not sound like something I should
be spending my time on, but the client is being audited, and this has
been raised as a concern by the auditing company.&lt;/p&gt;</description></item><item><title>Redirecting HTTPS from https://domain.com to https://www.domain.com</title><link>http://forums.iis.net/p/1151124/1876866.aspx#1876866</link><pubDate>Thu, 14 Aug 2008 17:03:43 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1876866</guid><dc:creator>bostonnole</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Is there some way in IIS 6 (running on Windows 2003) to redirect all pages, including parameters, from &lt;a href="https://domain.com/"&gt;https://domain.com&lt;/a&gt; to &lt;a href="https://www.domain.com/"&gt;https://www.domain.com&lt;/a&gt;?&lt;/p&gt;
&lt;p&gt;None SSL redirects are working fine.&lt;/p&gt;
&lt;p&gt;When a user attemps &lt;a href="https://domain.com/"&gt;https://domain.com&lt;/a&gt; they get a warning about the certificate not matching the name of the site.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;strong&gt;The name on the security certificate is invalid or does not match the name of the site&lt;/strong&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;I have created a seperate web site for &amp;quot;domain.com&amp;quot; and I have an SSL certificate for &amp;quot;domain.com&amp;quot;. This site is setup to do a permanent redirect to the &lt;a href="http://www.domain.com/"&gt;www.domain.com&lt;/a&gt; site.&amp;nbsp; As I indicated above, non-ssl redirects work fine.&amp;nbsp; Just the SSL redirects do not.&lt;/p&gt;</description></item><item><title>ISAPI Filters</title><link>http://forums.iis.net/p/1150157/1872874.aspx#1872874</link><pubDate>Mon, 30 Jun 2008 12:05:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1872874</guid><dc:creator>sweetleaf</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;I&amp;#39;ve recently installed a certificate on my Windows 2003 webserver and I don&amp;#39;t seem to be able to get it to work.&lt;/p&gt;&lt;p&gt;Http is fine, but if I try and access the site using https I just get &amp;#39;page cannot be displayed&amp;#39;.&amp;nbsp; I&amp;#39;ve looked through the usual MS documents to try and solve the issue and have downloaded the IIS Diag tool.&amp;nbsp; This reckoned strmfilt.dll was not loaded into lsass.exe and to check and install sspifilt.dll in ISAPI filters.&lt;/p&gt;&lt;p&gt;Sspifilt.dll isn&amp;#39;t installed in ISAPI filters and I can&amp;#39;t find it on the server or on the W2003 CD.&amp;nbsp; I can&amp;#39;t see any reference to it in relation to IIS6 (have found docs re sspifilt and IIS4/5).&lt;/p&gt;&lt;p&gt;Does IIS 6 really need sspifilt?&amp;nbsp; And if so, does anyone know where I can get it from?&amp;nbsp; I did download one, but IIS didn&amp;#39;t like it at all!&lt;/p&gt;&lt;p&gt;Thanks &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Client Certificates + SSL</title><link>http://forums.iis.net/p/1149813/1871473.aspx#1871473</link><pubDate>Wed, 11 Jun 2008 09:02:08 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1871473</guid><dc:creator>herr_raus</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Hi all,&lt;/p&gt;
&lt;p&gt;I have a question regarding client certificates that hasn&amp;#39;t been quite answered yet. &lt;br /&gt;I&amp;#39;d like to set up an IIS6 server with SSL and a client certificate. But I would like to create the certificate with custom information, and for use on the internet (!). Ofcourse I preffer not to pay for each client certificate. &lt;/p&gt;
&lt;p&gt;The certificate server is installed on the webserver so should both be accessible.&amp;nbsp;When using certsvr application internally this work&amp;nbsp;perfectly. Only when I&amp;nbsp;need to create&amp;nbsp;the certificate and mail it to a&amp;nbsp;3rd party over the internet this&amp;nbsp;ceases to work.&amp;nbsp;Is there any way to get this working?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thank you.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Kind Regards,&lt;/p&gt;</description></item><item><title>renewing SSL certificate problems on IIS6</title><link>http://forums.iis.net/p/1149773/1871270.aspx#1871270</link><pubDate>Mon, 09 Jun 2008 08:57:30 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1871270</guid><dc:creator>APLIT</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;Hi,&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I&amp;#39;m trying to renew my SSL certificate but I&amp;#39;m getting a country code error from all of the SSL suppliers so far. I&amp;#39;ve been told to set up a new website then copy over the certificate when it expires!&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I&amp;#39;m not wanting to implement a bodge, I&amp;#39;m wanting to renew the certificate with the CSR I&amp;#39;m getting from the server and then leave it be. It must be possible?&amp;nbsp;&lt;/p&gt;</description></item></channel></rss>