<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'ssl Server Certificate'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=ssl+Server+Certificate&amp;orTags=0</link><description>Search results matching tag 'ssl Server Certificate'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/p/1154109/1888980.aspx#1888980</link><pubDate>Mon, 05 Jan 2009 04:15:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1888980</guid><dc:creator>stamtarm</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;I&amp;nbsp;have tried several times, revoke and replace certificate, and asked&amp;nbsp;Verisign for help too. But at the end it still failed.&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Error message are shown as below:&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;- When installing the certificate: &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;font face="Arial" size="2"&gt;&amp;quot;Failed to install certificate, &lt;/font&gt;&lt;font face="Arial" size="2"&gt;keyset does not exists&amp;quot;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;/font&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;- When trying to export the private key using MMC function, the option for &amp;quot;Export private key&amp;quot; is disabled and it says &lt;/font&gt;&lt;font face="Arial" size="2"&gt;&amp;quot;Notes: The associated private key cannot be found.&amp;nbsp; Only the certificate can be exported.&amp;quot;&amp;nbsp;&amp;nbsp;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;I have changed the permission of the administrator and system&amp;nbsp;account to Full Control for the following folders and files already:&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;Folders&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;All files inside the following folder&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font face="Arial" size="2"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Please kindly assist!! Thank you very much!!&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;sta&lt;/div&gt;</description></item><item><title>403.7 64 on IIS 6 on both XP 64 and server 2003 R2 64</title><link>http://forums.iis.net/p/1152787/1883609.aspx#1883609</link><pubDate>Mon, 03 Nov 2008 15:01:01 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1883609</guid><dc:creator>Carrots</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;In the IIS logs, our client has found a bunch of 403.7 64 &amp;#39;s being
logged. Most of them are to /VirtualDirectoryName, for example:&lt;br /&gt;&lt;br /&gt;2008-10-30
06:41:00 W3SVC3 xxx.xxx.xxx.xxx GET /VirtualDirectoryName - 443 -
xxx.xxx.xxx.xxx
Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+5.1;+.NET+CLR+2.0.50727;+.NET+CLR+1.1.4322;+.NET+CLR+3.0.04506&lt;br /&gt;.30;+.NET+CLR+3.0.04506.648;+.NET+CLR+3.5.21022) 403 7 64&lt;br /&gt;&lt;br /&gt;These happen quite often, sometimes 4 or so requests in a row.&lt;br /&gt;Directory
browsing is disabled on the sites, and the default page is set to
default.htm which exists, so theoretically, there should be no requests
for the path.&lt;br /&gt;I have enabled schannel logging, but couldnt find one
matching the timestamp in IIS. For example, in IIS we have one for
2008-10-30 11:49:50, and in event viewer we have one for 11:49:52 and
one for 11:49:45. I also couldnt find a patter that makes it look like
the one is trailing the other by a couple of seconds.&lt;br /&gt;&lt;br /&gt;All the IIS requests are on port 443, none are on 80.&lt;br /&gt;&lt;br /&gt;Schannel logs information events, but no warnings.&lt;br /&gt;The client confirmed that the system logs and IIS logs were from the same server.&lt;br /&gt;&lt;br /&gt;They run Windows 2003 x64 R2 on a NLB cluster. The machines in the testing environment is a single machine only.&lt;br /&gt;I
am able to intermittently reproduce it on my own environment (XP 64).
One out of 20 times doing the exact same actions will give me the error
in the logs. The error does not affect the user at all.&lt;br /&gt;&lt;br /&gt;Testers
currently test on Windows XP 32, with IE6, IE7 and Firefox, using
software certs, or in some cases USB tokens. I replicated using a
software cert.&lt;br /&gt;&lt;br /&gt;Now this does not sound like something I should
be spending my time on, but the client is being audited, and this has
been raised as a concern by the auditing company.&lt;/p&gt;</description></item><item><title>Securing sites - classic asp - .Net 1.1, .Net 2.0, and .Net 3+</title><link>http://forums.iis.net/p/1152358/1881921.aspx#1881921</link><pubDate>Mon, 13 Oct 2008 18:54:58 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1881921</guid><dc:creator>mybestguess</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;It as been the recent task of our team to come up with both short and long term solutions to the concern of SSL security on our sites.&lt;/p&gt;
&lt;p&gt;The first solution off the top of the head is to do 1 of the following 2.&amp;nbsp; Either take the pain and time consuming option of coding each individual website to rediret to https to use ssl.&amp;nbsp; The second approach would be to have IIS force a redirect to the https and www paths.&lt;/p&gt;
&lt;p&gt;The catch is what would be the best approach.&amp;nbsp; I am thinking of a quick and easy temporary solution first.&amp;nbsp; Then a long term solution.&amp;nbsp; But the long term solution has a catch.&amp;nbsp; In the next few months (early - Mid 2009) we are moving to Server 2008 with IIS7 and that may negate the changes necessary in IIS6.&lt;/p&gt;
&lt;p&gt;Any and all suggestions are appreciated on this matter.&amp;nbsp; If you have any suggestions regarding the best way to add SSL to existing sites please let me know.&amp;nbsp; I would like to try and avoid a manual reprogramming of that many websites.&amp;nbsp; Thank you&lt;/p&gt;
&lt;p&gt;MBG&lt;/p&gt;</description></item><item><title>Import ssl certificate on iis 7</title><link>http://forums.iis.net/p/1149877/1871743.aspx#1871743</link><pubDate>Sat, 14 Jun 2008 16:44:32 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1871743</guid><dc:creator>saquib189</dc:creator><cs:applicationKey>iis7_-_security--1</cs:applicationKey><description>&lt;p&gt;Hi, I got the 14 days trial certificate from Verisign for testing my site. www.saquibs.com and i have windows vista workstation but i don&amp;#39;t know how to install the ssl certificate and also get the Intermediate CA cerificate code which i save on .cer file . so please help me how can i enable ssl on my remote site.

thank you &lt;/p&gt;</description></item></channel></rss>