Welcome to ISAserver.org
Forums |
Register |
Login |
My Profile |
Inbox |
RSS
|
My Subscription |
My Forums |
Address Book |
Member List |
Search |
FAQ |
Ticket List |
Log Out
SSL - Certificate missing
|
Users viewing this topic:
none
|
Logged in as: Guest
|
Login | |
|
SSL - Certificate missing - 11.May2001 1:28:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
I've tried for a little help in the Firewall general issues, with no luck, but this seems to be a more specific forum, I'll try my luck here... (Cheers to isaserver.org for the ever expanding support) Before I go on, Prior to installing an ISA Server firewall I had no problems witht he SSL web server. I'm trying to publish a SSL site in a DMZ behind ISA. I have successfully installed the Thawte Server certificate on the firewall, and under incoming request on the Array I have selected the certificate. I followed the instructions from the turtorial and ran the web publishing wizard, but when I go to select the certificate under the web publishing rule, it states that there are no certificates installed. And hence no SSL site. If I turn off require SSL on the web server and connect via http: everything is fine, but it needs to be SSL. Little help..?
|
|
|
|
RE: SSL - Certificate missing - 11.May2001 8:26:00 AM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Kb, Try installing the certificate on the web server, and then export it. After exporting it, import it to the ISA Server. I believe some others on these boards used this technique to get it to work. Let us know how it works! Thanks! Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get it Here!
|
|
|
|
RE: SSL - Certificate missing - 11.May2001 8:47:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Tom, That's actually how I got the certificate onto the machine in the first place however, I've just got your book and reading thru there are a numbr of problems trying to do what i want, so I might try again from the start with the books help. Your recommendation in the book is essentially away from the DMZ and I agree, and I don't need the functionality it would provide anyway. It would be nice to remove the net traffic from my internal network, but we're going to be upgrading the network infrastructure shortly and this won't be as big an issue.May I say that I have way to many of these types of books (tech manuals) but yours is a refreshing change in that regardless of how in significant the situation...(three homed dmz) you still devoted several pages to it. Thanks again for the response and I'll let you know how I go when I get around to restructuring the network for a standard setup. Cheers
|
|
|
|
RE: SSL - Certificate missing - 13.May2001 1:56:00 AM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Kb, Thanks for the kind words about the book  Let us know how it goes when you've got things reconfigured. Thanks! Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get it Here!
|
|
|
|
RE: SSL - Certificate missing - 14.May2001 8:26:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Tom and Others, Have goen back to an internal network only and followed the procedures for publishing a website and bridging SSL connections from Chapter 10. But I'm getting the following error when connecting to services that use SSL. 500 Internal Server Error - The target principal name is incorrect. (-2146893022) Internet Security and Acceleration Server So for http://mydomain.com/index.htm I get the page. But for https://mydomain.com/index.htm I get the error above... This is the same as when I was publishing from a DMZ... The book doesn't show a certificate under the web publishing rule, is this correct..? I can't see a certificate from here anyway, but it seems like I may need it here.. Cheers in advance
|
|
|
|
RE: SSL - Certificate missing - 15.May2001 10:22:00 AM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Kb, I have seen this error before the configuration change "takes" on the ISA Server. I had to restart the services or restart the ISA Server to get it to work properly. HTH, Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get it Here!
|
|
|
|
RE: SSL - Certificate missing - 16.May2001 12:49:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Cheers again Tom, I'm pretty sure it's been restarted since but I'll restart again this weekend, and do the certificate export again and see..
|
|
|
|
RE: SSL - Certificate missing - 18.May2001 2:49:00 AM
|
|
|
rg
Posts: 3
Joined: 18.May2001
From: hb,ca,usa
Status: offline
|
I am also getting this error and another user in this message board on May 17th is reporting this same problem. rg
|
|
|
|
RE: SSL - Certificate missing - 18.May2001 2:54:00 AM
|
|
|
rg
Posts: 3
Joined: 18.May2001
From: hb,ca,usa
Status: offline
|
[QUOTE]Originally posted by Kb575: [B]Tom and Others,(500 Internal Server Error - The target principal name is incorrect. (-2146893022) Internet Security and Acceleration Server) This is the exact error that I have been receiving. http is fine but ps produces this error. (The book doesn't show a certificate under the web publishing rule, is this correct..? I can't see a certificate from here anyway, but it seems like I may need it here..) This is the problem I have. I am assuming that this cert under the publishing rule is acting as a personal cert if this is in use on the web server side. rg
|
|
|
|
RE: SSL - Certificate missing - 24.May2001 6:59:00 AM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Guys, One thing I need to know is where is the certificate installed and where is the SSL connection being terminated? It works both ways, but I've found that the dreaded error message that you see comes up when you terminate at the ISA Server Inbound Web Requests listener interface. I have seen the same error, which most often happens before the machines or services have been restarted. I have also seen this error on a site that was working, then I stopped it, then started it again. I assumed, for the book, that it was a bug, and something that will be fixed with the first ISA Server service pack. But I didn't want to come right out and say that in the book, because it would be dating it  Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get It Here
|
|
|
|
RE: SSL - Certificate missing - 24.May2001 7:22:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
tom,
|
|
|
|
RE: SSL - Certificate missing - 24.May2001 7:25:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Tom, whoops... Anyway, in response to your question. The Thawte server certificate is installed on the Web server and on the Incoming requests ip for the ISA Server. It is not however able to be selected on the web publishing section. I wish the ssl connection to pass right thru to the web server as it requires client certificates to be verified on the web server. I can get ssl to work in the case where I terminate the SSL at the isa firewall, and pass http only requests to the web server, but it means I cannot require client certificates at the web server...Does this answer your question...?? Thoughts....??? Cheers
|
|
|
|
RE: SSL - Certificate missing - 30.May2001 5:46:00 PM
|
|
|
PeterE
Posts: 4
Joined: 25.May2001
From: DENMARK
Status: offline
|
I have seen this problem as well. This Q article describes the steps you need tpo perform to use a SSL certificate on the ISA in reverse hosting. http://support.microsoft.com/support/kb/articles/q292/5/69.asp I hope it helps \Peter
|
|
|
|
RE: SSL - Certificate missing - 31.May2001 1:15:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Thanks for the info Peter. I can actually get this to work and have gone thru the steps in this article, however, I require client certifictaes with one of the apps on the web Server and the CA for that app is on the web server also, so I need to require client certs at the web server in order to check there validity. If I'm only running http from the isa server tot he web server, when the web server executes the request for a client certificate it's not running under ssl and fails in the code. I need to pass the ssl right thru to the server.
|
|
|
|
RE: SSL - Certificate missing - 31.May2001 8:19:00 PM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
quote: Originally posted by Kb575: Thanks for the info Peter. I can actually get this to work and have gone thru the steps in this article, however, I require client certifictaes with one of the apps on the web Server and the CA for that app is on the web server also, so I need to require client certs at the web server in order to check there validity. If I'm only running http from the isa server tot he web server, when the web server executes the request for a client certificate it's not running under ssl and fails in the code. I need to pass the ssl right thru to the server.
Hi Kb, Do you have the client certificates installed on the clients that need to tunnel through the ISA Server? Thanks! Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get It Here
|
|
|
|
RE: SSL - Certificate missing - 31.May2001 8:25:00 PM
|
|
|
tshinder
Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
|
quote: Originally posted by Kb575: Tom, whoops... Anyway, in response to your question. The Thawte server certificate is installed on the Web server and on the Incoming requests ip for the ISA Server. It is not however able to be selected on the web publishing section. I wish the ssl connection to pass right thru to the web server as it requires client certificates to be verified on the web server. I can get ssl to work in the case where I terminate the SSL at the isa firewall, and pass http only requests to the web server, but it means I cannot require client certificates at the web server...Does this answer your question...?? Thoughts....??? Cheers
Hi Kb, As noted in this thread, you can terminate the conenction at the ISA Server by installing the certificate on the appropriate Inbound Web Requests listener and using Web Publishing Rules. Or, you can terminate the SSL connection on the web server by using Server Publishing rules. However, you cannot use Web Publishing and terminate the SSL connection at the web server. You *can* create a *new* SSL connection between the ISA Server and the Web Server, but that represents a second secure tunnel, and not the original one from the web client and the web server. HTH, Tom ------------------ Tom Shinder http://www.isaserver.org/shinder/ Get It Here
|
|
|
|
RE: SSL - Certificate missing - 3.Jul.2001 11:41:00 AM
|
|
|
hanchong
Posts: 9
Joined: 3.Jul.2001
From: Kuala Lumpur, Malaysia
Status: offline
|
quote: Originally posted by tshinder: Hi Kb,As noted in this thread, you can terminate the conenction at the ISA Server by installing the certificate on the appropriate Inbound Web Requests listener and using Web Publishing Rules. Or, you can terminate the SSL connection on the web server by using Server Publishing rules. However, you cannot use Web Publishing and terminate the SSL connection at the web server. You *can* create a *new* SSL connection between the ISA Server and the Web Server, but that represents a second secure tunnel, and not the original one from the web client and the web server. HTH, Tom
Hi Tom, Just one more question. What is the exact steps to set up the new SSL connection from the ISA to the internal web server then ?
|
|
|
|
RE: SSL - Certificate missing - 4.Jul.2001 5:51:00 AM
|
|
|
sfaryu
Posts: 84
Joined: 1.Feb.2001
From: Los Angeles, CA, USA
Status: offline
|
I would like to know the steps also. I want to terminate the SSL request at the Web Server so I don't have to install the certificate on the ISA server. Someone told me that I don't have to install the certificate on the ISA and got it to work. I would like to only install the SSL certificate on the web server and not on the ISA. Does this way work, Tom?
|
|
|
|
RE: SSL - Certificate missing - 4.Jul.2001 5:55:00 AM
|
|
|
Kb575
Posts: 29
Joined: 7.May2001
From: Canberra,ACT,Australia
Status: offline
|
Sfaryu, In my many postings to this group and thru the purchase of the book, all is not as easy as it seems. I have left this project sit for a while, but about three posts up it gives you a clue.You terminate the SSL connection at the ISA server with Web publishing or you can terminate it on the web server with server publishing. Again I state I haven't got this working yet, but more thru lack of effort than it not working. I have turn my attentions to other things.. If you have access to the book, the section on server publishing is very detailed and should help you get the job done. Post here with your success/failure.
|
|
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts |
|