Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SSL Bridging

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> SSL Bridging Page: [1]
Login
Message << Older Topic   Newer Topic >>
SSL Bridging - 23.Jun.2005 12:04:00 PM   
Pexowan

 

Posts: 6
Joined: 21.Jun.2004
From: Iowa
Status: offline
I am building ISA 2004 Enterprise environment and I am having trouble with bridging the SSL connection between the ISA Server and front-end exchange server. The environment consists of two ISA 2004 servers in an array configuration. I have imported the webmail certificate to the personal store on both ISA servers. On the bridging tab of the web publishing rule, I select "Use a certificate to authenticate to the SSL web server". I then click the corresponding "Select" button and get the follow error dialog box: "To select a certificate, you must install at least one identical certificate on each member server".

I have searched the message boards and Google and have come up short on this error message. Any help would be appreciated.
Post #: 1
RE: SSL Bridging - 23.Jun.2005 2:44:00 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Pex,

Try restarting each ISA firewlal in the ISA firewall array.

HTH,
Tom

(in reply to Pexowan)
Post #: 2
RE: SSL Bridging - 23.Jun.2005 2:56:00 PM   
Pexowan

 

Posts: 6
Joined: 21.Jun.2004
From: Iowa
Status: offline
Well, that didn't work. I do have a certificate installed on the listener. Any help would be appreciated.

(in reply to Pexowan)
Post #: 3
RE: SSL Bridging - 18.Aug.2005 9:30:00 AM   
Guest
You should use that option only if your owa server require client certificates for authentication.

from http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/digitalcertificates.mspx

Note
The option Use a certificate to authenticate to the SSL Web server enables you to specify the client certificate that ISA Server will use to authenticate itself to the Web server.

(in reply to Pexowan)
  Post #: 4
RE: SSL Bridging - 18.Aug.2005 10:11:00 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Edo,

Good eye! I didn't know that he was trying to configure the ISA firewall to use user cert auth to the OWA site.

Thanks!
Tom

(in reply to Pexowan)
Post #: 5
RE: SSL Bridging - 1.Sep.2005 9:26:00 AM   
jmdess

 

Posts: 4
Joined: 17.Jun.2005
From: Belgium
Status: offline
Hello.
I have the same problem.
ISA 2004 Enterprise with 2 array members and nlb.
I have imported the webmail certificate to the personal store on both ISA servers.
On a web listener properties|preferences, when I "Enable SSL" and click Select to select a Certificate I always get the follow error dialog box: "To select a certificate, you must install at least one identical certificate on each member server".

Question : How can I install identical certificates on the 2 array members to be recognized as valid certificates ?

Thank yo in advance.
jean-marie

I have searched the message boards and Google and have come up short on this error message. Any help would be appreciated.

(in reply to Pexowan)
Post #: 6
RE: SSL Bridging - 12.Oct.2005 10:37:00 AM   
jerumball

 

Posts: 52
Joined: 7.May2004
From: Sudbury, ON Canada
Status: offline
For what it's worth, I am getting the same error when trying to select a certificate for an SSL listener on my ISA2004 array for a secured web server I am trying to publish.

Does anyone know how to resolve this error?

Thanks.

(in reply to Pexowan)
Post #: 7
RE: SSL Bridging - 12.Oct.2005 4:23:00 PM   
pantherfan

 

Posts: 45
Joined: 7.Jun.2001
Status: offline
you should be creating/installing the cert on the actual exchange front end server, then export the cert to a file. Use that file to import into your isa server array members personal stores using the certificate mmc snap in.

On the publishing rule you should create a new listener and on that listener just choose the certificate that you have imported to your ISA server, but you should make sure the same certificate exists on all the isa server array members first.

Do not setup anything on the bridging tab for certs, that is for a wholly different purpose [Smile]

(in reply to Pexowan)
Post #: 8
RE: SSL Bridging - 4.Jul.2006 2:57:15 PM   
author22

 

Posts: 12
Joined: 20.May2006
Status: offline
You need to use here not just any certificate but that one you have private keys for. So be sure to include this option while exporting.

(in reply to pantherfan)
Post #: 9

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Exchange Publishing >> SSL Bridging Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts