|
tshinder -> RE: Discussion about article on publishing TSAC/Remote Desktop Web Sites article (23.Jun.2006 3:19:36 PM)
|
quote:
ORIGINAL: gary1218 Well, I needed two certs. In Microsoft's article:" Troubleshooting SSL Certificates in ISA Server 2004 Publishing", it states "The name of the certificate on the ISA Server computer must match the name that external clients will specify to reach the published Web site." and in the same article, referring to HTTPS to HTTPS connections, it states "...the name of the certificate on the IIS Web site of the published server must match the name by which ISA Server identifies the Web server", thereby implying that you need two certs. And, in Microsoft's article "Publishing Multiple Web Sites using a Wildcard Certificate in ISA Server 2004", it describes the method of using the Wildcard cert, then replacing the Wildcard cert with the internal common name cert on the internal Web server. We were receiving the 500 error regarding the "Target Principal Name" Using a Hosts entry didn't work to correct this problem, I tried that. I read this article AFTER I discovered that the two certs worked. I then changed and issued the Wildcard cert on the ISA server so I wouldn't have to create a new listener on the ISA every time. The reason is; we have a single solid DNS structure internally with a different internal domain name (internalcompany.org) than external public domain name (externalcompany.org), which initially had no public servers hosted from our network. This design was the prevailing wisdom at the time we implemented Windows 2000 Active Directory and is the same as (I'm certain), 99.98745% of the companies out there. Thanks for your reply! HTH Gary Hi Gary, You really don't need two different certs. If you read thorugh the articles on this site you'll learn lots of tips and tricks used by the ISA pros that show you how to make this work. Best and easiest way is to use a single cert, and create a well-designed split DNS. This was the most common configuration I heard about from the ISA firewall pros I talked to last week at TechEd. HTH, Tom
|
|
|
|