IIS Server Security - self signed server certificate

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > November 2004 > self signed server certificate





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author self signed server certificate
paul_mat

2004-11-02, 6:08 pm

I have a Windows 2000 server running IIS 5 and I need to install a self signed server certificate. How do I go about creating and then installing the certificate.

just a little bit more info, i've already read threw http://www.microsoft.com/technet/co...0304.mspx#EBBAA
and done all that it has told me to do, inculdeing download the SSLDiaq tool and have made a temperary CA, it only lasts for a week and i can not edit the details on it, i want to be able to edit it's details and make it last for a year.

any help offered would be greatll appercated.
Miha Pihler

2004-11-03, 2:48 am

Hi,

SSL Diag will not allow you to customize your certificate since it is only
meant for testing purposes.

If you need your own certificate, one option is to setup your own CA server
(CA service) on Windows 2000 or (even better on Windows 2003). If you setup
Windows 2000 CA with certificate validity of 5 years, you can then issue SSL
certificate for your web server that will last 5 years or less.

If you intend to move your web server from IIS 5 to IIS 6 (Windows 2003) you
can then use SelfSSL tool that will issue self signed certificate with
validity period of one year.

Here is more information on how to setup and run your own CA server

New features:
http://www.microsoft.com/technet/pr...lan/pkienh.mspx
Operations guide:
http://www.microsoft.com/technet/pr...y/ws03pkog.mspx
Managing PKI:
http://www.microsoft.com/technet/pr...ity/mngpki.mspx
Best Practices:
http://www.microsoft.com/technet/pr...y/ws3pkibp.mspx
Certificate templates -
http://www.microsoft.com/technet/pr...y/ws03crtm.mspx
Key archival -
http://www.microsoft.com/technet/pr...y/kyacws03.mspx
Certificate Autoenrollment in Windows Server 2003
http://www.microsoft.com/technet/pr...y/autoenro.mspx
Advanced certificate enrollment:
http://www.microsoft.com/technet/pr...ty/advcert.mspx
web enrollment:
http://www.microsoft.com/technet/pr.../webenroll.mspx
EFS:
http://www.microsoft.com/technet/pr...oy/cryptfs.mspx
CRLS: http://www.microsoft.com/technet/se...to/tshtcrl.mspx

Mike

"paul_mat" <paul_mat.1f4jd7@mail.webservertalk.com> wrote in message
news:paul_mat.1f4jd7@mail.webservertalk.com...
>
> I have a Windows 2000 server running IIS 5 and I need to install a self
> signed server certificate. How do I go about creating and then
> installing the certificate.
>
> just a little bit more info, i've already read threw
> http://tinyurl.com/4tc6n
> and done all that it has told me to do, inculdeing download the SSLDiaq
> tool and have made a temperary CA, it only lasts for a week and i can
> not edit the details on it, i want to be able to edit it's details and
> make it last for a year.
>
> any help offered would be greatll appercated.
>
>
>
> --
> paul_mat
> ------------------------------------------------------------------------
> Posted via http://www.webservertalk.com
> ------------------------------------------------------------------------
> View this thread: http://www.webservertalk.com/message457032.html
>



paul_mat

2004-11-03, 4:08 pm

So just to make sure i have this correct, if i had IIS 6 i could download the selfSSL tool and sign my own certificate, but becuase i have IIS 5 i can't download the selfSSLtool
Miha Pihler

2004-11-04, 2:46 am

Hi,

As far as I have checked SelfSSL will only work on II6 and IIS 5.1 (IIS 5.1
is IIS service running on Windows XP).

You could still issue certificate with SelfSSL on IIS 5.1 if you have it
around or if you set it up and once it is issued, you can export if and
import it to IIS 5 (Windows 2000).

Mike

"paul_mat" <paul_mat.1f65pc@mail.webservertalk.com> wrote in message
news:paul_mat.1f65pc@mail.webservertalk.com...
>
> So just to make sure i have this correct, if i had IIS 6 i could
> download the selfSSL tool and sign my own certificate, but becuase i
> have IIS 5 i can't download the selfSSLtool
>
>
>
> --
> paul_mat
> ------------------------------------------------------------------------
> Posted via http://www.webservertalk.com
> ------------------------------------------------------------------------
> View this thread: http://www.webservertalk.com/message457032.html
>



Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com