IIS Server Security - changing "CN" name

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > July 2006 > changing "CN" name





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author changing "CN" name
Gregg

2006-07-25, 1:23 pm

Hi,

I setup a CA server on Server 2003 (active Directory) with exchange. When I
access exchange through Outlook from home, I get the error "The server you
are connected to is using a security certificate that could not be verified
and certificate's CN name does not match the passed value" I looked at the
certificate and noticed it reads "issued by owacert.mydomain.com". We are
mydomain.net. Could this be causing the problem?
I am trying to let some of our people be able to use outlook out of office
and not have that certificate warning every time.

Thanks,
Gregg
Miha Pihler [MVP]

2006-07-25, 7:22 pm

Hi,

Are you using Outlook or Outlook Web Access to connect to Exchange from
home?

There are quite a few checks of the certificate before you can connect using
Outlook. Name (URL) that you entered in Outlook must be the same as the name
in the certificate (e.g. mail.domain.com). If this is URL that you are
using, but you e.g. have certificate issued to webmail.domain.com connection
will not be successful.
Certificate is also checked that it chains to trusted CA server. Your
computer where you hare using Outlook must trust CA server that issued the
certificate -- or again the connection will fail.

You can also test this by using IE. Enter https://webmail.domain.com
(replace this URL with URL to your Exchange server). Do you get any pop-ups
(Security Alerts)?

--
Mike
Microsoft MVP - Windows Security

"Gregg" <Gregg@discussions.microsoft.com> wrote in message
news:C7E40C3D-9968-4360-83E4-140A019FF4BF@microsoft.com...
> Hi,
>
> I setup a CA server on Server 2003 (active Directory) with exchange. When
> I
> access exchange through Outlook from home, I get the error "The server you
> are connected to is using a security certificate that could not be
> verified
> and certificate's CN name does not match the passed value" I looked at
> the
> certificate and noticed it reads "issued by owacert.mydomain.com". We are
> mydomain.net. Could this be causing the problem?
> I am trying to let some of our people be able to use outlook out of office
> and not have that certificate warning every time.
>
> Thanks,
> Gregg



Gregg

2006-07-25, 7:22 pm

I'm using outlook 2003. the settings in oultlook for smtp and pop are
exchange server's IP. When i do the test you suggested, i get page can't be
displayed.
Is their a way to change the CN name or should I start from scratch with the
CA server and make sure the .com is .net?

Gregg

"Miha Pihler [MVP]" wrote:

> Hi,
>
> Are you using Outlook or Outlook Web Access to connect to Exchange from
> home?
>
> There are quite a few checks of the certificate before you can connect using
> Outlook. Name (URL) that you entered in Outlook must be the same as the name
> in the certificate (e.g. mail.domain.com). If this is URL that you are
> using, but you e.g. have certificate issued to webmail.domain.com connection
> will not be successful.
> Certificate is also checked that it chains to trusted CA server. Your
> computer where you hare using Outlook must trust CA server that issued the
> certificate -- or again the connection will fail.
>
> You can also test this by using IE. Enter https://webmail.domain.com
> (replace this URL with URL to your Exchange server). Do you get any pop-ups
> (Security Alerts)?
>
> --
> Mike
> Microsoft MVP - Windows Security
>
> "Gregg" <Gregg@discussions.microsoft.com> wrote in message
> news:C7E40C3D-9968-4360-83E4-140A019FF4BF@microsoft.com...
>
>
>

Ken Schaefer

2006-07-26, 1:21 am

You will need to issue a new certificate. You should also revoke the old one
if you do not intend to use it.

Cheers
Ken

"Gregg" <Gregg@discussions.microsoft.com> wrote in message
news:7EB0D529-2C88-4239-BE27-FEE748C4165E@microsoft.com...[vbcol=seagreen]
> I'm using outlook 2003. the settings in oultlook for smtp and pop are
> exchange server's IP. When i do the test you suggested, i get page can't
> be
> displayed.
> Is their a way to change the CN name or should I start from scratch with
> the
> CA server and make sure the .com is .net?
>
> Gregg
>
> "Miha Pihler [MVP]" wrote:
>


Gregg

2006-07-26, 1:25 pm

If I do a new certificate, there is no way to change the CN. I have created
new certificates but they are still issued by risp.com, not risp.net.
Wouldn't i need to fix this first?

thanks for all the help.
Gregg

"Gregg" wrote:

> Hi,
>
> I setup a CA server on Server 2003 (active Directory) with exchange. When I
> access exchange through Outlook from home, I get the error "The server you
> are connected to is using a security certificate that could not be verified
> and certificate's CN name does not match the passed value" I looked at the
> certificate and noticed it reads "issued by owacert.mydomain.com". We are
> mydomain.net. Could this be causing the problem?
> I am trying to let some of our people be able to use outlook out of office
> and not have that certificate warning every time.
>
> Thanks,
> Gregg

Ken Schaefer

2006-07-26, 1:25 pm

No.

The "common name" in the issued server authentication certificate must match
the FQDN used by the user.

The root CA's certificate must be installed into the user's certificate
store so that it will trust certificates issued by that CA

Cheers
Ken

"Gregg" <Gregg@discussions.microsoft.com> wrote in message
news:2B7CEDAB-694E-4646-867D-D58ADB2A3550@microsoft.com...[vbcol=seagreen]
> If I do a new certificate, there is no way to change the CN. I have
> created
> new certificates but they are still issued by risp.com, not risp.net.
> Wouldn't i need to fix this first?
>
> thanks for all the help.
> Gregg
>
> "Gregg" wrote:
>


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com