12-13-04 11:38 PM
Hi Mike-
I followed the steps you outlined below and I still am prompted with every
visit to the test site. I am using my own CA to do this and can see the
imported certificate in IE. Does it need to be in any specific container? It
is in the "Trusted Root certification Authorities"
I also took a look at the certificate and it appears to be OK, but there is
a warning on the security alert message box that reads "The name on the
security certificate is invalid or does not match the name of the site."
Thanks
-Phil
"Miha Pihler" <mihap-news@atlantis.si> wrote in message
news:uFyeUAp3EHA.3908@TK2MSFTNGP12.phx.gbl...
Hi Phill,
To avoid this the client would have to trust your CA server certificate. You
can instruct your user to import the CA certificate.
If you setup your own CA here is where you can download CA certificate:
Open Web Interface for your CA server and go to Download a CA certificate,
certificate chain or CRL. Here click on Download CA certificate. Save the
file and transfer it on the client (all your clients and servers that will
work with your Exchange server). Double click on it and follow the wizard.
Default values should be OK. Once you install it, all the certificates
issued on this CA will be trusted.
If this site will be only used inside domain, you can import CA certificate
to the clients using active directory.
Another option would be to buy the certificate (prices are usually about 150
USD or more per year) from trusted CA agency (e.g. Thawte or Verisign).
Mike
"Phil Strack" <philstrack@hotmail.com> wrote in message
news:eg8wWej3EHA.3316@tk2msftngp13.phx.gbl...
> Hi-
> Never configured SSL on IIS 6.x before. I've set up a site and enabled
> SSL.
> I have created a local cert authority on another internal server and have
> installed the certificate on web server. (Servers are all Win 2003
> Standard...clients are all XP SP1 & 2) SSL appears to work okay, when I
> hit
> the site from a browser it requires https but it prompts to OK the
> certificate every time on the client. Is there anyway to have it only
> prompt
> the first time and trust the client for future visits to the site?
>
> On the client I have followed the prompt to view the certificate and
> import
> it locally (Which was successful) however, I am still prompted every I
> visit
> the site.
>
> Thanks in advance for any guidance regarding this problem.
>
> -Phil
>
>
[ Post a follow-up to this message ]
|