IIS Server Security >> SSL and certificates

by Kevin » Tue, 09 Dec 2003 22:30:00 GMT

Are client certificates necessary for SSL or just server
certificates?

The Microsoft help for setting up SSL takes you through
creating a server root certificate and another server
certificate and then installing each on all of the
clients. But other documentation that I have read
suggests that SSL only needs server certificates and that
client certificates are only needed for certificate
authentication. I want to use forms authentication and
don't won't to force our customers to deploy client
certificates if they don't have too.


IIS Server Security >> SSL and certificates

by Keith W. McCammon » Tue, 09 Dec 2003 23:22:33 GMT


Only a server certificate is required. The client should have the root
certificate of the issuing CA installed, but in most cases (I.e., public
sites with certificates issued by Verisign, Entrust, etc.) this is already
done, so many folks simply assume that this step doesn't exist.








IIS Server Security >> SSL and certificates

by Keith W. McCammon » Wed, 10 Dec 2003 01:42:42 GMT

Unless you want everyone to get an annoying warning every time they visit
your site, yes. It's actually not that bad, though. You can push it out
via SMS, or have them download an auto-installing file from a web site.








RE: SSL and certificates

by a-chaun » Thu, 11 Dec 2003 05:25:55 GMT



A server certificate is what you'll want to do encrypted traffic over port
443 between IIS and a client's browser. You can install CA on one of your
IIS boxes and make your own certificates, you can get a temporary sample
certificate for free from Verisign to test with and play with, or you can
purchase one from a certification authority such as Verisign or Thwate or
such.

Client certificates are what you might want to issue to select clients if
you want to control who can and cannot authenticate to an IIS website.
Client certificates give you an alternative to Integrated, Digest, and
Basic authentication and can even be mapped to Active Directory accounts.
It gives you a method of authentication that works as seamlessly as
Integrated authentication but, unlike integrated, will work over multiple
router hops.


Here is a list of some certificate-related KB articles for your reference:


324069 HOW TO: Set Up an HTTPS Service in IIS
http://support.microsoft.com/?id=324069

299525 HOWTO: Set Up SSL Using IIS 5.0 and Certificate Server 2.0
http://support.microsoft.com/?id=299525

290625 HOW TO: Configure SSL in a Windows 2000 IIS 5.0 Test Environment by
http://support.microsoft.com/?id=290625


257591 Description of the Secure Sockets Layer (SSL) Handshake
http://support.microsoft.com/?id=257591


257587 Description of the Server Authentication Process During the SSL
Handshake
http://support.microsoft.com/?id=257587

257586 Description of the Client Authentication Process During the SSL
Handshake
http://support.microsoft.com/?id=257586


239875 HOW TO: Use ASP to Force SSL for Specific Pages
http://support.microsoft.com/?id=239875

234022 XCLN: Configuring Exchange OWA to Use SSL
http://support.microsoft.com/?id=234022

216907 HOW TO: Obtain a Test Certificate or a Test Client Authentication
http://support.microsoft.com/?id=216907


197306 How to Troubleshoot SSL in Internet Information Server 4.0
http://support.microsoft.com/?id=197306


187504 HTTP 1.1 Host Headers Are Not Supported When You Use SSL
http://support.microsoft.com/?id=187504



228991 How to Create and Install an SSL Certificate in Internet Information
4.0
http://support.microsoft.com/?id=228991


279681 How to Force SSL Encryption for an Outlook Web Access 2000 Client
http://support.microsoft.com/?id=279681



320291 XCCC: Turning On SSL for Exchange 2000 Server Outlook Web Access
http://support.microsoft.com/?id=320291


232136 HOW TO: Back Up a Server Certificate in Internet Information
Services 5.0
http://support.microsoft.com/?id=232136



232137 How to Import a Server Certificate for Use in Internet Information
Services 5.0
http://support.microsoft.com/?id=232137


246072 Certificate Authorities: Using Digital Certificates for
Authentication (in IIS 4.0)
http://support.microsoft.com/?id=246072


289749 Certificate Revocation Lists (CRL) and IIS 5.0: Common Questions
http://support.microsoft.com/?id=289749


281106 How to Use a Certificate for SSL Authentication Within a Web
Publishing (ISA 2000)
http://support.microsoft.com/?id=281106


295281 How To Renew or Create New Certificate Signing Request While Another
(IIS5)
http://support.microsoft.com/?id=295281


310114 HOW TO: Export Certificates in Windows 2000
http://support.microsoft.com/?id=310114



310178 HOW TO: Install Imported Certificates on a Web Server in Windo

Similar Threads

1. SSL/TLS Certificates on 2003 Cluster

We have Exchange 2003 running on a Server 2003 Active/Passive cluster. 
We're required to begin sending email using TLS soon to one specific domain. 
When I go to generate a CSR so that the CA can generate our certificate, 
will it be for the node that the CSR is generated from.  If so, wouldn't 
exchange fail to send messages to that domain or is there a way to use the 
certifcate on both nodes.
Thanks,
Andrew 


2. SSL Client Certificate

3. IIS 6, Windows 2003 Release 2, SSL and certificates

IIS 6 on Windows 2003 release 2 configures the default web site to use SSL. 
I can understand why what with the general philosophy of locked down by 
default. However, for an intranet, is it okay to turn if off? Otherwise 
users get a certificate error. We don't want to specifically pay for a SSL 
certificate for each IIS server for internal use. We have thought about 
generating our own and distributing it around all the machines but that 
seems a bit naff.

Any comments?

Thanks, Rob. 


4. SSL Public Certificate Timeout

5. SSL renewal certificate problem

Hi,
  I have just renewed the SSL certificate on my 
site but a problem has arisen. 
  
  The SSL certificate on my site was about to expire and I 
thought to renew the certificate before the expiry date. 
  I started the renewal process on the Verisign site. I 
selected Old CSR option in the drop down and entered the 
CSR which I had present on the system (as my common name 
and other details in my ceritificate had not changed). I 
next entered the other details as usual and entered my 
payment information. 

  The whole process went smoothly and Verisign gave me the 
successful message at the end and allotted me an order 
number.

  However, even after the passing of one month, when ever 
I or anyone else try to browse the site a popup appears 
stating that the certificate of the site is expired or not 
valid. 

  This is very frustrating and I would like to know what 
is the problem. I have emailed Verisign several times but 
they only give general answers. 

  I would like to point out that I have not received any 
response CSR (private key or renewal certificate) from 
them of any kind but Verisign keeps on insisting in its 
emails to install the renewal certificate. 

Please help me ASAP.

Asif

6. Porblem with SSL client certificates on IIS win2k3 after installing SP1 - IIS Server Security

7. Seeking setup advice on SSL and Certificates for W2k3

Although I have been working with PC networks for a little over ten years, I 
am new to the IPSec, SSL, and Certificate configuration and management part 
of it.  To the point, I have been given the task of configuring my server to 
allow users to access e-mail via OWA with SSL and/or a pocket PC using 
Windows mobile 5 with IPSec/L2TP.



Forgive me if this is not the place for this question, but I do know that I 
will need to use IIS during the setup process.



I have searched Microsoft's site for articles on SSL and Certificates but 
there are just too many to sort through and find the one that will best help 
me setup my Windows Server 2003 with IIS 6.0 to have SSL/Certificates/IPSec. 
I also have Exchange 2003 SP2.  I am not looking for a long-winded how-to in 
a response but more of a best practices advice and a link or two to some 
good step-by-step instructions.  Like I said, I have read some instructions 
that appear to be what I need but inevitably at some point in the steps 
given the instruction no longer match what I see on the screen, and 
therefore I get lost.



Maybe a response could also include the must-have items to make SSL work 
with OWA, like "you must have this; this, and this to have it work.  I 
appreciate any and all responses, advice, or just directional signs to a 
better place to get the advice I seek.



Thanks, - Eunis


8. SSL Wildcard Certificate Replacement - IIS Server Security