Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IIS and SSL - cached SSL Certificate stuck??

Status
Not open for further replies.

nigelmoore

Technical User
May 26, 2003
8
AU
Guys & Gals,

Can anyone point me in the direction of what I have done wrong?

I have setup an SBS Server with IIS and Outlook Web Access. Up until I had purchased a third party SSL certificate I had issued a local one (from the local machine) and just had users click on the "YES" when going to the site.

I have now purchased the new certificate, removed the old one from IIS completely and installed the new one. However whenever I go to the site, it still comes up with the old certificate. I have tried rebooting the server, rebooting the client machines (I have tried from many different locations) and clearing the client machines cache's.

Whenever I go to the site now it still acts as though it is using the original locally issued certificate. Has anyone got any ideas on how I can get rid of this?
 
Hello,

I have exact the same problem. I think it would be helpful to find out, how to delete cerificates from the server.

Regards

Mathias.

[sadeyes]
 
This may be a long shot but look in the System32 folder and see if your certificate is being held there. It should have a .cer extension
 
Hello,

I only found some old .cer files in the system32\certserv, but they were not valid.

I found another solution to change the wrong propagation of the certificate: There is an option in sbs2000 in ISA Server properties where you can change the active certificate, which will be propagated if it is set at this point. Open ISA Server properties of the server and then incoming requests and there you can change your current certificate. After that the web proxy will be restarted. Now it should work.

Regards

Mathias.

[thumbsup2]


 
Hi,

Excellent work - that was the problem with my setup as well. Strange that complete re-installs of all the software (including ISA) server did not pick it up?

Now I have to battle the next problem. 500 Internal Server error, the target principle name is incorrect. I think this has something to do with host header names and what site the ISA is forwarding the requests onto. I will look into it next week

Anyway Mathias, thank you for posting your solution. It seemed to fix the issue so far!

Regards,

Nigel
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top