Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Small Business Server > Trusted Cert Woes on SBS 2008

Reply
Thread Tools Display Modes

Trusted Cert Woes on SBS 2008

 
 
Bill Glidden
Guest
Posts: n/a

 
      09-30-2009
I decided to install a trusted cert from GoDaddy to make access to RWW,
OWA and Outlook Anywhere more user-friendly. I used:
http://smbtn.wordpress.com/2009/02/1...e-on-sbs-2008/
for my first few attempts (installing the intermediate bundle) and when
I had issues with this, I eventually used:
http://blogs.technet.com/sbs/archive...-sbs-2008.aspx
I have had several goes at this (using re-keyed certs)always with the
same results:

1. The trusted certificate never appears for selection as the preferred
certificate in the Certificate Wizard(only self-signed certs are
displayed). In the SBS Console, Network/Connectivity/Web Server
Certificate is showing the trusted cert from GoDaddy.

2. When I launch Outlook 2007, I get two Security Alerts from the site
remote.glidden.net.au. View Certificate shows the name of the trusted
cert office.glidden.net.au. This happens on PCs that are not using
Outlook Anywhere as well.

Otherwise the trusted certificate is functioning: no certificate warning
nags in RWW, OWA or Company Website.

A clue to all this is that the name of the trusted cert is different to
the self-signed one. Also, I run the fix my network wizard it tells me
that the trusted certificate has expired and removes it if checked.
I am new to and pretty clueless with certs: this is the first time i
have tried to install a trusted cert.

SBS BPA finds no issues.

Can someone please help me to sort this? Driving me bananas.
 
Reply With Quote
 
 
 
 
Les Connor [SBS MVP]
Guest
Posts: n/a

 
      09-30-2009
Hi Bill,

I'm assuming you use https://remote.blah.blah/remote or /owa to acces your
SBS, but your cert is for office.blah.blah.

If you use https://office.blah.blah/remote, your cert matches and you get no
warning. I looked at your cert, and it looks fine.


--
-----------------------------------------------
Les Connor [SBS MVP]

"Bill Glidden" <> wrote in message
news:...
> I decided to install a trusted cert from GoDaddy to make access to RWW,
> OWA and Outlook Anywhere more user-friendly. I used:
> http://smbtn.wordpress.com/2009/02/1...e-on-sbs-2008/
> for my first few attempts (installing the intermediate bundle) and when I
> had issues with this, I eventually used:
> http://blogs.technet.com/sbs/archive...-sbs-2008.aspx
> I have had several goes at this (using re-keyed certs)always with the same
> results:
>
> 1. The trusted certificate never appears for selection as the preferred
> certificate in the Certificate Wizard(only self-signed certs are
> displayed). In the SBS Console, Network/Connectivity/Web Server
> Certificate is showing the trusted cert from GoDaddy.
>
> 2. When I launch Outlook 2007, I get two Security Alerts from the site
> remote.glidden.net.au. View Certificate shows the name of the trusted cert
> office.glidden.net.au. This happens on PCs that are not using Outlook
> Anywhere as well.
>
> Otherwise the trusted certificate is functioning: no certificate warning
> nags in RWW, OWA or Company Website.
>
> A clue to all this is that the name of the trusted cert is different to
> the self-signed one. Also, I run the fix my network wizard it tells me
> that the trusted certificate has expired and removes it if checked.
> I am new to and pretty clueless with certs: this is the first time i have
> tried to install a trusted cert.
>
> SBS BPA finds no issues.
>
> Can someone please help me to sort this? Driving me bananas.


 
Reply With Quote
 
Les Connor [SBS MVP]
Guest
Posts: n/a

 
      09-30-2009
ps, you can change remote.blah.blah to office.blah.blah in the SBS wizard by
selecting the 'advanced' button. 'remote' is the default prefix.

--
-----------------------------------------------
Les Connor [SBS MVP]

"Bill Glidden" <> wrote in message
news:...
> I decided to install a trusted cert from GoDaddy to make access to RWW,
> OWA and Outlook Anywhere more user-friendly. I used:
> http://smbtn.wordpress.com/2009/02/1...e-on-sbs-2008/
> for my first few attempts (installing the intermediate bundle) and when I
> had issues with this, I eventually used:
> http://blogs.technet.com/sbs/archive...-sbs-2008.aspx
> I have had several goes at this (using re-keyed certs)always with the same
> results:
>
> 1. The trusted certificate never appears for selection as the preferred
> certificate in the Certificate Wizard(only self-signed certs are
> displayed). In the SBS Console, Network/Connectivity/Web Server
> Certificate is showing the trusted cert from GoDaddy.
>
> 2. When I launch Outlook 2007, I get two Security Alerts from the site
> remote.glidden.net.au. View Certificate shows the name of the trusted cert
> office.glidden.net.au. This happens on PCs that are not using Outlook
> Anywhere as well.
>
> Otherwise the trusted certificate is functioning: no certificate warning
> nags in RWW, OWA or Company Website.
>
> A clue to all this is that the name of the trusted cert is different to
> the self-signed one. Also, I run the fix my network wizard it tells me
> that the trusted certificate has expired and removes it if checked.
> I am new to and pretty clueless with certs: this is the first time i have
> tried to install a trusted cert.
>
> SBS BPA finds no issues.
>
> Can someone please help me to sort this? Driving me bananas.


 
Reply With Quote
 
Bill Glidden
Guest
Posts: n/a

 
      09-30-2009

Les Connor [SBS MVP] wrote:
> Hi Bill,
>
> I'm assuming you use https://remote.blah.blah/remote or /owa to acces
> your SBS, but your cert is for office.blah.blah.
>
> If you use https://office.blah.blah/remote, your cert matches and you
> get no warning. I looked at your cert, and it looks fine.
>
>

Hi Les,

No. I use either remote or office, and want to use office only, but i
get the same result with either. I know there is no error when I use
/owa or /remote. I'm only seeing the Outlook security warning.
 
Reply With Quote
 
Bill Glidden
Guest
Posts: n/a

 
      09-30-2009
Les Connor [SBS MVP] wrote:
> ps, you can change remote.blah.blah to office.blah.blah in the SBS
> wizard by selecting the 'advanced' button. 'remote' is the default prefix.
>

I missed that Advanced button... Will go there and do that. Thanks, Les.
 
Reply With Quote
 
Bill Glidden
Guest
Posts: n/a

 
      09-30-2009
Les Connor [SBS MVP] wrote:
> ps, you can change remote.blah.blah to office.blah.blah in the SBS
> wizard by selecting the 'advanced' button. 'remote' is the default prefix.
>


Les, I did that and interestingly, it made one of the Security Alerts go
away. Still got one. Will multiple office.glidden.net.au GoDaddy certs
be a problem or is only one of these active?
 
Reply With Quote
 
Bill Glidden
Guest
Posts: n/a

 
      09-30-2009
Les Connor [SBS MVP] wrote:
> ps, you can change remote.blah.blah to office.blah.blah in the SBS
> wizard by selecting the 'advanced' button. 'remote' is the default prefix.
>

Oh, and Les, I can now see and select the Trusted cert in the Wizard. I
can also see the for GoDaddy certs that I installed during the saga. All
have type=unknown. AND no more Outlook Security nags.

Thanks for helping me sort this and pointing me in the general direction
of SBS Console, Advanced Mode!

Cheers,
Bill
 
Reply With Quote
 
Les Connor [SBS MVP]
Guest
Posts: n/a

 
      09-30-2009
Good stuff, Bill - glad you got it sorted.

Key is the name in the cert must match the url/site you're accessing. You
can get a cert for multiple sites but in this instance you only need
office.<domain.com>

--
-----------------------------------------------
Les Connor [SBS MVP]

"Bill Glidden" <> wrote in message
news:...
> Les Connor [SBS MVP] wrote:
>> ps, you can change remote.blah.blah to office.blah.blah in the SBS wizard
>> by selecting the 'advanced' button. 'remote' is the default prefix.
>>

> Oh, and Les, I can now see and select the Trusted cert in the Wizard. I
> can also see the for GoDaddy certs that I installed during the saga. All
> have type=unknown. AND no more Outlook Security nags.
>
> Thanks for helping me sort this and pointing me in the general direction
> of SBS Console, Advanced Mode!
>
> Cheers,
> Bill


 
Reply With Quote
 
Ace Fekay [MCT]
Guest
Posts: n/a

 
      09-30-2009
"Bill Glidden" <> wrote in message
news:...
> Les Connor [SBS MVP] wrote:
>> ps, you can change remote.blah.blah to office.blah.blah in the SBS wizard
>> by selecting the 'advanced' button. 'remote' is the default prefix.
>>

> Oh, and Les, I can now see and select the Trusted cert in the Wizard. I
> can also see the for GoDaddy certs that I installed during the saga. All
> have type=unknown. AND no more Outlook Security nags.
>
> Thanks for helping me sort this and pointing me in the general direction
> of SBS Console, Advanced Mode!
>
> Cheers,
> Bill



Les, with an Exchange UC/SAN certificate, you can add those names into one
cert. The one certificate will allow multiple names added into the
certificate in what's called a subjective alternate names list. Once you've
purchased, or have your current certs modified or combined into one
certificate by GoDaddy (Exchange can use a single cert with multiple names
and they should be able to combine all of them into one for you and pro-rate
the price), you can use the Exchange PowerShell Commands to add the services
the cert will be used for.

Read the following for more info. I also just added a step-by-step in the
blog, today, to illustrate how to request and import the new cert, as well
as how to enable the use of the cert for other services, such as IIS, SMTP,
IMAP, POP, etc. Enabling it for IIS will work for what you want, as long as
the names that you need, such as rww.domain.com, office.domain.com, or
whatever else you need, is in the certificate subject alternate names list.
The manual methods work with SBS 2008, too.

Exchange 2007 UC/SAN Certificate
http://msmvps.com/blogs/acefekay/arc...rtificate.aspx


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCTS 2008, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA
Messaging
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.


 
Reply With Quote
 
Ace Fekay [MCT]
Guest
Posts: n/a

 
      09-30-2009
"Bill Glidden" <> wrote in message
news:...
> Les Connor [SBS MVP] wrote:
>> ps, you can change remote.blah.blah to office.blah.blah in the SBS wizard
>> by selecting the 'advanced' button. 'remote' is the default prefix.
>>

> Oh, and Les, I can now see and select the Trusted cert in the Wizard. I
> can also see the for GoDaddy certs that I installed during the saga. All
> have type=unknown. AND no more Outlook Security nags.
>
> Thanks for helping me sort this and pointing me in the general direction
> of SBS Console, Advanced Mode!
>
> Cheers,
> Bill



I meant to address my last post to Bill, not Les. Sorry....


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Server 2008 Trusted Certificate Machunter Windows Small Business Server 1 07-13-2009 04:07 PM
SBS 2008: using cert and dyndns.info and Outlook anywhere GARETT - TVGTECH Windows Small Business Server 6 04-16-2009 06:20 PM
Re: Cert generation in Windows SBS 2008 Les Connor Windows Small Business Server 2 12-17-2008 04:46 PM
Server 2008: Print driver installation woes Steve Friedl [MVP] Windows Server 3 08-15-2008 07:43 PM
Trusted Root Cert Auth Stor -empty/corrupt BrianG Windows Small Business Server 6 06-15-2005 01:27 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59