Windows Server - leaf certificate

Asked By Ingmar Van Glabbeek
19-Mar-10 05:22 AM
When working with a self signed certificate, how do I make a new leaf
for webmail.foo.bar?
IIS
(1)
ServerOp
(1)
Glabbeek
(1)
Myserver
(1)
SBS2008
(1)
Schreef
(1)
Cert
(1)
CSR
(1)
  Ingmar Van Glabbeek replied to Ingmar Van Glabbeek
19-Mar-10 05:29 AM
To clarify, this is on a SBS2008 server

Op 19/03/2010 10:22, Ingmar Van Glabbeek schreef:
  Cliff Galiher - MVP replied to Ingmar Van Glabbeek
20-Mar-10 01:51 PM
You do not.  Self-signed, by definition, is not capable of being in a chain.

You *can*, however, issue certificates from an internal CA.  These are not
server so they will not be trusted by non-domain machines...so they'd behave
very similar to self-signed certificates.

In SBS 2003, you would  have to install the CA role and configure it.  Technet
has several articles on this process.
In SBS 2008, the CA role is installed by default, so you would  use the
certificate MMC snap-ins to request and issue certificates.

-Cliff
  Ingmar Van Glabbeek replied to Cliff Galiher - MVP
22-Mar-10 08:02 AM
With the MMC module in sbs2008 I manage to enroll a new cert for my
server but I cannot see where I could issue another one for a different URL.



Op 20/03/2010 18:51, Cliff Galiher - MVP schreef:
  Cliff Galiher - MVP replied to Ingmar Van Glabbeek
22-Mar-10 03:25 PM
If this is for a web server (such as IIS) which it sounds like based on your
comments, you will need to use the IIS snap-in to generate a CSR.  You can
then either issue the certificate manually with the CSR generated, or you
can issue the certificate automatically as part of the CSR wizard.

Once you get into the IIS certificate wizard, it will become a lot more clear
and self-explanatory.

-Cliff
Create New Account
help
SBS2008 + Server 2008 R2 Terminal Windows Server SBS2008 Server2008R2 (Member of SBS2008 domain) I am configuring an SBS2008 environment. In this office there about 10 clients who log into the SBS. They are server and plan on running it as a Terminal Server (Remote Desktop). I have the SBS2008 running fine and the 2008R2 server installed and joined to the SBS2008 domain but I have not added the Remote Desktop Role to the 2008R2. I started of the web interface so I am looking into nntp news readers. Any suggestions? keywords: SBS2008, +, Server, 2008, R2, Terminal description: SBS2008 Server2008R2 (Member of SBS2008 domain) I am configuring an SBS2008 environment. In this office there
SBS2008 + C: \ partition very low on disk space Windows Server Hi All, Been to see someone who had a very early SBS2008 to do some service packing etc etc as they had been having some issues. When on some patching. No Previous Versions configured for C: \ Windows Server SBS Discussions Disk (1) IIS (1) Site (1) Ahhh here is someone with a similar problem. . . Sorry, not sure what on-the-c-drive-in-small-business-server-2008.aspx You can go into the IIS console and turn off the WSUS IIS logs keywords: SBS2008, +, C: \ , partition, very, low, on, disk, space description: Hi All, Been to see someone who had a very early SBS2008 to do some service packing etc etc as they had been having some issues. When
Need Opinions on Email Access Windows Server SBS2008 Remote clients (their computers not part of the domain) using Outlook 2003 / 2007 Currently they a POP connecter to access their email. I am transitioning the office to have the SBS2008 server host the email and I can easily transition each user in the office to look to the SBS2008 for email and migrate all of their existing email to the SBS2008. My problem is there are some remote users who are not part of the domain that just need to get access to their email (no other SBS2008 resources). What are my best options to 1) have those remote clients use their Outlook to access the SBS2008 instead of the ISP when it is transferred over 2) let those remote clients keep rrohio.com (remove 999 for proper email address) keywords: Need, Opinions, on, Email, Access description: SBS2008 Remote clients (their computers not part of the domain) using Outlook 2003 / 2007 Currently they
authentication turned on = 96 Under Exchange > Servers Based Authentication = 94 ticked, compression High set. Under IIS settings, I have my server > Web Sites> Default Web Site > Directory security set with the SP2 = 96 exchange has been reinstalled just in case, and SP2 reapplied Server is running IIS and ISA 6.0, with external certification in place. Outlook clients are both 2003 and Server (1) Outlook (1) Exception (1) Integrated Windows Authentication (1) Mobile devices Windows Mobile (1) IIS (1) Exchange Virtual Server (1) Protocols > HTTP> Exchange Virtual Server I have = 93enabled Forms Just console, if I look under the Server managment > Advanced Management > Active directories Users and Computers > myserver.local > Users. . . it does not list any of the users that I have created. Should Information Store Id no: 80040115-0514-000006bf> > occured 3) Unexpected Exchange mailbox Server error: Server (myserver.mydoimain.local) User : (a user@myaddress.co.uk) HTTP status code : [503]. Verify that the
_ / / _ / \ _@_ / \ _ _ | \ _ _ | \ _ __ _ / \ _ __ _ \ _ \ like servers Here, read this; Running IIS on Windows XP Professional Many people do not know that Windows XP Professional includes a fully functional web server, Microsoft IIS 5.1. For a small office or home, this is incredibly convenient. If you are wants to try web development with HTML, Javascript, Active Server Pages (ASP), or VBScript, having IIS can allow you to experiment quickly with files on your local system. Of course, you could always download and install the free and robust Apache web server, but IIS is somewhat simpler and the documentation is better. - - http: / / www.skepticalscience.com / http: / / stopbeck.com