Thursday, September 11, 2008
Issues with installing a new certificate Windows Server 2003
So a couple of weeks back we installed a new certificate on our Exchange front end server. The certificate had expired so instead of putting our users through the pain of clicking an extra button to accept the expired cert when they accessed OWA, we got a new one. A certificate is a basically adding another layer of encryption and authentication to a computer by making a secure connection to the server. Normal port 80 traffic is not encrypted. The new cert was installed without any problems. The next day we started getting calls that users were unable to access the front end server web page without being prompted several times for their credentials. Not all users were having this issue which pointed the individual problem to each computer instead of server. After scouring the internet for some kind of resolution I determined that the issue could temporarily be resolved by deleting temporary internet files, restarting IE and accessing the shortcut. Odd I thought, everything was working fine until we installed the new cert and now we’re having issues only a day after installing the new cert. Everything looked right. Computers were making a secure connection to the front server. We went to the CA with this issue and they told us everything was fine. I even reinstalled the cert. Everything pointed to the issue being with access to the directory, but didn’t make sense being prompted for credentials several times. Wouldn’t the browser just give an access denied? I kept trouble shooting the issue and determined that users were being prompted for the password, but as soon as they quit they were getting a message that access was denied. Additionally some were getting only part of the frames loaded when OWA came up. Again I thought it was odd when a user would try to access the front end, shouldn’t it give an all or nothing respond? Shouldn’t it load the whole page or give a straight up access denied? It was almost like OWA was asking for credentials for each frame on the front end. Well after more research and working with HP we discovered it was an issue with the URL. When users were setup for a shortcut to OWA we noticed that the server address was the same on all: https://frontendserver.domain.com/exchange/, but what about users that weren’t having issues. It turns out when you type in the https://frontendserver.domain.com you are directed to the Exchange/ after authenticating. I determined that the issue was something to do with the exchange/ on the end. After additional work with HP we determined that the problem was with anonymous access to the default web sites directory. After allowing this users were able to access the website with the / on the end or not. I’m not sure how this got changed? Was this a default change after installing a new certificate? At any rate this resolved my issue and I was happy. <3
Subscribe to:
Post Comments (Atom)

1 comments:
update yourself amigo
Post a Comment