Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

ISA 2006 - SSL Certificates showing as INVALID, but they are valid.

Posted on 2007-03-22
7
Medium Priority
?
5,179 Views
Last Modified: 2011-08-18
ISA 2006, Have imported valid, external SSL certificates into personal store of ISA server.  When pointing to them in ISA Listner, it is showing the certificate as "INVALID".   But, I have checked the certificate in MMC Certificates, and it is valid.
I have just downloaded a new SSL certificate from RapidSSL, and got the exact same issue.  

Help?
0
Comment
Question by:drakba
7 Comments
 
LVL 31

Expert Comment

by:merowinger
ID: 18772552
is it type "server certificate"?
0
 

Author Comment

by:drakba
ID: 18772682
It is a Web SSL cert created from a cert request in the companion IIS server.
0
 
LVL 3

Expert Comment

by:dbacks1000
ID: 18774591
So did you requested the SSL certificate with IIS on your Exchange server?  If not how did you do this?  If you did you will want to install that Cert on the Exchange Server and then export it out and install in on the ISA server.

You may want to download the Root certificate from RapidSSL and install it in your Trusted Root Certificates.
It look like thier Root Certificate is here...
http://www.rapidssl.com/legal/index.htm

Mike
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 3

Accepted Solution

by:
dbacks1000 earned 2000 total points
ID: 18774618
I am sorry, you never said Exchange you are just doing an IIS site.  You will want to export the Cert from the IIS site if you have not already done that and not use the one you download from RapidSSL form ISA.  (That has been my experience)
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18774637
First question, what are you publishing? Is this a direct connected service such as Sharepoint or a bridged item such as OWA?

If its bridged for owa, can you connect internally to the https://server/exchange url successfully and get a valid cert screen?
0
 

Author Comment

by:drakba
ID: 18779107
Ok, here is the deal.  

I took the certificate sent to me from RapidSSL, and imported it directly in to the ISA server.  That was the problem.  It did not get the private key from the IIS server.

I had to go into the IIS server, and export the cert. to a file (that included the private key), and import it that way into the ISA server, and BINGO, valid cert!
Thank you Dbaks1000!
0
 

Expert Comment

by:AboutToQuit
ID: 30519283
I joined this site to find a solution to this issue.  It was not here.  I'm sure that isn't the case 100% of the time, but thought I'd share what fixed the problem I was having...

You will receive this error if you are using enterprise edition, have an array of servers, and have not imported the certificate to all members of the array.  Until you do, it will show as invalid.

Cheers
0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are several problems reported according slow link speeds or poor performance in TMG 2010, UAG 2010 or ISA 2006. I want to collect here some of the common issues together to give a brief overview what can be the reason. Nevertheless, not all of…
Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
Integration Management Part 2
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question