Solved

How to load a reissued SSL certificate on a SBS 2008 server?

Posted on 2010-11-26
11
886 Views
Last Modified: 2012-05-10
I'm not getting much help from the certificate issuer so I'll throw it out to you guys.
Current setup:
I have 3 servers, SBS2008 and two IIS servers.
I have an SSL certificate with SAN successfully installed on the SBS box (using the SBS console wizard).

Problem:
The IIS servers both need a certificate installing for https so I have had my SAN cert reissued with extra SANs to use on these servers as well (cert is licensed for 3 servers so that's fine).
I have established that in order to successfully load the reissued cert onto my IIS servers I need to export it with key as .pfx on the original server and then import said pfx onto the other two servers. (I have done this successfully on one but of course it throws up cert errors in a browser as the version of the cert I exported/imported is the original without the extra SANs).
What I am having a surprising amount of trouble establishing is how to replace my original cert with the reissue on the SBS box, so that I can export/import it onto the other servers.

What I've tried so far:
I have tried regenerating a CSR with the SBS wizard and then loading the revised cert but it rejects it as not compatible.
I have tried importing a certificate already on the server (ie the reissue which I manually imported using MMC certificates snapin) using the SBS wizard but again it rejects it.
There are no more options in the SBS Wizard.
From previous experience I know that the standard Exchange 2007 ways of loading a certificate using EMS commands don't work on a SBS box.

Am I up a dead end? Is there any way of getting SBS2008 to accept a certificate with extra SANs?
0
Comment
Question by:texan_gerbil
  • 6
  • 5
11 Comments
 
LVL 38

Expert Comment

by:Philip Elder
Comment Utility
Why not generate a CSR on each IIS box  and use that to import the re-issued cert?

Why use the SBS wizard when realistically that is not what it was meant for.

Philip
0
 

Author Comment

by:texan_gerbil
Comment Utility
That doesn't work either (sorry forgot to mention that). If I do what you suggest, I get an error on loading the cert saying it doesn't match the pending request. This suggests perhaps that the details in the request file  don't match the reissued cert, but I am entering exactly what the issuer told me to.
I know the import pfx route will work if i can only load the new cert onto the SBS server.
0
 
LVL 38

Expert Comment

by:Philip Elder
Comment Utility
How are the HTTPS calls managed? Are they managed by a setup in ISA/TMG to deliver HTTPS requests to a certain server depending on the URL? Or is a gateway device using aliased IPs to deliver HTTP/HTTPS to each of the three servers?

Your CSR on each IIS should be:
 IIS 1:  sub1.domain.com
 IIS 2: sub2.domain.com
 SBS: remote.domain.com

Using a CSR via each server assures you that you have the correct primary common name and then the subdomains would be irrelevant.

Since your certificate provider allows for three servers, the above scenario should work.

Philip
0
 

Author Comment

by:texan_gerbil
Comment Utility
I think I see what you're saying. The latter scenario is what we do - firewall with NAT.
The only certificate I have been issued has common name remote.domain.com. At no point has anyone at issuer's agent or issuer (Globalsign btw) said anything about creating CSRs on the IIS servers with different common names. When I have done it as a test I have used remote.domain.com on all servers.

What you're suggesting would be fine if I effectively had three independent certificates, but I though that was the point of a SAN certificate - the same cert contains all the required domain names so you only need one instance.

Sorry, I don't know much about the ins and outs of all this and I'm getting steadily more confused...
0
 
LVL 38

Expert Comment

by:Philip Elder
Comment Utility
You have a point. In my digging around looking for specific info on configuring SAN certificates for SBS I did not see anything specific.

Does the certificate provider revoke any previous certificates when you generate/re-issue a new one?

Philip
0
Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

 

Author Comment

by:texan_gerbil
Comment Utility
I agree. I've not found anything specific to SBS either. I only got the original certificate installed correctly on the SBS box with the help of demazter here on EE - he was adamant that you have to use the wizard or the cert won't install correctly - the usual Exchange 2007 instructions using EMS commands don't work (which I confirmed).

To answer your question, I don't think they do revoke the previous certs - I'm still running the original certificate happily on the SBS box.

0
 
LVL 38

Accepted Solution

by:
Philip Elder earned 500 total points
Comment Utility
Yes, the original certificate can be installed using the SBS Wizard.

However, the wizard should not be used to set the certificate in place on the other two IIS machines. The wizard is not capable of dealing with the SAN aspect.

That is why I am suggesting to use the native IIS CSR ability to obtain the certificate. When the native IIS tool is used then when the cert is generated by the provider and you import it IIS receives the certificate it expects and things should just work.

Philip
0
 

Author Comment

by:texan_gerbil
Comment Utility
So let me get this straight. You're suggesting that I -
leave the SBS server as is;
generate two new CSRs for the two IIS servers with sub1.domain.com and sub2.domain.com as common names;
submit them to Globalsign and get them to make 2 reissues of the certificate with different common names to the original?

I can but ask them, although it may be Monday before I get a response. Watch this space...
0
 
LVL 38

Expert Comment

by:Philip Elder
Comment Utility
That is one option if they are amicable to it.

If not, then use the other server's IIS CSR to obtain a re-issue of the cert _for that server_ so that IIS gets a cert it requested.

Philip
0
 

Author Closing Comment

by:texan_gerbil
Comment Utility
I generated a new CSR on one of the IIS servers using the same common name (remote.domain.com), got the cert reissued against it and installed it OK. Then exported it to pfx and imported it onto the other one.
I still have the original issue cert installed on my SBS server and no-one has yet explained how I can replace that, although I don't need to. Just hope I can do it when the cert need renewing...
0
 
LVL 38

Expert Comment

by:Philip Elder
Comment Utility
When the time comes, delete the cert out of the Personal Cert store that is currently being used _after_ using the wizard to generate a new CSR.

Once the new cert is issued and the old one is deleted you can then use the wizard to import the newly generated cert.

You would be good to go from there.

Philip
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Easy CSR creation in Exchange 2007,2010 and 2013
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now