Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

Topic # 80185 28-Mar-2011 15:41
Send private message

Hi team,

Does anyone know of a good guide/tutorial for how to create a wildcard certificate? Before I buy one I want to be sure FTMG will perform the SSL routing (by URL) I desire so need to generate one for testing.


Create new topic


1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 460097 18-Apr-2011 13:21
Send private message

So I've created the Certificate Services server with a webpage for submission. Then used Opensso (Open SUSE) to create the CSR, but the Certificate Created is not accepted by FTMG.

Note: Microsoft AD propogates the Certificate Services Server as Trusted Root on all other machines on the domain.

3384 posts

Uber Geek
+1 received by user: 389

Trusted

  Reply # 460099 18-Apr-2011 13:22
Send private message

Not answering the question buuut - why not get more IPs - sooo much more simple.





 
 
 
 




1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 460100 18-Apr-2011 13:26
Send private message

Hmmm, I suspect my problem is that I did not create the CSR on the target host?



1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 460103 18-Apr-2011 13:29
Send private message

Zeon: Not answering the question buuut - why not get more IPs - sooo much more simple.


$$$$$$



1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 460104 18-Apr-2011 13:30
Send private message

To put in context, this at my home, not a commercial solution, just a self training exercise.



1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 460516 19-Apr-2011 14:37
Send private message

So, got this working. The important part was to use

certreq.exe -new

(and not a third party) with the following reqest.inf file (I went to this and then away again as it did not present a UI)

[NewRequest]
Subject = "CN=*."
MachineKeySet = True
KeyLength = 2048
KeySpec=1
[RequestAttributes]
CertificateTemplate = WebServer


Infrastructure Geek
4043 posts

Uber Geek
+1 received by user: 193

Trusted
Microsoft NZ
Subscriber

  Reply # 460634 19-Apr-2011 20:12
Send private message

the scenario you posted will work for several servers from the same SSL listener. you may run into problems if you need different authentication methods defined on the listeners. e.g. one for forms based AD integration for exchange web access, a different one for basic auth passthrough (e.g. web server with user/pass) and a different one again for RPC over HTTPS




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs




1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 461197 21-Apr-2011 08:56
Send private message

Yes, indeed I have. Cannot get RDGateway to work in this configuration. I'm not sure I'm going to be able to get everything I want to work through a single IP address. So far I have SharePoint, OWA and a basic Web Site configured. Critically I need the HTTPS proxy for Exchange and ActiveSync to work, which I have my doubts will be successful.

Infrastructure Geek
4043 posts

Uber Geek
+1 received by user: 193

Trusted
Microsoft NZ
Subscriber

  Reply # 461454 21-Apr-2011 20:51
Send private message

you can always serve up HTTPS/RPC over a custom port.  ActiveSync too, but its more a pain configuring phones to use custom ports




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs


15312 posts

Uber Geek
+1 received by user: 4035

Trusted
Lifetime subscriber

  Reply # 461470 21-Apr-2011 21:50
Send private message

I can't even see how to tell my phone to use a non standard port to connect to activesync over ssl. If you can tell me, I will have a statue erected in your honour!

I have android 2.3

Infrastructure Geek
4043 posts

Uber Geek
+1 received by user: 193

Trusted
Microsoft NZ
Subscriber

  Reply # 461486 21-Apr-2011 23:26
Send private message

networkn: I can't even see how to tell my phone to use a non standard port to connect to activesync over ssl. If you can tell me, I will have a statue erected in your honour!

I have android 2.3


if its supported, i would expect that you would just enter server name as myexchange.co.nz:444.  This plus the ssl required flag should result in calls to https://myexchange.co.nz:444/ .  Assuming its supported....




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs


Infrastructure Geek
4043 posts

Uber Geek
+1 received by user: 193

Trusted
Microsoft NZ
Subscriber

  Reply # 461487 21-Apr-2011 23:27
Send private message

hmm. lots of hate for google about this being an issue in android here: http://code.google.com/p/android/issues/detail?id=4901




Technical Evangelist
Microsoft NZ
about.me/nzregs
Twitter: @nzregs




1985 posts

Uber Geek
+1 received by user: 19

Trusted
Subscriber

  Reply # 461616 22-Apr-2011 15:56
Send private message

I'm abandoning TS Gateway and just going to try and get Exchange and SharePoint to work, if even that is achievable, the listener configuration for the two may conficting requirements, oh well, so much for cutting over this weekend.

Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

$3.74 million for new electric vehicles in New Zealand
Posted 17-Jan-2018 11:27


Nova 2i: Value, not excitement from Huawei
Posted 17-Jan-2018 09:02


Less news in Facebook News Feed revamp
Posted 15-Jan-2018 13:15


Australian Government contract awarded to Datacom Connect
Posted 11-Jan-2018 08:37


Why New Zealand needs a chief technology officer
Posted 6-Jan-2018 13:59


Amazon release Silk Browser and Firefox for Fire TV
Posted 21-Dec-2017 13:42


New Chief Technology Officer role created
Posted 19-Dec-2017 22:18


All I want for Christmas is a new EV
Posted 19-Dec-2017 19:54


How clever is this: AI will create 2.3 million jobs by 2020
Posted 19-Dec-2017 19:52


NOW to deploy SD-WAN to regional councils
Posted 19-Dec-2017 19:46


Mobile market competition issues ComCom should watch
Posted 18-Dec-2017 10:52


New Zealand government to create digital advisory group
Posted 16-Dec-2017 08:47


Australia datum changes means whole country moving 1.8 metres north-east
Posted 16-Dec-2017 08:39


UAV Traffic Management Trial launching today in New Zealand
Posted 12-Dec-2017 16:06


UFB connections pass 460,000
Posted 11-Dec-2017 11:26



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.