<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Renewing a self-signed certificate in SBS 2003</title>
	<atom:link href="http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003/feed" rel="self" type="application/rss+xml" />
	<link>http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003</link>
	<description>From the mind of David Schrag</description>
	<lastBuildDate>Wed, 25 Apr 2012 08:44:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: John Clegg</title>
		<link>http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003/comment-page-1#comment-69089</link>
		<dc:creator>John Clegg</dc:creator>
		<pubDate>Fri, 06 Apr 2012 18:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003#comment-69089</guid>
		<description>You are a prince among gurus and saved me hours of sweat on a bank holiday.

Many thanks! Now why the hell wasn&#039;t this findable in some Microsoft help files?</description>
		<content:encoded><![CDATA[<p>You are a prince among gurus and saved me hours of sweat on a bank holiday.</p>
<p>Many thanks! Now why the hell wasn&#8217;t this findable in some Microsoft help files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven Kelly</title>
		<link>http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003/comment-page-1#comment-37735</link>
		<dc:creator>Steven Kelly</dc:creator>
		<pubDate>Fri, 03 Sep 2010 21:18:06 +0000</pubDate>
		<guid isPermaLink="false">http://davidschrag.com/schlog/407/renewing-a-self-signed-certificate-in-sbs-2003#comment-37735</guid>
		<description>Thanks! This helped me on my way to a solution, but since we also have a 3rd party certificate, and multiple FQDNs (without SSL), I needed to do a little more - details below.

The CEICW on SBS 2003 Premium SP1 (with ISA 2004) makes two certificates, ISAcert and SBScert. ISACert is for the external FQDN, and external HTTPS connections use it. ISA then decrypts the request and re-encrypts it with SBScert to send it to the internal IIS web site, publishing.*.{lan&#124;local}.

If you use a 3rd party SSL certificate for your external FQDN, you probably still use tunnelling using the internal SBScert. If the internal SBScert expires before the external 3rd party certificate, clients get an odd 500 server error (see http://support.microsoft.com/kb/823074). Unlike a normal certificate error (e.g. for a self-signed or expired cert), clients can&#039;t ignore the error to continue to the site =&gt; bad news!

Re-running CEICW as stated above will correctly update both SBScert and ISAcert, but will leave ISA using the self-signed cert for external connections, rather than the paid-for 3rd party cert. In ISA, go to Firewall Policy, then in rightmost pane choose Toolbox, expand Web Listeners, double-click SBS Web Listener, on Preferences tab choose SSL Select... button, re-select your 3rd party certificate, and Apply.

If you also have other FQDNs (without SSL), the CEICW may/will have lost them. You need to add them back as Public Names in ISA&#039;s Default SBS Publishing Rule.</description>
		<content:encoded><![CDATA[<p>Thanks! This helped me on my way to a solution, but since we also have a 3rd party certificate, and multiple FQDNs (without SSL), I needed to do a little more &#8211; details below.</p>
<p>The CEICW on SBS 2003 Premium SP1 (with ISA 2004) makes two certificates, ISAcert and SBScert. ISACert is for the external FQDN, and external HTTPS connections use it. ISA then decrypts the request and re-encrypts it with SBScert to send it to the internal IIS web site, publishing.*.{lan|local}.</p>
<p>If you use a 3rd party SSL certificate for your external FQDN, you probably still use tunnelling using the internal SBScert. If the internal SBScert expires before the external 3rd party certificate, clients get an odd 500 server error (see <a href="http://support.microsoft.com/kb/823074" rel="nofollow">http://support.microsoft.com/kb/823074</a>). Unlike a normal certificate error (e.g. for a self-signed or expired cert), clients can&#8217;t ignore the error to continue to the site =&gt; bad news!</p>
<p>Re-running CEICW as stated above will correctly update both SBScert and ISAcert, but will leave ISA using the self-signed cert for external connections, rather than the paid-for 3rd party cert. In ISA, go to Firewall Policy, then in rightmost pane choose Toolbox, expand Web Listeners, double-click SBS Web Listener, on Preferences tab choose SSL Select&#8230; button, re-select your 3rd party certificate, and Apply.</p>
<p>If you also have other FQDNs (without SSL), the CEICW may/will have lost them. You need to add them back as Public Names in ISA&#8217;s Default SBS Publishing Rule.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

