Forwarding HTTPS site by IP address

Forwarding HTTPS site by IP address

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Forwarding HTTPS site by IP address girardmj375 05-11-2007
Posted by on May 11, 2007, 11:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We are in the planning stages of relocating our office, and we had
some concerns about forwarding our web site and the effect it would
have on our secure site.

We currently have our secure site established as https://www.company.com/access
and everything works fine because the certificate is registered to
company.com. However, after we relocate, we will be forwarding
requests for this site from our old office to the webserver in the new
office during the time it takes the DNS records to populate the web.
We were planning on using the IP address of the webserver in the new
office to accomplish this.

When we test this out at our current location, and try to access the
the site using the redirect address of https://203.XXX.XXX.XXX/access,
we get an SSL error stating that "The name on the security certificate
is invalid or does not match the name of the site", which is expected
because we are now using the IP to access the site rather than the
domain name that has been registered.

Does anyone know of any way to get around this so that our clients
don't recieve this error in the day(s) it takes for the DNS record to
populate. I realize it will only be for a day or two for the records
to populate and users can simply click "Yes" to get past the warning,
but we would rather figure out a way around this to avoid getting the
calls that are sure to come when clients see the warning message.

Any help is greatly appreciated.


Posted by Jim Watt on May 11, 2007, 1:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On 11 May 2007 08:03:04 -0700, girardmj375@yahoo.com wrote:

>We are in the planning stages of relocating our office, and we had
>some concerns about forwarding our web site and the effect it would
>have on our secure site.
>
>We currently have our secure site established as https://www.company.com/access
>and everything works fine because the certificate is registered to
>company.com. However, after we relocate, we will be forwarding
>requests for this site from our old office to the webserver in the new
>office during the time it takes the DNS records to populate the web.
>We were planning on using the IP address of the webserver in the new
>office to accomplish this.
>
>When we test this out at our current location, and try to access the
>the site using the redirect address of https://203.XXX.XXX.XXX/access,
>we get an SSL error stating that "The name on the security certificate
>is invalid or does not match the name of the site", which is expected
>because we are now using the IP to access the site rather than the
>domain name that has been registered.
>
>Does anyone know of any way to get around this so that our clients
>don't recieve this error in the day(s) it takes for the DNS record to
>populate. I realize it will only be for a day or two for the records
>to populate and users can simply click "Yes" to get past the warning,
>but we would rather figure out a way around this to avoid getting the
>calls that are sure to come when clients see the warning message.
>
>Any help is greatly appreciated.


A few days before you do the move change the TTL on the
DNS records to the minimum value.

Relocate the web server as 'company.com' and then increase
the TTL to a normal value.
--
Jim Watt
http://www.gibnet.com

Posted by on May 11, 2007, 4:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

We don't manage our DNS server, our ISP does. Is the TTL something
that ISPs can modify per client, or is it server-wide for all of the
sites they host?


Posted by Steve Williamson on May 12, 2007, 10:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On May 11, 9:50 pm, girardmj...@yahoo.com wrote:
> We don't manage our DNS server, our ISP does. Is the TTL something
> that ISPs can modify per client, or is it server-wide for all of the
> sites they host?

They can modify the TTL for each hostname associated with the IP
address in question. I think the minimum is 5 minutes (see A record
lookup for www.bbc.co.uk) so you should be sorted pretty quickly :)


Posted by on May 14, 2007, 9:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options

I'll talk to my ISP about this then. Thanks for all of your help.
It's greatly appreciated.


Similar ThreadsPosted
FTP SSH port forwarding December 27, 2006, 1:02 pm
Port forwarding/open ports? January 30, 2006, 2:51 pm
HTTPS over TOR May 11, 2006, 5:39 pm
https and the lock March 29, 2006, 1:09 pm
Phorm, mitm, and https February 23, 2008, 9:34 am
Hacking site! July 14, 2005, 12:14 pm
suspicious site January 23, 2008, 7:20 pm
Cross Site Scripting for .exe? June 6, 2005, 12:45 pm
US Gov looking for input about IE ONLY pre-patient web site... August 13, 2005, 11:57 pm
how to allow different companies to use a site without logging in? November 21, 2005, 1:55 pm

The site map in XML format XML site map

Contact Us | Privacy Policy