Using SSL Certificate for TSAC on NLB Windows 2003 Terminal Server

Using SSL Certificate for TSAC on NLB Windows 2003 Terminal Server

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Using SSL Certificate for TSAC on NLB Windows 2003 Terminal Server SOFULLER 03-28-2006
Posted by =?Utf-8?B?U09GVUxMRVI=?= on March 28, 2006, 11:42 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We have 2-load balanced Terminal Severs on our Intranet called TERMSRV1 and
TERMSRV2. We want to enable SSL on both for employee access via the Internet.
The Intranet NLB Cluster Name is TERMSRV and the FQDN on the Internet is
TERMSRV. We redirect HTTP requests for TERMSRV from the Internet to the
Intranet FQDN/NLB Cluster name TERMSRV via redirection using ISA2004 and can
do the same for HTTPS.

Would the certificates for both TERMSRV1 IIS and TERMSRV2 IIS be unique to
each server's FQDN or the NLB FQDN CLuster Name?

Thanks,
scott


--
Scott

Posted by =?Utf-8?B?U09GVUxMRVI=?= on March 28, 2006, 4:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The solution in our case was to create a certificate using Windows 2003 CA,
install the certificate on IIS (Changed default web site SSL port from 443 to
444) on the ISA2004.
Reconfigure the Firewall redirect rule to use HTTPS/SSL only and reference
the certificate created. This provides Secure TSAC Internet access to the
ISA2004 and then the traffic is redirected HTTP to the Terminal Server
cluster as it was before.
--
Scott


"SOFULLER" wrote:

> We have 2-load balanced Terminal Severs on our Intranet called TERMSRV1 and
> TERMSRV2. We want to enable SSL on both for employee access via the Internet.
> The Intranet NLB Cluster Name is TERMSRV and the FQDN on the Internet is
> TERMSRV. We redirect HTTP requests for TERMSRV from the Internet to the
> Intranet FQDN/NLB Cluster name TERMSRV via redirection using ISA2004 and can
> do the same for HTTPS.
>
> Would the certificates for both TERMSRV1 IIS and TERMSRV2 IIS be unique to
> each server's FQDN or the NLB FQDN CLuster Name?
>
> Thanks,
> scott
>
>
> --
> Scott

Posted by Brian Komar [MVP] on March 29, 2006, 7:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
SOFULLER@discussions.microsoft.com says...
> We have 2-load balanced Terminal Severs on our Intranet called TERMSRV1 and
> TERMSRV2. We want to enable SSL on both for employee access via the Internet.
> The Intranet NLB Cluster Name is TERMSRV and the FQDN on the Internet is
> TERMSRV. We redirect HTTP requests for TERMSRV from the Internet to the
> Intranet FQDN/NLB Cluster name TERMSRV via redirection using ISA2004 and can
> do the same for HTTPS.
>
> Would the certificates for both TERMSRV1 IIS and TERMSRV2 IIS be unique to
> each server's FQDN or the NLB FQDN CLuster Name?
>
> Thanks,
> scott
>
>
>
The certificates must contain the name used by the user to connect to
the server, so it would be termsrv.domain.com (not just termsrv)
Brian

Similar ThreadsPosted
Certificate enroll with Windows Server 2003? December 12, 2005, 9:46 pm
Certificate enroll with Windows Server 2003? December 12, 2005, 10:36 pm
Certificate problem with Windows Server 2003 May 22, 2006, 12:25 pm
Windows 2000 Certificate server---->2003 August 26, 2008, 3:52 pm
Certificate Services features vs Windows 2003 server editions May 24, 2006, 3:17 pm
Change CRL expiry date on Windows 2003 certificate Server July 27, 2006, 8:34 pm
Windows 2003 , MSDE 2000, Terminal Services January 12, 2008, 3:23 am
Certificate Error on 2003 server November 14, 2005, 2:23 pm
Using Server 2003 to sign Sonicwall VPN certificate March 27, 2007, 3:52 am
Certificate Web Enrollment (Server 2003 and Vista) November 14, 2008, 12:16 pm

The site map in XML format XML site map

Contact Us | Privacy Policy