INSTALLING YOUR SSL CERTIFICATE ON THE FILEHOLD SERVER ON WINDOWS 2008 X64 ON IIS 7



Similar documents
e-cert (Server) User Guide For Microsoft IIS 7.0

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

QMX ios MDM Pre-Requisites and Installation Guide

Generating an Apple Push Notification Service Certificate

CA NetQoS Performance Center

Setting Up SSL on IIS6 for MEGA Advisor

Wavecrest Certificate

Secure IIS Web Server with SSL

HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents

Enable SSL for Apollo 2015

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

Scenarios for Setting Up SSL Certificates for View

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Microsoft IIS 4 Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

Microsoft Exchange 2010 and 2007

Certificate Management for your ICE Server

S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

Document Classification: Public Document Name: SAPO Trust Centre - Generating a SSL CSR for IIS with SAN Document Reference:

Learning the Basics of Citrix Web Interface 4.6, Citrix Secure Gateway 3.1 and GoDaddy Wildcard SSL Certificate

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

etoken Enterprise For: SSL SSL with etoken

Mobility Manager 9.0. Installation Guide

BASIC CLASSWEB.LINK INSTALLATION MANUAL

How to Configure a Secure Connection to Microsoft SQL Server

Configuration (X87) SAP Mobile Secure: SAP Afaria 7 SP5 September 2014 English. Building Block Configuration Guide

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

RSA Security Analytics

Certificate Request Generation and Certificate Installation Instructions for IIS 5 April 14, 2006

Hardening Guide for EventTracker Server

2. In the Search programs and files field, enter mmc and hit the enter key

Millennium Drive. Installation Guide

To install the SMTP service:

Creating an Apple APNS Certificate

Sophos Anti-Virus for NetApp Storage Systems startup guide

ECA IIS Instructions. January 2005

NSi Mobile Installation Guide. Version 6.2

SETUP SSL IN SHAREPOINT 2013 (USING SELF-SIGNED CERTIFICATE)

APNS Certificate generating and installation

Deploying Remote Desktop IP Virtualization Step-by-Step Guide

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

DIGIPASS Authentication for Microsoft ISA 2006 Single Sign-On for Outlook Web Access

Browser-based Support Console

FTP Server Configuration

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

App Orchestration 2.5

Tel: (877) COMODO-5 Tel: +44 (0) Comodo Group.

e-cert (Server) User Guide For Microsoft Exchange Server 2010

Deploying Personal Virtual Desktops by Using RemoteApp and Desktop Connection Step-by-Step Guide

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

WHITE PAPER Citrix Secure Gateway Startup Guide

O Reilly Media, Inc. 3/2/2007

Reference and Troubleshooting: FTP, IIS, and Firewall Information

Setup SSL in SharePoint 2013 Using Domain Certificate

ACTIVE DIRECTORY DEPLOYMENT

Aspera Connect User Guide

Obtaining SSL Certificates for VMware Horizon View Servers

SSL Intercept Mode. Certificate Installation Guide. Revision Warning and Disclaimer

Managing the SSL Certificate for the ESRS HTTPS Listener Service Technical Notes P/N REV A01 January 14, 2011

Connection and Printer Setup Guide

Sharp Remote Device Manager (SRDM) Server Software Setup Guide

ACCEPT THE SECURITY CERTIFICATE FOR THE WEB FILTER

Installation Guide. SafeNet Authentication Service

OrgChart Now SSL Certificate Installation. OfficeWork Software LLC

FILEHOLD DOCUMENT MANAGEMENT SYSTEM 21 CFR PART 11 COMPLIANCE WHITE PAPER

Sophos Anti-Virus for NetApp Storage Systems startup guide. Runs on Windows 2000 and later

Obtaining SSL Certificates for VMware View Servers

HP Device Manager 4.6

SSL Guide. (Secure Socket Layer)

Customizing Remote Desktop Web Access by Using Windows SharePoint Services Stepby-Step

SSL Management Reference

1/4/12 Installing and Configuring WebDAV on IIS 7 : WebDAV for IIS 7.0 : Publishing Content to Web Sites : T

IIS, FTP Server and Windows

Desktop Deployment Guide ARGUS Enterprise /29/2015 ARGUS Software An Altus Group Company

Installation and Configuration Guide

SolarWinds Technical Reference

Intel vpro Technology. How To Purchase and Install Symantec* Certificates for Intel AMT Remote Setup and Configuration

Trend Micro Worry-Free Remote Manager Agent Installation Guide

User Guide Generate Certificate Signing Request (CSR) & Installation of SSL Certificate

Configuring Network Load Balancing with Cerberus FTP Server

Appendix E. Captioning Manager system requirements. Installing the Captioning Manager

Step By Step Guide: Demonstrate DirectAccess in a Test Lab

Certificates for computers, Web servers, and Web browser users

isupplier PORTAL ACCESS SYSTEM REQUIREMENTS

Pro-Watch Software Suite Installation Guide Honeywell Release 4.1

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Creating the Certificate Request

Sage HRMS 2014 Sage Employee Self Service Tech Installation Guide for Windows 2003, 2008, and October 2013

Microsoft IIS Integration Guide

Copyright

Lab 05: Deploying Microsoft Office Web Apps Server

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

App Orchestration 2.5

Global VPN Client Getting Started Guide

ProjectWise Mobile Access Server, Product Preview v1.1

Transcription:

INSTALLING YOUR SSL CERTIFICATE ON THE FILEHOLD SERVER ON WINDOWS 2008 X64 ON IIS 7

Copyright 2011 FileHold Systems Inc. All rights reserved. For further information about this manual or other FileHold Systems products, contact us at Suite 250-4664 Lougheed Highway Burnaby, BC, Canada V5C5T5, via email sales@filehold.com, our website www.filehold.com, or call 604-734-5653. FileHold is a trademark of FileHold Systems. All other products are trademarks or registered trademarks of their respective holders, all rights reserved. Reference to these products is not intended to imply affiliation with or sponsorship of FileHold Systems. Proprietary Notice This document contains confidential and trade secret information, which is proprietary to FileHold Systems, and is protected by laws pertaining to such materials. This document, the information in this document, and all rights thereto are the sole and exclusive property of FileHold Systems, are intended for use by customers and employees of FileHold Systems, and are not to be copied, used, or disclosed to anyone, in whole or in part, without the express written permission of FileHold Systems. For authorization to copy this information, please call FileHold Systems Product Support at 604-734-5653 or email sales@filehold.com.

Ta ble of Contents FileHold TABLE OF CONTENTS 1. CSR GENERATION: MICROSOFT IIS 7.X... 2 2. SSL CERTIFICATE INSTALLATION: MICROSOFT IIS 7.X... 5 3. INSTALLING THE ROOT AND INTERMEDIATE CERTIFICATES... 9 4. SET SITE BINDINGS IN IIS 7 ON DEFAULT WEB SITE FOR THE CERTIFICATE YOU HAVE INSTALLED FROM YOUR SSL PROVIDER... 13 5. ENSURE SSL IS REQUIRED ON THE FILEHOLD APPLICATION... 14 6. CHANGE WEB CONFIGS WITH FHINSTRUMENTATION TOOL... 14 7. TESTING YOUR SSL CERTIFICATE... 17 i May 2011

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 1. CSR GENERATION: MICROSOFT IIS 7.X WARNING: This information is provided purely as a guide and you should always follow the IIS 7 specific guide from your own SSL provider. 1. Click Start and go to Administrative Tools. 2. Start Internet Services Manager. 3. Click Server Name. 4. From the center menu, double-click Server Certificates in the Security section. 5. From the Actions menu, click Create Certificate Request. 2 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 6. This will open the Request Certificate wizard. 7. In the Distinguished Name Properties window, enter the information as follows: The Common Name field should be the Fully Qualified Domain Name (FQDN) or the web address for which you plan to use your IIS SSL Certificate. You will need to insure that the common name submitted in the CSR is the correct domain name / FQDN that you intend to use the certificate for. For wildcard SSL certificates the common name should contain at least one asterisks (*) e.g. *.comodo.com,*.instantssl.com,etc May 2011 3

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver Enter Organization and Organization Unit. These are your company name and department respectively. Enter your City/locality, State/province and Country/region. 8. Click Next. 9. In the Cryptographic Service Provider Properties window, leave both settings at their defaults (Microsoft RSA SChannel and 1024) and then click Next. 10. Enter a filename and location to save your CSR. You will need this CSR to enroll for your IIS SSL Certificate. 11. Click Finish. Your new CSR is now contained within the file c:\certreq.txt. 4 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 12. When you make your application, make sure you include the CSR in its entirety into the appropriate section of the enrollment form - including -----BEGIN CERTIFICATE REQUEST-----to-----END CERTIFICATE REQUEST----- 13. Click Next. 14. Confirm your details in the enrollment form and click Finish. TO SAVE YOUR PRIVATE KEY 1. Go to Certificates snap-in in the MMC. 2. Select Requests. 3. Select All tasks. 4. Select Export. 2. SSL CERTIFICATE INSTALLATION: MICROSOFT IIS 7.X 1. Click Start and select Administrative Tools. 2. Start Internet Services Manager. 3. Click Server Name. 4. From the center menu, double-click the Server Certificates button in the Security section. 5. From the Actions menu, click Complete Certificate Request. May 2011 5

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 6. This will open the Complete Certificate Request wizard. 7. Enter the location of your IIS SSL certificate (you will need to browse to locate your IIS SSL certificate this file will be the certificate sent to you in a zip file and should be named yourdomainname.crt ).Then enter a Friendly name. The friendly name is not part of the certificate itself, but is used by the server administrator to easily distinguish the certificate. Click OK. NOTE: There is a known issue in IIS 7 giving the following error Cannot find the certificate request associated with this certificate file. A certificate request must be completed on the computer where it was created. You may also receive a message stating ASN1 bad tag value met. If this is the same server that you generated the CSR on then, in most cases, the 6 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold certificate is actually installed. Simply cancel the dialog and press F5 to refresh the list of server certificates. If the new certificate is now in the list, you can continue with the next step. If it is not in the list, you will need to reissue your certificate using a new CSR and replace this Certificate. Please use the instructions provided from your SSL provider for this task. 8. After the certificate has been successfully installed to the server, you will need to assign that certificate to the appropriate website using IIS. 9. From the Connections menu in the main Internet Information Services (IIS) Manager window, select the name of the server to which the certificate was installed. 10. Under Sites, select the site to be secured with SSL. 11. From the Actions menu), click on Bindings. 12. This will open the Site Bindings window. 13. In the Site Bindings window, click Add. This will open the Add Site Binding window. May 2011 7

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 14. Under Type, select https. The IP address should be the IP address of the site or All Unassigned, and the port over which traffic will be secured by SSL is usually 443. The SSL Certificate field should specify the certificate that was installed previously. 15. Click OK. You now have an IIS SSL server certificate installed. 16. IMPORTANT!: You must now restart the IIS / the website to complete the install of the certificate 17. Once you have completed the above steps you will need to install the Root and Intermediate certificates manually. For installation instructions on how to manually install the other Root and Intermediate Certificates that are sent with your web server that you have been sent PLEASE read the next page 8 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 3. INSTALLING THE ROOT AND INTERMEDIATE CERTIFICATES 1. Please use the SSL certificates you have purchased from your certificate authority that provides sells SSL certificates. 2. Save these Certificates to the desktop of the web server machine. 3. Click Start, select Run, type mmc and click OK. 4. Click File and select Add/Remove Snap in. 5. Select Add. May 2011 9

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 6. Select Certificates from the Add Standalone Snap-in window and click Add. 7. Select Computer Account and click Next. WARNING: This step is very important. It must be the computer account and no other account. 10 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 8. Select Local Computer and select Finish. 9. Close the Add Standalone Snap-in window and click OK. 10. Return to the MMC TO INSTALL THE YOUR ROOT CERTIFICATE 1. Right click the Trusted Root Certification Authorities, select All Tasks, and select Import. May 2011 11

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 2. The Certificate Import Wizard opens. Click Next. 3. Locate the Root Certificate and click Next. 12 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 4. When the wizard is completed, click Finish. TO INSTALL THE INTERMEDIATE CERTIFICATE/CERTIFICATES 1. Right click the Intermediate Certification Authorities, select All Tasks, select Import. 2. Complete the Certificate Import Wizard again, but this time locating the intermediate Certificate when prompted for the Certificate file. NOTE: You will need to repeat this step for all the intermediate certificates that are sent to you. 3. Ensure that the Root certificate appears under Trusted Root Certification Authorities. 4. Ensure that the intermediate certificate / certificates appear under Intermediate Certification Authorities. 5. Once these are installed you may need to restart the server. 4. SET SITE BINDINGS IN IIS 7 ON DEFAULT WEB SITE FOR THE CERTIFICATE YOU HAVE INSTALLED FROM YOUR SSL PROVIDER 1. Click on Default Web Site in IIS 7 Administration application. May 2011 13

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 2. Click Bindings and then edit the bindings as needed. You can remove the port 80 HTTP binding if you wish. We recommend this. 5. ENSURE SSL IS REQUIRED ON THE FILEHOLD APPLICATION 6. CHANGE WEB CONFIGS WITH FHINSTRUMENTATION TOOL 1. Launch the FHInstrumentation tool located at: Program Files\FileHold Systems\Application Server\FH\FileHold\FHinstrumentation 2. Right-click and Run as Server or domain administrator account and remove the check mark to run with restricted permissions. Do this at all times when running this tool. 14 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 3. Select Change port, server name or protocol wizard and click Start. 4. Browse to find the Application Server Folder and then click Next. This locates the config files so the FHInstrumentation utility can change them. 5. Select Change Protocol check box and click Next. May 2011 15

FileHold Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver 6. The tool will update all web.config files from http to https and will save about 15 minutes of work with Notepad or Notepad ++. 7. Click Update to finish the procedure. 8. The task will finish successfully if the account you are using to run this tool has the appropriate server administrator permissions. 16 May 2011

Installing Your S SL Ce rti f icat e on the Fil ehold Ser ver FileHold 9. Click Finish. 10. Restart World Wide Web Service in Services.msc control panel or go to control panel and select services and restart it there. 7. TESTING YOUR SSL CERTIFICATE 1. Change all Web Client short cuts to HTTPS and FDA connection URL s to HTTPS and try to login. 2. Testing with Web Client: Do a test of search, adding a document, checking out a document, checking in a document, launching and completing a workflow (if you use this optional module). 3. Testing with Desktop Client: Repeat the same test. Do a test of search, adding a document, checking out a document, checking in a document, launching and completing a workflow (if you use this optional module) May 2011 17