SSL Certificates For IIS 5 And IIS6
May 26, 2008a few migration of domains from IIS 5 to IIS 6, these have SSL certs, wonder can the SSL certs of IIS 5 be used on IIS 6? Anyone tried that before?
View 2 Repliesa few migration of domains from IIS 5 to IIS 6, these have SSL certs, wonder can the SSL certs of IIS 5 be used on IIS 6? Anyone tried that before?
View 2 RepliesI use an SSL certificate on IIS6 for Outlook web access.
I have to renew in the next few days.
Now I find that Godaddy have changed the minimum bit length from 1024 to 2048, but the Microsoft Wizard doesn't give me the chance to change the bit length when I try to generate the CSR file.
If I remove the certificate and generate a new certifcate CSR will I be OK? (I can stand a little downtime - it's a small organisation).
Do I have to get all the text the same as when I first requested the SSL certificate? Or just the URL bit?
I am fairly new to managing an IIS 6 server and recently installed PHP 5. I am still learning about ISAPI and ISAPI filters. In the WSE within IIS Manager I have allowed PHP to be used. Is PHP running as an ISAPI application and if so why would no filter be showing up in the ISAPI filters property box of the website? Everything works fine, I am just trying to get a better grasp of this issue.
View 0 Replies View RelatedI have a web application built with PHP which uses the MVC design pattern.
The application forwards all requests through index.php.
I am using IIRF (similar to mod_rewrite - IIS6 has no native rewrite module) to rewrite all requests through the index.php file and this is successful.
My application has several "modules" which I wish to be accessible via different URLs. For example the following is how I wish to set up my URLs: ...
I have enabled compression in IIS6 on win2k3 server and the dynamic compression is working lovely but the static compression is not functioning. I have double checked the metabase settings and permissions on the Temp Folder (IUSR write permissions) but nothing is ever written to the folder and my static files (htm,html) are not sent with compression! FWIW I can compress them by adding the filetype to the dynamic compression metabase string and they work but this is not efficient. I think I must have overlooked something...
Here are the metabase values:
<IIsCompressionSchemeLocation ="/LM/W3SVC/Filters/Compression/deflate"
HcCompressionDll="%windir%system32inetsrvgzip.dll"
HcCreateFlags="1"
HcDoDynamicCompression="TRUE"
HcDoOnDemandCompression="TRUE"
HcDoStaticCompression="TRUE"
HcDynamicCompressionLevel="9"
HcFileExtensions="htm
html
txt"
HcOnDemandCompLevel="9"
HcPriority="1"
HcScriptFileExtensions="asp
dll
php"
>
</IIsCompressionScheme>
<IIsCompressionSchemeLocation ="/LM/W3SVC/Filters/Compression/gzip"
HcCompressionDll="%windir%system32inetsrvgzip.dll"
HcCreateFlags="1"
HcDoDynamicCompression="TRUE"
HcDoOnDemandCompression="TRUE"
HcDoStaticCompression="TRUE"
HcDynamicCompressionLevel="9"
HcFileExtensions="htm
html
txt"
HcOnDemandCompLevel="9"
HcPriority="1"
HcScriptFileExtensions="asp
dll
php"
>
</IIsCompressionScheme>
<IIsCompressionSchemesLocation ="/LM/W3SVC/Filters/Compression/Parameters"
HcCacheControlHeader="max-age=86400"
HcCompressionBufferSize="8192"
HcCompressionDirectory="C:WINDOWSIIS Temporary Compressed Files"
HcDoDiskSpaceLimiting="FALSE"
HcDoDynamicCompression="TRUE"
HcDoOnDemandCompression="TRUE"
HcDoStaticCompression="TRUE"
HcExpiresHeader="Wed, 01 Jan 1997 12:00:00 GMT"
HcFilesDeletedPerDiskFree="256"
HcIoBufferSize="8192"
HcMaxDiskSpaceUsage="99614720"
HcMaxQueueLength="1000"
HcMinFileSizeForComp="256"
HcNoCompressionForHttp10="FALSE"
HcNoCompressionForProxies="TRUE"
HcNoCompressionForRange="FALSE"
HcSendCacheHeaders="TRUE"
>
</IIsCompressionSchemes>
A client of mine suffered repeated attacks on his web pages defaced with msg
New Priv8 Bug In iis6
I can't seem to be able to solve for him, have arranged hardening of his server, have done root kit scans etc all came out to nothing.
Is there any IIS 6 bug that is not patched that can cause this?
I've installed Imagemagick on our server and tested that it works using the little test that you do at the end of the installation. All is fine.
However, in order for my web site to seeuse it I assume I need to tell IIS 6 about it's presence? If so, how do I do it? If not, do I just need to allocate permissions to the Imagemagick folder (eg IUSR)?
I have virtual folder in IIS6 which has asp file as default and several jpg files. How to prevent JPG files download from server? I want to let execute asp file only and do not let users download jpg files.
View 0 Replies View Relatedwe've been installing a web-app on a domain controller at work. Previously the app ran on WAMP but the new server has to run IIS, though PHP and MySQL is acceptable for now.
We've jumped through hoops to get it working as well as it is now, but we've hit a few snags which seem common, but none of the solutions work for us.
We were having problems where the MySQL extensions for PHP could not be loaded because of access rights. When we look at a phpinfo() output the MySQL information is completely missing. This happens with any user set in the application pool with the exception of Administrator. When we make that user the one that runs that application pool then the MySQL extensions load fine and the whole system works perfectly. Even if we change it to another admin user the system still won't work.
I am having trouble setting up webdav on IIS6. I wasted all day on this today.
So far I have set it up to work over the internet with anonymous access.
Now I want to turn on:
1) basic authentication
2) SSL
I try to turn on (1) but:
- when try to access over the internet, it prompts for my login but it doesn't accept the login and keeps reprompting me.
- when I try to access from the local server, it seems to accept the login but gives an error 'the folder you entered does not appear to be valid, please choose another'
I have created a new user who has permission to access both the directory on the server and the virtual directory in IIS. I have turned on the webdav extension. I have tried reinstalling IIS too.
i recently set up a new testing web server(iis6), but can't view any of my websites hosted on my mac (osx leopard). I can ping the server from the mac, and RDP with out any problems, just can't view any websites. i've tried using the ip of the server (192.168.1.15) in the browser the server name but still no luck. server firewal has been disabled
View 3 Replies View Relatedweb stats software for my server.
Need the basics stuff like hits, but path analysis would be awesome.
I thought maybe if it was an IIS extension, that would be good?
Anyways, i was wondering who the major players are out there, and which ones are popular. I am willing to get a paid one.
I'm told smart stats is good.
I am attempting to change the host headers on my site that take my domains and forward them out to another domain.
My problem is that if a person type in [url], it brings them to my site and every link of the site is then [url]instead of redirecting it to my intended [url]
My site is hosted on a friends server, which is in his office on a 24MB Business ADSL connection, and is running Server 2003 Enterprise.
I thought i'd try and set up custom error pages for my site last night, but for whatever reason, I can't get them working.
I did a test page with random text, and named it 404.htm.
I then did a file with the following in:
<Files .htaccess>
order allow,deny
deny from all
</Files>
ErrorDocument 404 /404.htm
I then renamed the file to .htaccess after uploading both of the files.
However, when I tried entering a non existant page url, the normal IIS 'page cannot be found' error came up.
In addition, the .htaccess file was still visible when I connected via ftp again.
Now I think of it, I can understand the file not ending up invisible, since files with a . in front are most commonly used on *nix OS's.
However, that wouldn't explain the error page not working.
Is there something I need to get the person who owns the server to do to get it working, or am I doing it completely the wrong way for a Windows machine?
should have done a search before posting really.....I was doing it the wrong way, and I will need to get him to do it, as it needs setting up in the IIS config.
When ever I edit php.ini the changes are not reflected in my PHP applications (I check using phpinfo). Even after restarting IIS (Right click on the computer in IIS > All Tasks > Restart IIS) the changes are not reflected.
The only way I found out how to update the changes is by restarting the whole server, but this is not pratical.
How can I get the edits in php.ini to reflect in my PHP applications without having to restart the whole server?
how to trace or know who is overloading IIS in windows 2003 server?
When i check in the task manager , i saw sometimes w3wp.exe (IIS Worker Process) using high CPU usage for long time. That cause the server to be sluggish and sometime not responding.
Any tips or software that can tell which websites that cause the overload?
Customer wants to move his website in-house along with his email. The hardware guy installed a windows 2003 64-bit exchange server. I logged in with logmein and created a directory c:Inetputwwwroot hewebsite. Copied iisstart.html to the new dir. Put the company name in the iisstart file. Opened IIS6. Went to properties of the default website and pointed to the new directory on the home dir page. Added iisstart.html the Documents page and moved it to the top. Closed everything. Opened Internet Explorer 7 and put in http://localhost. All worked well. Brought up the new start page. Opened IE7 on my pc and put there ip address in and it also brought up the new webpage (tested the port 80 in the router). Said we were ready to go.
The hardware guy sent me an email stating that he was having problems with the 64-bit version and took the server back to the 32-bit version of windows exchange server. I logged back in with logmein and followed the same exact steps as above but it will not show the new webpage. Am getting a page not found error.
I have done the above on several 2003 servers and several xp pro machines. Always works.
Have done one 2003 exchange server. Went to a couple of those servers and made sure the default website settings were exactly the same as the ones that work. Still no help.
Downloaded an iis6 troubleshooting program from microsoft but cannot locate the error. I have been studying the II6 documentation and 2003 exchange server documentation. Went thru all the tutorials in google on iis6 and exchange I can find no help.
We are migrating an existing multi-site Windows2003/IIS6 web hosting system with
CFusion8
MS Access backend databases
SQL2000 backend databases
http and https site access
to
Windows2012 R2/IIS8.5 with
CFusion10
MS Access backend databases (not updated)
SQL2014 databases
http and https site access
On the new system we are looking to add Plesk12 to give users easier management of their own websites.I am about to install the trail version of Plesk12 WebHOST.I have the following questions:
1. Can we use the plesk migration tool to move the websites from the old IIS6 to the new IIS8.5 server?
2. If not, am I right to think we would migrate from IIS6 to IIS8.5 manually and then import these websites into Plesk12 from the new server?
3. Can I migrate the existing websites piecemeal over onto the new server and into the Plesk control panel at the same time as creating brand new websites under the control panel?
4. Once Plesk is installed on the new IIS server is there a KB article on how to add all these existing websites to Plesk - I could not find one.
5. Is the local windows administrator account used for the install used to run any services?
I need to setup SSL.
I've never used SSL on any of my websites and I've never really understood how the certificates work.
I understand that SSL is used as a secure connection protocol (https://) and that it needs a valid certificate so that the encrypted data transfer can be committed.
OK makes sence, but why do some websites seem to have such difficultly setting up valid certificates?
You can setup SSL by with Apache + OpenSSL, but why do website hosting providers still allow you to purchase SSL certificates (isn't it supposed to be free)?
Finally, is it possible to setup SSL for a multiple-domain (Victual Host) server?
I have a client who requested me to do a website for his credit union company.
Some of the pages are forms that require customers to enter crucial information ie ssn etc etc. I told him that this can be broken into..and therefore he would need a secure way of transmitting this information. Therefore would the SSL certificate work for this issue? Where do i get one? We have a dedicated server and do i need to configure anything on that? Where can i get a trusted SSL Certificate, and ofcourse help to install it.
if you could recommend a place to get a certificate... I have seen many people talking about that you could get a rapidSSL for $15 +/- , but I was not able to find any sites that low.
View 14 Replies View RelatedA year ago I bought a Geotrust quick SSL vertificate from my dedicated server host for about 299.
Now I see companies like server tastic selling the same Geotrust cert for $79 ehen Geotrusts website is still $299. How can that be? what am I missing here.
who offers the best package?
View 5 Replies View RelatedIf your provider has a self-signed ssl.. anyway you can import those into clients like Outlook or Windows Mail (formerly OE6 on XP)
To stop the nagging prompts.. or is there a setting to stop prompts?
I purchased an EV SSL Cert, and all is fine. Installed via cPanel, and I get the green address bar in Firefox, but not in IE.
Comodo (the vendor) have an Auto-Enhancer feature which automatically tells IE to give me a green bar. They state in their FAQ the following instructions to install the feature:
Replace the bundle file that is in use for the web site.
Use the 'SSLCertificateChainFile' directive instead of the 'SSLCACertificateFile'/'SSLCACertificatePath' directives.
I have download a .CA-BUNDLE file from them.
Please tell me, now what do I do? I am at a lost at their instuctions, and going by my dealings with them, I think I can get help from you guys more accurately and quickly.
The server runs WHM/cPanel 11 with Apache 2 with mod_ssl. Full root access, but I am a Linux newbie.
I do web hosting (reseller); how much, in USD per year, do you think is a "reasonable" fee to charge clients for a shared SSL connection ?
The SSL is going to cost me $$ per year and I may have some use for it, but if clients want a shared SSL, instead of buying their own, I need to apportion the costs I incur somehow, and (maybe) make some small profit. I see the shared SSL as more of a service, but clients should pay _some_ $$ if they want to use one.
Any ideas on how much I should charge, please ?
Thanks,
Peter
I'm just looking for some background information or a place where I can learn more about this.
Here's the problem:
The web site runs on a dedicated Apache server. There's 2 SSL certificates installed, one for e-commerce for https://www.mysite.com and one to help with the administrative interface for https://admin.mysite.com. I run a custom php application that forces the web page from http://www.mysite.com to https://www.mysite.com when going to an e-commerce page.
Generally everything runs Ok but a few times this year there has been a problem where the php application points to https://www.mysite.com/ecom.php but instead it gets https://admin.mysite.com/ecom.php and gets a page not found.
In discussing this with my web hosting company they claim they haven't changed anything but they do manage to fix the problem and get the web site working correctly again.
I generally figure that the web hosting company has done some type of maintenance on the web server and messed-up the dns entries or something for the SSL part of the web site but this is really outside my area of experience. I'm trying to understand what went wrong and where the entries are that determine when going to SSL which SSL certificate/URL is used.
I want to know how to install SSL Certificate and what kind of certificates available. How they work? Is there any cheap and good certificate.
View 5 Replies View RelatedMy website is currently running on http and the plesk control pannel is running on https
However the certificate for https for the plesk panel is out of date and self signed therefore web browsers promit its not valid.
I want to get a valid SSL certificate for https for Plesk, Client/Billing area and the main website.
I want to do it as easy as possiable (as I'm not one for technical stuff but if it was resoniable I could give it a go)
I dont want a self signed and want to try to go for something free or very cheap.
Any got any suggestions? I've looked around and come up with companys wanting alot of money I did come across another which was free but it was self signed.
I currently have a reseller accounts from Thawte, Comodo, and RapidSSL, but have realized that I can purchase Comodo and Geotrust SSL certificates cheaper from Namecheap.com and Enom.com
Namecheap.com support is (as always) superb. Any opinions from Enom.com support?
What about Resellerclub.com? I know that they recently started to sell Thawte certs at very good prices. How good is their support?
I have an ssl certificate installed on my main server. How can I encrypt a page on a website hosted on that server sharing the certificate?
View 11 Replies View Related