Home Contact Us

 
 

Comtrust Support: Server Certificate: Microsoft Internet Information Server 4.01

Requirements.
STEP 1- Generating CSR (Certificate Signing Request).
STEP 2- APPLYING & DOWNLOADING SERVER CERTIFICATE .
STEP 3- Configuring the Server Certificate.
TESTING YOUR SERVER CERTIFICATE.
SECURITY ALERTS.


 

Requirements:

  • IIS 4.0
  • Internet Explorer 5.01 or higher


STEP 1- Generating CSR (Certificate Signing Request)

  1. Open the Microsoft Management Console.


  2. Expand the Internet Information Server folder by selecting the "+" sign.


  3. After expanding this folder, select the "+" sign next to the computer name.


  4. Right Click on the Default web site and choose properties.


  5. Choose Directory Security, Click on Edit.


  6. Click on Key Manager.


  7. Right Click on the WWW icon and select "Create New Key..."


  8. Choose "Put the request in a file that you will send to an authority."


  9. Type in the file name or keep the default.


  10. Click on Next


  11. Fill in the Key name, Password, Confirm Password. Set the Bit Length to 1024

    NOTE: In some cases, IIS 4 might not be able to show you 1024 Bit Length, to fix this problem:
    1. Upgrade Internet Explorer to the latest version (version 5.01 or higher)
    2. Upgrade your cipher strength for Internet Explorer to 128-bit

    These upgrades should have an effect on IIS. After a restart you should be able to generate your key with 1024 Bit Length.


  12. Click on Next


  13. Fill in the Organization, Organization Unit.


  14. Fill in the Common name. NOTE: This should be a fully qualified domain name like www.abc.com


  15. Click on Next


  16. Fill in the Country, State/Province and City/Locality.


  17. Click on Next


  18. Fill in Your name, Email address and Phone number


  19. Click on Next and then Finish


  20. Close the Key Manager and Choose YES when asked to " Commit all Changes ? "


  21. Now you should have a text file where you already specified its location in step 9. This file contains the CSR and it should look like this if opened with notepad:

STEP 2- APPLYING & DOWNLOADING SERVER CERTIFICATE :

  1. Apply for server certificate from http://www.comtrust.co.ae/PKIForms/serverenroll.htm.


  2. Click Request Server Certificate link.


  3. File all the fields in the enrolment page and in the last field copy the part that is shown below of the CSR file including the lines that contain the begin and end statements into the field as follow:


  4. Click order at the bottom of the page.
    Note : Customer can generate many keys as he want, BUT he has to make sure to keep the valid one before applying for server certificate to avoid any confusion ( i.e. The information in the downloaded certificate and CSR should be matched )

  1. After approving the certificate from Comtrust, customer will receive an email providing the certificate reference number and the URL to pickup the digital certificate.


  2. Go on http://www.comtrust.co.ae/pkiforms/serverdownload.htm


  3. Put your reference number.


  4. Use Cut & Paste download method.


  5. Click Download.


  6. A text file will be generated and displayed to you on the browser as following.


  1. Copy all the content and pasted in a text file and save this file - this file is your server certificate.


  2. Copy each part between BEGIN & END and save it in separate files the naming of these files could be as follow:

    1. The 1st part (GTE CyberTrust Root) : gteroot.cer
    2. The 2nd part (Comtrust Server Certificate Authority): ctserverca.cer
    3. The 3rd part (Your certificate): abc
    4. The 4th part (Comtrust Root Certificate Authority): ctrootca.cer Note: All parts of the certificates are very important to define the trusted path. Without installing these parts a warning message will appear to the client whenever he accesses the web server.

STEP 3- Configuring the Server Certificate

A. Installing sever certificate (on the web server)

  1. Open Microsoft Management Console.


  2. Right Click on the Default Web Site and choose properties


  3. Click on Directory Security, Click on Edit and then click on Key Manager.


  4. Right Click on the key that you created and Select Install Key.


  5. From the Open dialog, choose the 3rd file (abc.txt) that you have already saved.


  6. Enter the Password.


  7. Click OK for server bindings dialog.


  8. Close the key manager and choose YES when asked to "Commit all Changes?"


  9. Your Key should now be completely installed.
B. Installing the root certifying authority certificates (in the IE browser)

  1. Open Internet Explorer (5.01 or higher a mandatory option)


  2. Click on Tools


  3. Select Internet options


  4. Choose Content from the top menu


  5. Click on Certificate.


  6. Click import


  7. Browse to the root certifying authority certificate that you want to add.


  8. Select X.509 Certificate (*.cer;*.crt) file type.


  9. Add gteroot.cer file.


  10. Click next .


  11. Select Place all certificates into the following store.


  12. Click Browse, and then click Show physical stores.


  13. Expand the Trusted Root Certification Authorities, select Local Computer, and then click OK.


  14. Click Next, and then click Finish.


  15. Replay point 6 to 14 for the other files (ctserverca.cer & ctrootca.cer )


  16. Restart your Web server.


  17. END of all the procedures.

TESTING YOUR SERVER CERTIFICATE.

  1. Open Internet Explorer 5.01 or higher.


  2. Type your URL : https://www.abc.com


  3. Double Click on the lock symbol which is located right down in the browser.


  4. Check certification path, you should see the trusted following path:
    • GTE CyberTrust Root CA
    • Comtrust Server Certificate Authority - GTE Corporation
    • Comtrust Root Certificate Authority
    • www.abc.com : Customer URL

SECURITY ALERTS

A security Alert may pop up when you try to access your secure web page for various reasons:

Alert Suggestion fix
This security certificate was issued by a company you have not chosen to trust. Make sure that you installed the browser certificates correctly (STEP III)-B
The security certificate date is not valid. You have to renew your certificate from Comtrust (Contact Comtrust)
The name on the security certificate does not match the name of the site Make sure that you enter the site by typing the name of your site https://www.abc.com (which is the name you used to generate your certificate) instead of the using IP address of another name.


 

 

For more info on our products please email us at info@comtrust.ae

 

 
Home  |  Quality Policy  |  Privacy Policy  |  Jobs  |  Contact Us
©2004 Comtrust. All Rights Reserved