<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx</link><description>SelfSSL bug which only allows one website to be SelfSSL'd at a time</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#413765</link><pubDate>Sat, 30 Apr 2005 22:33:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:413765</guid><dc:creator>Paul Carrig</dc:creator><description>I read a post stating there was no workaround for the SelfSSL certificates only working for the last generated certificate (&lt;a rel="nofollow" target="_new" href="http://groups-beta.google.com/group/microsoft.public.inetserver.iis.security/browse_frm/thread/476598ea35f6f09a/5fc0a957c1c0f655?q=selfssl+multiple+known+issue&amp;amp;rnum=1&amp;amp;hl=en#5fc0a957c1c0f655"&gt;http://groups-beta.google.com/group/microsoft.public.inetserver.iis.security/browse_frm/thread/476598ea35f6f09a/5fc0a957c1c0f655?q=selfssl+multiple+known+issue&amp;amp;rnum=1&amp;amp;hl=en#5fc0a957c1c0f655&lt;/a&gt;).  &lt;br&gt;&lt;br&gt;I recently encountered the issue and successfully implemented a workaround. Please let me know if I've missed something obvious here....&lt;br&gt;&lt;br&gt;1 - create certificate for site 1&lt;br&gt;2 - export the certificate to a pfx file (IIS-&amp;gt;directory security-&amp;gt;server certificate wizard)&lt;br&gt;3 - create certificate for site 2.  First site's certificate should no longer work&lt;br&gt;4 - remove certificate from site 1&lt;br&gt;5 - import pfx from step 2 using same wizard&lt;br&gt;&lt;br&gt;SSL on both sites should now work!&lt;br&gt;&lt;br&gt;As I've not seen the workaround posted elsewhere, I'm sharing it the hope of it making it easier for others encountering the same issue....</description></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443686</link><pubDate>Wed, 27 Jul 2005 06:39:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443686</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443688</link><pubDate>Wed, 27 Jul 2005 06:41:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443688</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443690</link><pubDate>Wed, 27 Jul 2005 06:41:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443690</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443692</link><pubDate>Wed, 27 Jul 2005 06:43:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443692</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443694</link><pubDate>Wed, 27 Jul 2005 06:45:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443694</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443696</link><pubDate>Wed, 27 Jul 2005 06:46:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443696</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>MSDE   SelfSSL = asking for trouble</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#443698</link><pubDate>Wed, 27 Jul 2005 06:47:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:443698</guid><dc:creator>Ben Cartwright's Technology Blog</dc:creator><description /></item><item><title>SelfSSL and Site ID</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#449143</link><pubDate>Mon, 08 Aug 2005 23:00:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:449143</guid><dc:creator>David Truxall</dc:creator><description>SelfSSL is a tool found in the IIS 6.0&amp;amp;amp;nbsp;Resource Kit. It allows you to generate SSL certificates...</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#517797</link><pubDate>Thu, 26 Jan 2006 13:11:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:517797</guid><dc:creator>Arjan</dc:creator><description>David,&lt;br&gt;&lt;br&gt;I just downloaded and installed the latest IIS Resource Toolkit with a modify date of 20 januari 2006. But the bug in SelfSSL is still there. Can you tell me where I can find the right version of SelfSSL without the BUG.&lt;br&gt;&lt;br&gt;Kind Regards,&lt;br&gt;Arjan.</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#517823</link><pubDate>Thu, 26 Jan 2006 16:27:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:517823</guid><dc:creator>David Wang</dc:creator><description>Arjan - IIS Resource Toolkit cannot be updated, so this bug in SelfSSL will be there forever.&lt;br&gt;&lt;br&gt;I suggest download the IIS Diagnostics Toolkit which has SelfSSL with updates integrated into the SSL Diagnostics commandline.&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/windowsserver2003/iis/diagnostictools/default.mspx"&gt;http://www.microsoft.com/windowsserver2003/iis/diagnostictools/default.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;//David&lt;br&gt;</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#528581</link><pubDate>Thu, 09 Feb 2006 17:47:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:528581</guid><dc:creator>Mark Minasi</dc:creator><description>Hey David --&lt;br /&gt;&lt;br /&gt;I've found SelfSSL helpful and tell many people about it. &amp;nbsp;I didn't know about the bug or the fix, so here's just a note to say thanks!&lt;br /&gt;&lt;br /&gt;Mark Minasi</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#530417</link><pubDate>Sun, 12 Feb 2006 13:35:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:530417</guid><dc:creator>David.Wang</dc:creator><description>Mark - you're welcome!&lt;br&gt;&lt;br&gt;You won't hit the bug until you try to enable SSL on &amp;gt;1 websites on the IIS server... but that has been fixed and incorporated into SSLDiag 1.1, a part of IIS Diagnostics Toolkit&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/windowsserver2003/iis/diagnostictools/default.mspx"&gt;http://www.microsoft.com/windowsserver2003/iis/diagnostictools/default.mspx&lt;/a&gt; &lt;br&gt;&lt;br&gt;//David</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#540654</link><pubDate>Tue, 28 Feb 2006 19:53:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:540654</guid><dc:creator>Stuart</dc:creator><description>David,&lt;br&gt;&lt;br&gt;We are trying to get a Paml Treo 700W to go on our exchange server, and I need to export the public certificate AND the publisher's certificate to the Palm to get this to work. I can easily get the public and private cert, but would you know how I could get the publisher's cert from a previous SelfSSL run?&lt;br&gt;&lt;br&gt;Perhaps this post that I found will explain what I need more clearly:&lt;br&gt;-------------------------------------------------------------&lt;br&gt;So, there has been a decent amount of rumblings about the new Palm Treo 700w from Verizon Wireless (running Windows Mobile 5.0) - and it's apparent inability to sync with SBS.&lt;br&gt;&lt;br&gt;Sean has a good post outlining how Windows Mobile 5.0 has changed how it handles certificates. &amp;nbsp;The good news is that if you're using self-signed certificates with your SBS, you can get your Treo 700w to sync wirelessly with your Exchange server. &amp;nbsp;As proof, I just did this myself - configured a new 700w for one of our internal users to sync with our SBS, and we're using a self-signed certificate.&lt;br&gt;&lt;br&gt;The trick is to install both your self-signed certificate ( \\&amp;lt;your_sbs\ClientApps\SBSCert ) AND your CA certificate (publishing.company.local - &amp;nbsp;check out &amp;nbsp;\CertEnroll&amp;quot;&amp;gt;\\&amp;lt;your_sbs&amp;gt;\CertEnroll ). &amp;nbsp;Copy these two .cer files to your device using ActiveSync. &amp;nbsp;Then on your device, use FileExplorer to browse to the folder where you copied the certs, and double-click to install each. &amp;nbsp;Voila! &amp;nbsp;You're good to go . . . &lt;br&gt;&lt;br&gt;Now, there has been some talk that WM5 doesn't trust as many Certification Authorities (CAs) as regular ol' Windows. &amp;nbsp;As a result, if you have purchased an SSL cert from a CA, there is a chance that CA may not be trusted by WM5. &amp;nbsp;In that case, you're not going to be able to sync with your Exchange, since you won't have access to the CA cert to manually install it on your WM5 device. &amp;nbsp;However, you could always convert to a self-signed cert and get it to work that way.&lt;br&gt;&lt;br&gt;From:&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://msmvps.com/blogs/cgross/archive/2006/01/19/81475.aspx"&gt;http://msmvps.com/blogs/cgross/archive/2006/01/19/81475.aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;&lt;br&gt;Stu&lt;br&gt;&lt;br&gt;</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#541990</link><pubDate>Thu, 02 Mar 2006 14:01:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:541990</guid><dc:creator>David.Wang</dc:creator><description>Stuart - On the server that ran selfssl, you should find the self-signed certificate used by the server for SSL under &amp;quot;Personal Certificates&amp;quot; for &amp;quot;Local Computer&amp;quot; and the CA cert which signed the self-signed certificate under &amp;quot;Trusted Root&amp;quot; for &amp;quot;Local Computer&amp;quot;.&lt;br&gt;&lt;br&gt;I do not see why one needs to install the self-signed certificate (this belongs to the server and is sent to the client during SSL handshake) onto the mobile device. You only need to install the self-signed certificate into the Trusted Root on the mobile device to allow it to trust the self-signed certificate when it communicates with the server over SSL.&lt;br&gt;&lt;br&gt;//David</description></item><item><title>SelfSSL headaches</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#1630716</link><pubDate>Fri, 09 Feb 2007 03:47:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1630716</guid><dc:creator>Alert: [object]</dc:creator><description>&lt;p&gt;In development and test, you often need to configure a site (or a portion of a site) to run under...&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#2197629</link><pubDate>Fri, 20 Apr 2007 00:39:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2197629</guid><dc:creator>Ilia Broudno</dc:creator><description>&lt;p&gt;I was wondering if you could provide some incite into the nature of that bug.&lt;/p&gt;
&lt;p&gt;We have a very similar sounding problem on production with real certs from trusted providers.&lt;/p&gt;
&lt;p&gt;A second question: I tried using the SSLDiag and it worked - the bug in question did not come up.&lt;/p&gt;
&lt;p&gt;But the certs it creates are only valid for 2 weeks and have the same CN.&lt;/p&gt;
&lt;p&gt;What I was hopping to get are 2 certs with different names valid for a couple of years.&lt;/p&gt;
&lt;p&gt;Is there anything I can do to tweak either what selfSSL or SSLDiag does to get what I want?&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#6764688</link><pubDate>Thu, 13 Dec 2007 23:33:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6764688</guid><dc:creator>Tray_Harrison</dc:creator><description>&lt;p&gt;I have the same question as Ilia. &amp;nbsp;SSL Diag did fix the issues I was having with tryin to run to SelfSSL certs on the same server. &amp;nbsp;The problem is I can't find a way to configure the certificate validity length with SSL diag. &amp;nbsp;I really don't want to have to go in and renew the certs on our test sites every 2 weeks. &amp;nbsp;Is there a way to configure this?&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#7932719</link><pubDate>Thu, 28 Feb 2008 13:09:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7932719</guid><dc:creator>Snorre Garmann</dc:creator><description>&lt;p&gt;You can run ssldiag from commandline the same way as selfssl:&lt;/p&gt;
&lt;p&gt;ssldiag /selfssl /V:365 /N:CN=myserverdnsrecord /S:123455646&lt;/p&gt;
&lt;p&gt;The only feature I cannot figure out how to fix is the /T:&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#8435609</link><pubDate>Mon, 28 Apr 2008 18:55:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8435609</guid><dc:creator>Matthew Bauer</dc:creator><description>&lt;p&gt;Paul - thanks for the fix - it works for me.&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#8744922</link><pubDate>Thu, 17 Jul 2008 23:42:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8744922</guid><dc:creator>Eila</dc:creator><description>&lt;p&gt;How can i retrieve the self signed certificate hash using c/c++&lt;/p&gt;
&lt;p&gt;thanks,&lt;/p&gt;
&lt;p&gt;Eila&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#9351578</link><pubDate>Wed, 21 Jan 2009 01:04:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9351578</guid><dc:creator>Javier</dc:creator><description>&lt;p&gt;Thank you!!!&lt;/p&gt;
&lt;p&gt;Three years later and still helpful.&lt;/p&gt;
</description></item><item><title>re: BUG: SelfSSL allows only one website to have SSL at a time</title><link>http://blogs.msdn.com/david.wang/archive/2005/04/20/SelfSSL-Bug-with-websites.aspx#9921168</link><pubDate>Thu, 12 Nov 2009 04:26:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9921168</guid><dc:creator>David Liu </dc:creator><description>&lt;p&gt;Thanks. This blog helped to resolve my issue with selfSSL.&lt;/p&gt;
</description></item></channel></rss>