Posts

Showing posts from December, 2012

General steps and resources for setting up SSL Certificates and PKI infrastructure

Project: Set up a development web server environment which requires SSL and accepts client certificates.  The client certificates may come from a CA that is not immediately contactable, because the development environment is firewalled out of the CA network. Using IIS7.5 on a Windows 7 Ultimate workstation. General steps: 1) Install an SSL certificate for your web server to enable SSL.     a. I had a Certificate Authority server set up in my development environment.            Certificate Authority services come with Windows Server 2003 and above. You just need to enable the feature.      b. I requested a domain certificate from IIS7.5 Server Certificates feature which is located at the web server level of the IIS Managment Console.     c. Then I enabled SSL on IIS 7.5 at the web site level. http://www.iis.net/learn/manage/configuring-security/how-to-set-up-ssl-on-iis 2) Your client workstation must trust the CA.       a) Go to the CA and get a copy of the CAs public