16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 25: Firewall Considerations for SharePoint Portal Server Deployments 683<br />

5. Verify that Certificate store text box points to the Personal store, <strong>and</strong> that<br />

Place all certificates in the following store is selected.<br />

6. In Completing the Certificate Import Wizard dialog box, click Finish.<br />

7. Click OK to confirm the successful import of the certificate.<br />

Configuring the Listener for Incoming Web Requests to Use a<br />

Certificate<br />

The next steps are to enable the listener for incoming Web requests to listen for<br />

requests on TCP Port 443 (the default SSL port), <strong>and</strong> then to associate the listener<br />

with the certificate you imported in the previous step.<br />

To enable the listener for incoming Web requests to use the certificate, do the<br />

following:<br />

1. Open the ISA Management MMC console, right-click your server, <strong>and</strong> select<br />

Properties.<br />

2. In the Properties dialog box, click the Incoming Web Requests tab.<br />

3. In the Identification section, select Enable SSL listeners. This is a global setting<br />

for all listeners <strong>and</strong> cannot be configured on a per-listener basis.<br />

4. After you’ve selected the check box, a message appears. It says that SSL<br />

requests will be accepted only if each listener is configured with an appropriate<br />

certificate. Click OK.<br />

5. In the Identification section, highlight the listener you would like to configure<br />

<strong>and</strong> click Edit.<br />

6. In the Add/Edit Listeners dialog box, select the Use a server certificate to<br />

authenticate to web clients check box, <strong>and</strong> then click Select.<br />

7. In the Select Certificate dialog box, select the certificate you imported in the<br />

previous section, <strong>and</strong> click OK.<br />

8. In the Add/Edit Listeners dialog box, verify that the external FQDN of the<br />

portal site is listed as the certificate common name in Use a server certificate<br />

to authenticate web clients. In our example, it is external.contoso.com.<br />

Click OK.<br />

A warning appears that says that the changes will be applied only after<br />

the restart of the Web proxy service. You can select either the Save the<br />

changes, but don’t restart the service(s) option <strong>and</strong> then manually restart<br />

the Web proxy service or the Save the changes <strong>and</strong> restart the service(s)<br />

option. If you do not see the certificate in the Select Certificates dialog box,<br />

check the steps undertaken in the previous sections to make sure that the certificate<br />

has been exported correctly <strong>and</strong> that it has been added to the correct<br />

certificate store.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!