16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 27: Securing an Extranet Using SSL <strong>and</strong> Certificates 735<br />

You should test that you can access the home page of the portal site from the<br />

browser by using HTTPS with the common name of your server farm. This time, you<br />

should not receive a security alert stating that the certificate name is invalid or does<br />

not match the name of the site when you access the portal site with HTTPS.<br />

To test SSL from the index management server<br />

Before you perform the following steps, verify that the index management<br />

server has access to the front-end Web servers over the port that you have specified<br />

for SSL, such as the default port 443. This is especially important for perimeter network<br />

(also known as DMZ, demilitarized zone, <strong>and</strong> screened subnet) deployments<br />

or segmented-network deployments.<br />

To view your portal site from the index management server, open a new browser<br />

window, <strong>and</strong> type the HTTPS URL for the portal site that is on the primary front-end<br />

Web server or the computer that hosts the parent portal site for shared services.<br />

As before, you can ignore the warning “Revocation information for the security<br />

certificate for this site is not available.” It signifies that your server is unable to connect<br />

to the certificate server to verify that the certificate you just obtained has not<br />

been revoked. To continue, click Yes.<br />

If an authentication prompt appears, type your user name <strong>and</strong> password, <strong>and</strong><br />

then click OK. The home page of the portal site should be displayed.<br />

If you receive a certificate warning that states, “The security certificate was<br />

issued by a company you have chosen not to trust,” you must install the Trust Root<br />

Authority, as described in “Obtaining <strong>and</strong> Installing the Certificate Authority Root” in<br />

the “Troubleshooting” section at the end of this chapter. If you receive any other<br />

warning, review the steps you used to create <strong>and</strong> install the certificate, <strong>and</strong> try again.<br />

To modify settings to update search<br />

We will now modify SharePoint Portal Server settings so that the content from<br />

the SSL-protected portal site is included in the index.<br />

As before, Default Web Site in IIS is our portal site. To include content from the<br />

SSL-protected portal site in the index, first you modify the alternate portal site access<br />

settings to use HTTPS, as follows:<br />

1. On the SharePoint Portal Server Central Administration for server_name page,<br />

in the Portal Site <strong>and</strong> Virtual Server Configuration section, click Configure<br />

alternate portal site URLs for intranet, extranet, <strong>and</strong> custom access.<br />

2. On the Configure Alternate Portal Access Settings page, rest the pointer on<br />

Default Web Site, click the arrow that appears, <strong>and</strong> then click Edit on the<br />

menu that appears.<br />

3. On the Change Alternate Access Setting page, in the Default URL box, change<br />

http to https, <strong>and</strong> then click OK.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!