16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 27: Securing an Extranet Using SSL <strong>and</strong> Certificates 741<br />

3. In the Certificate dialog box, click the Certification Path tab. The certification<br />

path should show no errors in the chain. If errors are shown, you must<br />

download <strong>and</strong> install the certificate authority root on each front-end Web<br />

server following the steps in “Obtaining <strong>and</strong> Installing the Certificate Authority<br />

Root” in the “Troubleshooting” section at the end of this chapter.<br />

4. Click OK to close the Certificate dialog box.<br />

We will now create a certificate trust list (CTL). You must create a certificate<br />

trust list on each front-end Web server.<br />

Note After you create a certificate trust list, put all of your certificate<br />

authorities for client <strong>and</strong> server certificates in this list. Do not create a new<br />

certificate trust list for each certificate authority that you add.<br />

To create a CTL, do the following on each front-end Web server:<br />

1. Open Internet Information Services (IIS) Manager. In the Internet Information<br />

Services management console, exp<strong>and</strong> the tree view, <strong>and</strong> then exp<strong>and</strong> Web<br />

Sites. Right-click Default Web Site, <strong>and</strong> then click Properties.<br />

2. Click the Directory Security tab.<br />

3. In the Secure communications section, click Edit.<br />

4. In the Secure Communications dialog box, select the Enable certificate<br />

trust list check box, <strong>and</strong> then click New.<br />

5. In the Certificate Trust List Wizard, do the following:<br />

a. On the Welcome to the Certificate Trust List Wizard page, click Next.<br />

b. On the Certificates in the CTL page, click Add from Store.<br />

c. In the Select Certificate dialog box, select one or more certificates that<br />

you want to use, <strong>and</strong> then click OK.<br />

d. On the Certificates in the CTL page, click Next.<br />

e. On the Name <strong>and</strong> Description page, type a name in the Friendly name<br />

box, <strong>and</strong> then click Next. For example, you can use a friendly name such<br />

as All CAs as a reminder to place all additional certificate authorities in<br />

this one list.<br />

f. On the Completing the Certificate Trust List Wizard page, click Finish.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!