Knowledge Base

How to Troubleshoot SSL in Internet Information Server 4.0

Article ID: 197306

Article Last Modified on 6/23/2005


APPLIES TO


This article was previously published under Q197306
We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site:

SUMMARY

This article describes how to troubleshoot Secure Sockets Layer (SSL) functionality in Microsoft Internet Information Server 4.0. It is divided into the following sections:

MORE INFORMATION

Key Manager

Key Manager is an application that allows for the installation of Server Certificates for the SMTP and WWW services. The following points are important to remember when you use this application:

Microsoft Management Console (MMC)

The properties for a Web site include the following important configuration options:
  1. On the Master Properties sheet of Internet Information Server, click the ISAPI Filters tab. There should be a listing for "sspifilt" with the Status showing a green, upward-pointing arrow and a Priority of "HIGH."
  2. On the Web site Properties tab, the SSL Port should be set to 443.
  3. On the Secure Communications area of the Directory security tab, click to select the "Require secure channel when accessing this resource" check box.
NOTE: If instead of an Edit button being displayed on the Directory Security tab, the button displays "Key Manager," the WWW Service is unaware of a key for SSL. If a key is installed already in Key Manager, see the "Key Manager" section of this document.

Standard SSL Connectivity

If you follow the "Key Manager" and "Microsoft Management Console" sections above, and SSL is not fully functional, see the following:
The HOST header is packaged in the HTTP request, which is in-turn encrypted in the TCP packet. The TCP packet is sent to a specific IP address and the HTTP request is opened by the first Web site bound to that IP. Because many HOST header Web sites may bound to an IP address, unexpected results may occur.

SSL with Client Certificates

If client authentication is enabled, but not fully functional, see the following:
NOTE: Due to known issues with the Service Pack 3 version of the Schannel.dll file, it is highly recommended that you apply Service Pack 4 to any server relying on SSL functionality.

Additional query words: SSL Key Manager Certificate

Keywords: kbhowto KB197306