Problem with Web Server Certificate when accessing site by IP Address

0
August 16, 2011

We have a specialized IIS 6.0 web server running under Server 2003 that one of our applications uses to transfer information between sites.  The site has a FQDN and the certificates are loaded properly on both the server and what would consider to be the "client" machine.

The "client" uses an automated process to access the web server.  However, due to configuration constraints, the "client" cannot use the FQDN, so it must access the system via the IP address.

The problem is that now the system hangs up on the "There is a problem with this website's security certificate" message.  Since this is an automated process, there is no way to "click" on "Continue to this website (not recommended)" link.

If you do go to the FQDN, the site works fine.  Unfortunately, that is not an option with the custom program we are using.  We must access via IP address only.

I see no way to issue a certificate based on IP address versus FQDN.  Does anyone know a registry setting or other fix that will always ignore the "Continue to this website...." message?

Thanks,

Joe

Comments See all(0)

Add comment
0
August 16, 2011

I recommend fixing the client to accept hostnames instead of IP addresses. However, it is possible to create SSL certs that use an IP address as the common name. I don't think eg. Windows CA will allow that, but I'd imagine you can create a self-signed cert that way.

http://www.globalsign.com/ digital_ce rtificate/ options/pu blic- ip-ad dress.htm http://www.tc.umn.edu/~bra ms006/self sign.html http://msdn.microsoft.com/ en-us/libr ary/ aa1940 55(office. 11).aspx

0
August 16, 2011

Windows CA does allow issuing to IP addresses for the subject name.  What you would probably want to do is to issue the certificate using a Subject Alternative Name (SAN).  Basically you choose one name for the subject for the CSR, then when you submit to the certsrv page you use the Attributes field to include DNS=

www.domain.com&IP=192. 168.0.1&DN S=hostname

Note that you need SAN enabled on the CA for this to work.  Refer to this document for more info:

http://support.microsoft.c om/kb/9313 51

If you are using public certs, consider a Unified Communications Certificate (UCC or UC Cert), sometimes referred to as multi-domain certificate.  Pretty much the same thing - you submit the CSR and then they provide a text field where you can just type in on separate lines what you want to be valid - these can be hostnames, IP addresses, DNS names/aliases, etc.  They cost a bit more but worth it when you need one.  Most commercial CAs will offer these (Verisign, Comodo, GoDaddy, etc.).

0
August 16, 2011

The self cert worked great since our CA does not allow IP's....many thanks!

Related Questions

configuring users in squid

Hi. I have installed Squid proxy server in my Windows 2003 server... i want to add users in the configuration file . For example, if an administrator needs to use internet, i want to configure squid t Read More

Views

326

Votes

0

Answers

6

August 15, 2011

This is the very first question

Hello guys! This is the first post in this site Read More

Views

2k

Votes

4

Answers

2

January 08, 2016

report values not showing up.

I have a crystal report which I pass a DataSet to using VB.NET. The report was working fine, but then I make some changes to the import query and now nothing shows up in the crystal report. Crystal do Read More

Views

1k

Votes

0

Answers

12

September 06, 2005

Event log doesn't overwrite as needed in SP4

Hello All, After upgrading from SP3 to SP4 on several Windows 2000 PRO machines everything looked fine, but from time to time applications can't write to the event log. When I try to view the appl Read More

Views

1k

Votes

0

Answers

9

May 11, 2003

"Failed to self-register XYZ.dll"

Hi there, I wrote a OLE-automation-server DLL in VB4.0. I use Installshield Express to install it as part of my program on the target computers. Now on some computers I get the message "Failed to Read More

Views

8k

Votes

0

Answers

2

November 08, 1998

Please help understand these notes on image processing

Can someone please help me understand these lecture notes... On the right of the page; What does "normalised by one notion of the area of a pixel" mean? On the first formula for A, Is that a Read More

Views

1k

Votes

0

Answers

3

February 05, 2009

Can someone please explain this paragram on the chain rule in image processing

Please see the screenshot, How is 3133030 got from 10103322? Read More

Views

1k

Votes

0

Answers

1

January 05, 2009

AD on 2003

We have created an AD Domain on Windows 2000 Server with no problems. We just created an AD Domain on Windows 2003 and we're getting some weird problems. Both of these domains are behind firewalls Read More

Views

1k

Votes

0

Answers

15

May 11, 2003

ADDT ASP Upload Error " Type mismatch: 'tNG_isFileInsideBaseFolder' "

I am trying to create a simple insert record and upload image function on an ASP page built using Adobe Dreamweaver Developer Toolkit. I have done this many times before with no problem, however, i ha Read More

Views

1k

Votes

0

Answers

0

November 02, 2008

MYSQL Select query with custom ORDER BY

Hi, is it possible to customize the order of the returned rows in mysql? Example: I have a Table with a column "name", now I want to have all entries ordered by name, but I want the entries Read More

Views

1k

Votes

0

Answers

5

July 02, 2010

Folder Redirection in Server 2003

We have a Windows Server 2003 Standard Ed. Is there a way to redirect the users my documents to a folder that has already been created on the server? Read More

Views

1k

Votes

0

Answers

2

July 05, 2007

Partiton magic  version 8.0 having error 1523 while executing batch

I followed the partition magic 8.0 wizard to partition my hard disk while rebooting  I came across this problem  "error 1523 while executing batch" What can I do to solve this prob Read More

Views

1k

Votes

0

Answers

2

May 11, 2003

Please explain this paragraph in image processing (screenshot attached)

Two questions; How is the equation (10.1-15) formed? "are isotropic for rotation increments of 90 degrees and 45 degrees respectively" What does this mean Read More

Views

1k

Votes

0

Answers

7

January 05, 2009

xp_cmdshell with net use

Hi, when I use 'net use \192.168.0.1\c$ password /user:username' at the command prompt, it works fine.  But if i try to use it in sql with " exec master..xp_cmdshell 'net use \19 Read More

Views

999

Votes

0

Answers

5

April 11, 2003

hp ux11

i have a hp ux11 server. and i edited the /etc/resolv.conf to use my win2003 server dns server. That went fine, however, I would like to go the other way and add an entry on my win2003 dns to resolve Read More

Views

627

Votes

0

Answers

3

October 12, 2009

Using an application over a LAN

I have written an application that needs to be used on a LAN.  The application setup wizard takes care of registering everything on a single PC, but how do you go about writing a setup program th Read More

Views

550

Votes

0

Answers

9

August 07, 1998

Need subnet of 12 IPs.

Please, Can someone help me to create a subnet consisting of 12 IP's. Thanks.. Read More

Views

558

Votes

0

Answers

5

April 11, 2003

Drill down in a cross-tabl report

Hello, Would some experts to show me if it is possible to do drill-up or drill-down (or both) in a cross-tab report? I would also like to know if it is possible to control what fields to be displayed/ Read More

Views

446

Votes

0

Answers

0

September 06, 2005

Using RDO, Enterprise V Professional

We would like to use RDO on our project made up of 4 developers. Do we need to have a copy of Enterprise for each developer or is it possible to use Professional for those developers not writing the R Read More

Views

537

Votes

0

Answers

6

January 07, 1998

Can't Edit IIS Metabase.xml

We do this on every windows 2003 server and never had an issue. We cannot edit the IIS Metabase.xml We have stopped IIS and made change click save, no problem but it does not take the new information. Read More

Views

519

Votes

0

Answers

0

July 05, 2007