Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


April 16, 2001

Securing Web Communications with SSL


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

In previous columns, I've talked about using Windows 2000’s Certificate Services to build a public key infrastructure (PKI) to provide secure network communications. This week, I explain how to use PKI, Microsoft IIS 5.0, and Secure Sockets Layer (SSL) to secure your Web site’s sensitive content.

SSL is a security protocol that Netscape Communications developed to secure traffic on the Internet. When a client connects to a Web site that uses SSL, the Web server sends a copy of its digital certificate to the client’s browser. This certificate, which includes the Web site’s public key, verifies the server’s identity. The client’s Web browser generates a master key that will be used to encrypt data transmissions between the browser and the server, and it then encrypts a copy with the Web server’s public key and sends the copy of the encrypted master key to the Web server. The Web server and client browser continue to encrypt the traffic between them using keys derived from the master key. With SSL configured on the Web server, this process occurs transparently to the user.

Using the Web Site Certificate Wizard to Request a Certificate
Before you can enable SSL for a Web site that uses IIS 5.0, you must first get a digital certificate from a valid Certificate Authority (CA). (Although for this article I assume that you have installed Win2K's Certificate Services and created your own CA hierarchy, a process I explain in Configuring Your Own CA, the process I outline here is similar if you use any CA.)

You use the Web Site Certificate Wizard to request a certificate for an IIS 5.0 Web site.

Open the Internet Service Manager (ISM) from the Web server’s Administrative Tools group, right-click the Web site, and choose Properties. Next, click the Directory Security tab, and, under Secure Communications, choose Server Certificate to launch the wizard. The Web Site Certificate Wizard lets you assign an existing certificate, restore a certificate from a backup, or create a new certificate. If you choose Create a new request and you have access to an online enterprise CA, the wizard handles the request and walks you through the process.

Requesting a Certificate from the Certificate Services Web Pages
You can also access the CA's Certificate Services Web pages to request a certificate. From the Web server, point your browser to http://CA_Server Name/certsrv. Once connected, choose Request a Certificate and, on the Request Type page that appears, choose Advanced Options. Click Next. On the Advanced Certificate Request page, you can either submit a request file that you generated using the Web Site Certificate Wizard or use a form to submit a new request. To submit a new request, fill out the appropriate information in the form, and, under Key Options, choose Use Local Machine Store. After the request processes, you'll have the option to install the certificate, which adds it to your local certificate store. To assign the certificate to your Web site, open the Web Site Certificate Wizard and choose Assign an Existing Certificate.

Enabling SSL
Once you have installed a certificate on your Web server, you can enable SSL. You can enable SSL for your entire Web site, but you should consider enabling it only for the directories that contain sensitive information because encryption and decryption consume additional processor resources for both the client and server. To enable SSL on a directory, open ISM, right-click the directory you want to secure, and choose Properties. Next, click the Directory Security tab and, under Secure communications, choose Edit. Finally, on the Secure Communications dialog box, choose Require secure channel to enable SSL.

When enabled, SSL secures communications between your server and a client’s browser whenever someone connects to your site's protected areas. However, be aware that if you use your own CA to issue the certificate for your Web server, clients will see a dialog box warning them that an untrusted CA issued the certificate. To prevent this dialog box from appearing, users can add your CA to the list of trusted sites in Internet Explorer's (IE's) Security settings.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. Put simply, Windows 7 is not responsible for any battery life issues ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Deep Dive into Windows Server 2008 R2 presented by John Savill

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement