PDA

View Full Version : Https Sites (SSL)



JCruyff
11-01-2001, 01:14 PM
I am having problems connecting PC's on my network to Https sites. I believe the administrator before me has restricted them as it seems to depend on the user logged in who has access. We are running Windows Policies but I cannot find a template file (*.adm) that relates to this. These users have access to all protocols on the Firewall and IE5 settings are all correct (128bit security etc). We use a proxy server and our ISP supports SSL.

Any ideas on registry keys that may effect access to these sites or indeed a policy file that can be downloaded?

Mosaic1
11-01-2001, 06:52 PM
<a target="_blank" href=http://support.microsoft.com/directory/article.asp?ID=KB;EN-US;q182569>http://support.microsoft.com/directory/article.asp?ID=KB;EN-US;q182569</a>

Have a look at the key described in the article and see if you find any diferences.

JCruyff
11-02-2001, 10:14 AM
Unfortunately this did not work. The address appears as a HTTPS address and has Done in the bottom left hand corner of the IE5 browser window but the screen is blank, or we get a page not found standard error.

Any more ideas? HELP!!!!

Smitty
11-02-2001, 11:59 AM
Jcruyff

While you wait for Mosaic1 to get back to you:

This filtered seatch on Google returns 245 hits restricted to Microsoft.com only..

ssl registry "explorer" site:microsoft.com

Maybe something will help..

GL

Smitty

Mosaic1
11-02-2001, 06:26 PM
That sounds more like a software problem than a restriction. Exactly what, I am not sure.
Have a look at this article regarding https
<a target="_blank" href=http://support.microsoft.com/support/kb/ARTICLES/Q188/7/73.asp>http://support.microsoft.com/support/kb/ARTICLES/Q188/7/73.asp</a>

Quote:
When you attempt to view a Web page using Internet Explorer, you may receive the following error message:

Cannot open Internet site https://<Web address>. A connection to the server could not be established.



CAUSE
This behavior can occur for any of the following reasons:

You have mismatched Windows Sockets dynamic-link library (DLL) files. For example, this behavior can occur if you install the Windows Sockets (Winsock) 2.0 update for Windows 95 on a Windows 95-based computer, upgrade to Windows 98, and then attempt to revert to your previous version of Winsock by running the Ws2bakup.bat file.


Your Dial-Up Networking (DUN) or Internet settings are incorrect.
or maybe this one
<a target="_blank" href=http://support.microsoft.com/support/kb/articles/Q239/4/49.ASP>http://support.microsoft.com/support/kb/articles/Q239/4/49.ASP</a>

IIS 5.0:
The page cannot be displayed.
Cannot find server or DNS Error.



CAUSE
This is by design. Unlike non-SGC certificates, which allow the user to accept a situation where the name used in the certificate does not match the name used in the URL accessing the site, SGC certificates require that the names match. If the names do not match, the error message is returned instead of a dialog box.



WORKAROUND
To work around this issue, do the following:

Get a SGC certificate, which has a common name that matches the DNS name of the Web site.


Make a hosts file entry on the client computer to ensure that the common name is used.

JCruyff
11-07-2001, 04:13 PM
Checked all these settings as suggested but still no luck. ???????????