{"id":1662,"date":"2012-05-18T05:44:49","date_gmt":"2012-05-18T05:44:49","guid":{"rendered":"http:\/\/www.obieta.com\/?p=1662"},"modified":"2012-05-18T05:44:49","modified_gmt":"2012-05-18T05:44:49","slug":"how-to-enable-ssl-on-a-sharepoint-2010-web-application","status":"publish","type":"post","link":"http:\/\/obieta.com\/?p=1662","title":{"rendered":"How to enable SSL on a SharePoint 2010 web application ?"},"content":{"rendered":"<p>Hello my friends, I thought that to start blogging about SharePoint 2010 with very basics, like creation of the site with host address that configured in the DC, enable SSL, enable Kerberos authentication etc.<\/p>\n<p>Being a developer we won\u2019t do these configurations regularly but for admin guys it will be a cake walk J<\/p>\n<p>So, let me start with the details of my machine details. I have two machines, first machine is my Domain Controller with Active Directory, I have installed SQL server 2008 with SP1 + CU2 in this machine.<\/p>\n<p>Second machine has SharePoint 2010 Public Beta, Visual Studio 2010 Beta, Office 2010 Beta, SharePoint designer 2010 Beta.<\/p>\n<p>Both machines are running with Windows Server 2008 R2 and domain name is \u201csowmyan.com\u201d<\/p>\n<p>My first task is create a very basic team site with a URL <a href=\"http:\/\/www.sowmyan.com\">www.sowmyan.com<\/a><\/p>\n<p>1.  First I am going to enter a host entry in the DNS in my Domain Controller(you can do it even after creating the site, but here I am going to add a new host entry with name \u201cwww\u201d, thus the FQDN will be <a href=\"http:\/\/www.sowmyan.com\">www.sowmyan.com<\/a>) and pointing it to the IP address of my SharePoint server.<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image002_6.jpg\"><\/a><\/p>\n<p>2.   Now create a new web application in SharePoint central administration site. While creating the web application specify the port as 80 and host header as <a href=\"http:\/\/www.sowmyan.com\">www.sowmyan.com<\/a>, so while accessing the URL it will be neat and no need to specify port number.<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image004_6.jpg\"><\/a><\/p>\n<p>3.       After creating the web application creating a new site collection at the root.<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image006_6.jpg\"><\/a><\/p>\n<p>4. Once the site got created browse to the site and if there is a loop back check then we can\u2019t successfully login to the site, it may prompt for credentials 3 times and will show blank page. To resolve this issue follow the below KB article :<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/support.microsoft.com\/kb\/896861#letmefixit\">http:\/\/support.microsoft.com\/kb\/896861#letmefixit<\/a><\/p>\n<p>In my environment the issue got resolved after adding the DisableLoopBackCheck entry in the registry settings and a reboot by following the above mentioned KB.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image008_6.jpg\"><\/a><\/p>\n<p>5.       Finally here is our site J<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image010_6.jpg\"><\/a><\/p>\n<p>Now we will see how we can make our site SSL enabled.<\/p>\n<p>We can either configure the web application to use SSL whenever we create new web application or extend the web application. In my scenario since I have already created a web application, I have to do the configuration manually.<\/p>\n<p>For that I am going to do the following.<\/p>\n<p>1.       Go to Alternate Access Mappings: Central Administration \u00e0 Application Management \u00e0 Alternate Access Mapping.<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image012_6.jpg\"><\/a><\/p>\n<p>2.       Select the web application in the right most drop down and click on \u201cAdd Internal URLs\u201d<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image014_6.jpg\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>3.  Add a new URL with HTTPS, here I have added <a href=\"https:\/\/www.sowmyan.com\">https:\/\/www.sowmyan.com<\/a> and select a zone, here I have<\/p>\n<p>selected Intranet zone. Then AAM collection will show the list of URLs with zones.<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image016_6.jpg\"><\/a><\/p>\n<p>4.       Now if we try to browse to the site using https it won\u2019t browse because we have to install the certificate and<\/p>\n<p>configure the website in IIS.<\/p>\n<p>5.       If you are not using DNS host entry then can create a self-signed certificate in IIS 7 or get a certificate from a third<\/p>\n<p>party CA and can bind it with your SharePoint   website. You can refer the following article for getting more<\/p>\n<p>information about it.<\/p>\n<p><a href=\"http:\/\/learn.iis.net\/page.aspx\/144\/how-to-setup-ssl-on-iis-70\/\">http:\/\/learn.iis.net\/page.aspx\/144\/how-to-setup-ssl-on-iis-70\/<\/a><\/p>\n<p><a href=\"http:\/\/blog.mikeobrien.net\/PermaLink,guid,12d9628c-a350-4f7b-a573-9d05429b54e8.aspx\">http:\/\/blog.mikeobrien.net\/PermaLink,guid,12d9628c-a350-4f7b-a573-9d05429b54e8.aspx<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Follow the below TechNet to know more about the \u201cConfiguring Server Certificates in IIS 7\u201d<\/p>\n<p><a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/cc732230%28WS.10%29.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/cc732230(WS.10).aspx<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>But in my scenario since I am using DNS and thus I can\u2019t use self-signed certificate if the host entry is in DNS. If I use a self-signed certificate I will get a Certificate Error:<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image018_6.jpg\"><\/a><\/p>\n<p>For that I have to first add \u201cActive Directory Certificate Service\u201d Role in my Domain Controller. Please follow <a href=\"http:\/\/blogs.msdn.com\/sowmyancs\/archive\/2010\/02\/12\/how-to-enable-active-directory-certificate-service-in-your-windows-server-2008-r2.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">my post<\/a> to know how to add that role in Windows 2008 R2.<\/p>\n<p><span style=\"color: #004080;\">Now we are ready for the configuration of IIS website for SSL.<\/span><\/p>\n<p><span style=\"color: #004080;\">1. Double click on \u201cServer Certificates\u201d and it will open the configuration window.<\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image002_3.jpg\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image002_3.jpg\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">2. On left side it will show the actions, and select \u201cCreate Domain Certificate\u201d. <\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image004%5B1%5D.jpg\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image004%5B1%5D.jpg\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">3. It will open the below window and provide the details, but make sure the certificate&#8217;s &#8220;Common Name&#8221; (CN) <\/span><span style=\"color: #004080;\"> matches the host header in the request, e.g. if the client is making a request to <\/span><a href=\"http:\/\/www.contoso.com\/\"><span style=\"color: #004080;\">www.contoso.com<\/span><\/a><span style=\"color: #004080;\">, then the CN must also be <\/span><a href=\"http:\/\/www.contoso.com\"><span style=\"color: #004080;\">www.contoso.com<\/span><\/a><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image005_2.png\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image005_2.png\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">4. In the next screen you have to provide the Online Certification Authority details. You have to provide it in a specific format like below ( see the red box)<\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image006_2.png\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image006_2.png\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">If you don\u2019t know the certification authority\u2019s name then open the server manager in the DC machine and can find it out under \u201cActive Directory Certificate services\u201d<\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image007_2.png\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image007_2.png\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">You may get some error if you didn\u2019t specify the certificate authority name correctly or didn\u2019t import it to the local machine\u2019s trusted certificates folder (how it is <a href=\"http:\/\/blogs.msdn.com\/sowmyancs\/archive\/2010\/02\/12\/how-to-enable-active-directory-certificate-service-in-your-windows-server-2008-r2.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">done here<\/a> \u2013 last portion)<\/span><\/p>\n<p><span style=\"color: #004080;\">5. Once it completed successfully you can see the certificates and once you click on the newly created certificate you <\/span><\/p>\n<p><span style=\"color: #004080;\"> can see the details.<\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image009_2.jpg\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image009_2.jpg\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">6. Next step is create a new binding with HTTPS and use the certificate that we just created.<\/span><\/p>\n<p><span style=\"color: #004080;\"><strong><span style=\"text-decoration: underline;\">Create an SSL Binding<\/span><\/strong><\/span><\/p>\n<p><span style=\"color: #004080;\">Select a site in the tree view and click Bindings&#8230; in the Actions pane.  This brings up the bindings editor that lets you create, edit, and delete bindings for your website.  Click the Add&#8230; button to add your new SSL binding to the site.<\/span><\/p>\n<p><a href=\"http:\/\/learn.iis.net\/file.axd?i=642\"><span style=\"color: #004080;\"> <\/span><\/a><\/p>\n<p><span style=\"color: #004080;\">New bindings default to http on port 80.  Select https in the Type drop-down. Select the certificate that we created earlier from the SSL Certificate drop-down and click OK.<\/span><\/p>\n<p><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image011_2.png\"><\/a><\/span><\/p>\n<p><span style=\"color: #004080;\">Now you have a new SSL binding on your site and all that remains is to verify that works.     <br \/><\/span><a href=\"http:\/\/learn.iis.net\/file.axd?i=644\"><span style=\"color: #004080;\"> <\/span><\/a><\/p>\n<p><strong><span style=\"text-decoration: underline;\"><span style=\"color: #004080;\">Verify the SSL Binding<\/span><\/span><\/strong><\/p>\n<p><span style=\"color: #004080;\">Look in your site&#8217;s Actions pane for a link that will browse your site over your new HTTPS binding. Click this link to test your new binding.     <br \/><\/span> <a href=\"http:\/\/learn.iis.net\/file.axd?i=74\"><span style=\"color: #004080;\"> <\/span><\/a><\/p>\n<p><span style=\"color: #004080;\">Once it is done just browse to your site with https: If everything is fine then you can see a small lock sign in the address bar and once you click on it will give you the details of your certificate and it will say that the connection to the server is encrypted.<\/span><\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image015_2.jpg\"> <\/a><span style=\"color: #004080;\"><a href=\"http:\/\/blogs.msdn.com\/blogfiles\/sowmyancs\/WindowsLiveWriter\/HowtoenableSSLonaSharePointwebapplicatio_1DAF\/clip_image015_2.jpg\"><\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello my friends, I thought that to start blogging about SharePoint 2010 with very basics, like creation of the site with host address that configured in the DC, enable SSL, enable Kerberos authentication etc. Being a developer we won\u2019t do these configurations regularly but for admin guys it will be a cake walk J So, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[5,1],"tags":[],"_links":{"self":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1662"}],"collection":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1662"}],"version-history":[{"count":0,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1662\/revisions"}],"wp:attachment":[{"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1662"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}