IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old May 22nd, 2012, 05:57 AM
1DMF's Avatar
1DMF 1DMF is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2009
Posts: 320 1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level) 
Time spent in forums: 3 Days 16 h 57 m 54 sec
Reputation Power: 227
Wildcard SSL / multiple domains

hi,

We need to be able to have multiple sub domains with individual AName DNS records pointing to the same server IP address and SSL encrypt traffic for these sub domains.

I beleive what we need is a wildcard SSL certificate, and IIS will handle the headers for the relevant sub domains.

Our host is unsure if you can have multiple AName records for different subdomains pointing to the same IP address and use a single SSL certificate.

We think that's what a wildcard SSL certificate enables, but wanted to be sure before we purchase something if it doesn't do what we need.

All advice appreciated.

1DMF
__________________
Free MP3 Dance Music Downloads

To err is human; To really balls things up you need Microsoft!

Reply With Quote
  #2  
Old May 22nd, 2012, 06:24 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Jun 2003
Posts: 14,233 Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 4 Weeks 14 h 15 m 56 sec
Reputation Power: 4445
What's an AName record, do you mean a DNS A record?

Anyway, you can certainly have multiple DNS A records pointing to a single IP, unless there is some arbitrary restriction put on DNS by whomever is providing your domain DNS. How that will affect a wildcard SSL certificate, I have no clue. Maybe your cert vendor has some help on this.
__________________
======
Doug G
======
It is a truism of American politics that no man who can win an election deserves to. --Trevanian, from the novel Shibumi

Reply With Quote
  #3  
Old May 22nd, 2012, 07:17 PM
seack79 seack79 is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: surfing the interwebz
Posts: 2,313 seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 20 h 22 m 46 sec
Reputation Power: 1940
Doug is correct about having multiple "A" records point to a single IP; IIS will just use host header data to determine which site to route the http traffic to. Wildcard SSL(s) simply let you purchase a signed SSL certificate for a top-level domain; which will allow you to use that SSL cert for subdomains. For instance, you may purchase a wildcard SSL for domain.com...and use that for mail.domain.com...buyit.domain.com...server1.sub.domain.com...etc.

If you don't need that feature, you could buy a standard SSL cert for a single domain name such as mail.domain.com, or www.mysite.com. I do believe though, either way, you'll have to purchase a unique SSL cert per top level domain.

Reply With Quote
  #4  
Old May 23rd, 2012, 04:09 AM
1DMF's Avatar
1DMF 1DMF is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2009
Posts: 320 1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level)1DMF User rank is Captain (20000 - 30000 Reputation Level) 
Time spent in forums: 3 Days 16 h 57 m 54 sec
Reputation Power: 227
Quote:

What's an AName record, do you mean a DNS A record?
Yes A record not C, sorry mixed up terminology, long day!

I have been told you cannot have separate single domain SSL's bound to same IP and to create additonal IP's means a lot of messing about with routing tables, which the host would prefer not to do.

Quote:
Maybe your cert vendor has some help on this.
Yeah right have you tried having a coherent conversation with GoDaddy or RapidSSL front line support?

Yesterday tried both, GoDaddy spent 10 minutes unable to find my account, so I gave up, I only wanted to ask a few questions about SSL, but the guy on the phone was only interested in finding our account on the system.

So I tried RapidSSL 'live chat', either they put someone who doesn't know what they are talking about on the front line and so they have to look up the answer before they can reply, or they are expected to have too many 'live chats' with too many people open at the same time and so trying to get a response in a reasonable time is impossible, pulling teeth would be quicker and easier! I gave up, closed the chat window and came posted here insead!

Looks like wildcard SSL it is then, now I just need to find out how I create the request and where I apply the sencond level domain bit as we don't actually have a second level domain in IIS as we use sub domain www, with non-www as an additional alias.

Any guidance for doing this on IIS7?

Edit -> Managed to find my customer number with GoDaddy and so got through to someone who was very helpfull, though 'sales' orientated trying to push the 3year deal!

They have also offered to help with cert request generation and SSL install, so should be sorted once the new server is ready for configuration.

Last edited by 1DMF : May 23rd, 2012 at 05:01 AM.

Reply With Quote
  #5  
Old May 23rd, 2012, 06:33 PM
seack79 seack79 is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: surfing the interwebz
Posts: 2,313 seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 20 h 22 m 46 sec
Reputation Power: 1940
Sounds like you've got it sorted out. If you have any questions let us know, but the process for installing certs is fairly straight forward, and from what I recall, when you purchase a cert from a place like GoDaddy or other, they provide you with installation instructions.

Reply With Quote
  #6  
Old November 3rd, 2012, 03:08 PM
jasonmoran jasonmoran is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2012
Posts: 8 jasonmoran User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 17 m 48 sec
Reputation Power: 0
I think you do have the right idea. Wildcards for multiple subdomains, UCC for multiple domains on a single ssl certificate, thus single ip address.

Reply With Quote
  #7  
Old March 4th, 2013, 05:11 AM
DerekHitch DerekHitch is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2013
Posts: 2 DerekHitch User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 17 m 32 sec
Reputation Power: 0
Yes, you can go with Wildcard SSL to secure your multiple sub domains which are hosted on same IP. For more information you can contact to our certificate vendor ClickSSL.com

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Wildcard SSL / multiple domains

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap