Microsoft KB Archive/313299

= How to load balance a Web server farm by using one SSL certificate in Internet Information Services version 6.0 and in Internet Information Services 5.0 =

Article ID: 313299

Article Last Modified on 12/3/2007

-

APPLIES TO


 * Microsoft Internet Information Services 6.0
 * Microsoft Internet Information Services 5.0

-



This article was previously published under Q313299



IN THIS TASK

 * INTRODUCTION
 * How to obtain and install a Web server certificate for the first Web server
 * How to install a signed certificate
 * How to export a private key
 * How to import a certificate to the Personal store
 * How to assign the imported certificate to the Web site



INTRODUCTION
This article describes how to set up Web server farms that contain multiple Microsoft Internet Information Services (IIS) Web servers with the same certificate. When you do this, communications between the Web client computers and servers are secured by Secure Sockets Layer (SSL).

back to the top



How to obtain and install a Web server certificate for the first Web server
To perform load balancing of a Web server farm with a single certificate in Microsoft Integrated Information Server (IIS) 5.0 or in Microsoft Integrated Information Server (IIS) version 6.0, follow these steps:
 * 1) Click Start, point to Programs, point to Administrative Tools, and then click Internet Services Manager or Internet Information Services (IIS) Manager.
 * 2) Expand your server name, right-click the Web site, and then click Properties.
 * 3) Click the Directory Security tab.
 * 4) Click Server Certificate.
 * 5) After the Web Server Certificate Wizard starts, click Next.
 * 6) On the Server Certificate page, click the method that you want to use to assign the site a new certificate, for example, click Create a new certificate.
 * 7) On the Delayed or Immediate Request page, click one of the following options, and then click Next.
 * 8) * If you have an online certificate server in your organization, click Send the request immediately to the online certification authority.
 * 9) * If you have to send the request to a third-party provider or to a certification authority (CA) that is off the network, click Prepare the request now, but send it later. The procedure that is described in this article assumes that you click this option.
 * 10) On the Name and Security Settings page, type a name for the new certificate in the Name box, click 1024 in the Bit length box, and then click Next.
 * 11) On the Organization Information page, type the name of your organization in the Organization box, type the name of your organizational unit in the Organizational Unit box, and then click Next.
 * 12) On the Your Site's Common Name page, type the fully qualified domain name (FQDN) that users use to access the site in the Common name box, and then click Next.

Note If you use the server on the intranet only, you can use the NetBIOS name of the server.
 * 1) On the Geographic Information or Geographical Information page, click your country in the Country/Region box, type the full name of your state or your province in the State/province box, type the full name of your city or your locality in the City/locality box, and then click Next.
 * 2) On the Certificate Request File Name page, type the complete path of the certificate request file or use the default certificate request, and then click Next.
 * 3) On the Request File Summary page, review the settings, and then click Next.
 * 4) On the Completing the Web Server Certificate Wizard page, click Finish.
 * 5) Retrieve the certificate request, and then either e-mail the request or use a floppy disk to deliver the request to your CA provider. The provider returns the signed certificate to you.
 * 6) Install the certificate on the Web server.

back to the top

How to install a signed certificate

 * 1) Obtain and install a Web server certificate for the first Web server.
 * 2) Click Start, point to Programs, point to Administrative Tools, and then click Internet Services Manager or Internet Information Services (IIS) Manager.
 * 3) Expand your server name, right-click the Web site, and then click Properties.
 * 4) On the Directory Security tab, click Server Certificate.
 * 5) After the Web Server Certificate Wizard starts, click Next.
 * 6) On the Pending Certificate Request page, click Process the pending request and install the certificate, and then click Next.
 * 7) On the Process a Pending Request page, type the full path of the certificate in the Path and file name box, and then click Next.
 * 8) On the Certificate Summary page, review the settings in the certificate, and then click Next.
 * 9) On the Completing the Web Server Certificate Wizard page, click Finish.
 * 10) Click OK.
 * 11) Stop and restart the Web site.

back to the top

How to export a private key
To export the key that you installed on the first Web server, follow these steps. This key is imported to other Web servers in the farm.
 * 1) Click Start, click Run, type mmc, and then click OK.
 * 2) On the Console menu in IIS 5 or the File menu in IIS 6, click Add/Remove snap-in or Add/Remove Snap-in, and then click Add.
 * 3) Click Certificates, and then click Add.
 * 4) Click Computer account, and then click Next.
 * 5) Click Local computer (the computer this console is running on), and then click Finish.
 * 6) Click Close, and then click OK.
 * 7) In the left pane, expand Certificates, and then expand Personal.
 * 8) Click Certificates under Personal.
 * 9) Right-click the Web server certificate in the right pane, point to All Tasks, and then click Export.
 * 10) After the Certificate Export Wizard starts, click Next.
 * 11) On the Export Private Key page, click Yes, export the private key, and then click Next.
 * 12) On the Export File Format page, click to select the Include all certificates in the certification path if possible check box, and then click Next.

Note If you want to enable strong protection in IIS 5 for Microsoft Internet Explorer 5.0 or for Microsoft Windows NT 4.0 service packs, click to select the Enable strong protection check box. If you do not want to turn on strong protection in IIS 6, click to clear the Enable strong protection check box.
 * 1) On the Password page, type a password in the Password box, retype the password in the Confirm password box, and then click Next.
 * 2) On the File to Export page, type the file name of the exported certificate in the File name box, and then click Next.
 * 3) On the Completing the Certificate Export Wizard page, click Finish.

back to the top

How to import a certificate to the Personal store
After the certificate has been exported, copy the certificate to a location on another Web server in the load balanced server farm. You must import the certificate to the computer's Personal certificate store. To import the certificate to the computer's Personal certificate store, follow these steps:
 * 1) Click Start, click Run, type mmc, and then click OK.
 * 2) On the Console menu in IIS 5 or the File menu in IIS 6, click Add/Remove snap-in or Add/Remove Snap-in, and then click Add.
 * 3) Click Certificates, and then click Add.
 * 4) Click Computer account, and then click Next.
 * 5) Click Local computer (the computer this console is running on), and then click Finish.
 * 6) Click Close, and then click OK.
 * 7) In the left pane, expand Certificates, and then expand Personal.
 * 8) Right-click Certificates under Personal, point to All Tasks, and then click Import.
 * 9) When the Certificate Import Wizard starts, click Next.
 * 10) On the File to Import page, type the complete path of the file in the File name box or click Browse to locate the file, and then click Next.
 * 11) On the Password page, type the password that is assigned to the certificate in the Password box, and then click Next.
 * 12) On the Certificate Store page, click Place all certificates in the following store, confirm that Personal is selected as the store, and then click Next.
 * 13) On the Completing the Certificate Import Wizard page, click Finish.
 * 14) Click OK.

back to the top

How to assign the imported certificate to the Web site
To assign the imported certificate to the Web site, follow these steps:
 * 1) Click Start, point to Programs, point to Administrative Tools, and then click Internet Services Manager or Internet Information Services (IIS) Manager.
 * 2) Expand your server name, right-click the Web site, and then click Properties.
 * 3) On the Directory Security tab, click Server Certificate.
 * 4) After the Web Server Certificate Wizard starts, click Next.
 * 5) On the Server Certificate page, click Assign an existing certificate, and then click Next.
 * 6) On the Available Certificates page, click the certificate that you imported, and then click Next.
 * 7) On the Certificate Summary page, review the settings, and then click Next.
 * 8) On the Completing the Web Server Certificate Wizard page, click Finish.
 * 9) Click OK.

Repeat the import and the certificate assignment procedures on any other server in the Web server farm.

back to the top

Keywords: kbhowto kbenv KB313299

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.