Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

Generate New Certificate from Existing HTTPS Inspection

$
0
0

Dear All,

Months ago the TMG2010 encountered problems that all HTTPS web sites were not able to access, which returns message "This page cannot be displayed" on client PC.

Checked from TMG logging and found error message 0x8009000a, which related to a certificate problem.

I followed the article below to generate a new certificate for the environment, and finally the problem was resolved.

http://blogs.technet.com/b/isablog/archive/2014/05/28/tmg-https-inspection-is-failing-if-the-target-web-site-is-using-a-cng-certificate.aspx

After that I found the content of the new certificate has a bit difference with the original one generated from TMG ifself.

For example, from Details of the cert, there is fewer descriptions on the Key Usage and some other attributes.

I am wondering, with the existing HTTPS Inspection rule, can I regenerate a new cert from it? Does it affect any problems or applications associate with it (break the trust)?

Or I have to remove the existing HTTPS Inspection and recreate a new one from scratch?

Best Regards

Ben


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>