SSL certificate management on Systems Engineering managed servers

SSL certificate management on Systems Engineering managed servers

Background

While SE can provide assistance to customers with the installation of SSL certificates for web and/or application servers, it is the responsibility of the customer to purchase, request, install, and renew their SSL certificates. SE considers SSL certificate management to be within the realm of application administration not operating system maintenance. Customers that want assistance from SE with the installation of SSL certificates for web and/or application servers should email their primary system administrator and copy the associated OS support team.

SSL certificate installation instructions

Complete documentation regarding purchasing and using certificates can be found at https://it.wisc.edu/about/division-of-information-technology/enterprise-information-security-services/cybersecurity/security-tools-software/server-certificates/. Below is a summary of the process:

NOTE: Items in bold are done from the application/web server, other items are done from the application administrator's workstation.

Notes

Help and Documentation

General

  • While there isn't an official turnaround time for certificate requests, budget a few business days between a certificate request and the issuing of a certificate.
  • When filling out the certificate request form, it is recommended that you use a service-specific mailing list as the email address of the technical contact.
  • Creating meetings in your calendar is one way of notifying yourself about certificate expiration dates.
  • A web server that serves pages using HTTPS must be hosted on a web server with a dedicated IP address. At present, most web browsers and web servers do not support virtual hosting with SSL protected web sites.

UNIX, OpenSSL-based applications (e.g., Apache httpd, Apache Tomcat)

  • When using Apache httpd (or any OpenSSL-based application), you have the option to protect your private key with a passphrase. Protecting your key with a passphrase is not recommended. If you do this, your application will not start automatically - a person will need to enter this passphrase every time an application using the certificate is started. SE can show you other ways of protecting a key without the need for a passphrase.

Windows (IIS, Microsoft SQL Server)

  • When installing a certificate in Windows, marking the private key as exportable allows you to copy the SSL certificate to another server in the future.
  • Error message when you try to install a certificate by using IIS 7.0 Manager: "Cannot find the certificate request associated with this certificate file"
    http://support.microsoft.com/kb/959216
  • Windows users not using IIS may find the DigiCert Certificate Utility for Windows useful for CSR creation and certificate installation:
    https://www.digicert.com/util/


KeywordsSSL certificate management renew renewal expiration expiring incommon cert certs ssl   Doc ID14455
OwnerSteve T.GroupSystems Engineering
Created2010-06-13 19:00:00Updated2021-02-22 08:39:12
SitesSystems Engineering
Feedback  0   0