SharePoint Cafe

All MindsharpBlogs

My Links

Article Categories

Archives

Blog Stats

2007 IT Pro Resources

Mindsharp Instructors

Mindsharp Training

SharePoint Portal Server and SSL (Secure Sockets Layer)

We all know that host headers don't support SSL. And we know that SharePoint is written to support host headers, primarily.  Also, some have taken the phrase “SharePoint doesn't support SSL termination” to mean that SharePoint didn't support bringing in the SSL stream directly to the WFE server. 

So, please let me clear up some confusion.  First, SSL is supported coming all the way into the WFE server in the farm.  In fact, this is the *preferred* method of doing SSL.  What is not preferred is to terminat the SSL stream at an appliance before it reaches the WFE server in the farm.  While we can use the alternate portal access mappings as a workaround, we should strive to bring the SSL stream into the WFE server.

Also, there are two supported scenarios:  1)  create the SSL virtual server with the IP address as All Unassigned and then use a unique port number.  Doing this will enable you to create as many SSL portals in your farm as you wish.  2) Use a separate WFE server for each SSL-enabled portal and leave all the portals on 443.  Either is supported, but obviously, option 1 is less costly to implement.

FrontPage 2003 does work over SSL to Windows SharePoint Services or SharePoint Portal Server 2003.  I'm doing it right now in my office on my medium server farm.  The trick is to ensure that you are not using an IP address on the SSL-enabled virtual server.

I know there are conflicting statements in the SharePoint community today about SSL, but I'm confident that each of my assertions here is correct and can be demonstrated.  Perhaps I should do a Live Meeting on this in the near future.

posted on Friday, February 11, 2005 10:18 AM

Feedback

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 2/17/2005 10:01 AM Bill English

Let me add that SharePoint doesn't like the SSL packet being terminated before the packet arrives at the WFE server. SharePoint would rather have the SSL packet come directly to the WFE server.

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 2/18/2005 12:18 PM Andrew Connell

SharePoint doesn't support virtual servers that are ip-bound... only set to "All Unassigned" it. Is there a published reason why? We just started getting bit by the error "assembly can't be loaded" which the KB article 830342, but it doesn't explain why. This is less secure than ip-bound sites.

The fact you can't have more than one SSL enabled portal on a single server without implementing port numbers is an unreasonable requirement. Short sighted architecture requirements IMHO.

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 2/18/2005 12:31 PM Bill English

I don't think the product teams see this as a feature set. In fact, I'm sure we'll see the ability to have IP-Bound virtual servers in the future. There is no published reason as to why this was their design for this version. But the product team is aware of the problem and they are actively working on it.

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 6/30/2006 4:38 PM Mindy Kelly

I believe that a lot of this has changed since this post.

For example, support for off-box SSL using ISA: http://support.microsoft.com/kb/917064/en-us

and support for SSL with Host Headers in Windows Server 2003 SP1 as explained here: http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032280958&EventCategory=5&culture=en-US&CountryCode=US

Has anyone tried this?

Thanks,
Mindy

# çizgi film 8/16/2008 5:52 PM Çizgi Film

very good

# film izle 8/16/2008 5:53 PM film izle

very good

# gelinlikler 8/16/2008 5:54 PM Gelinlikler

very good

# masaüstü resimleri 8/16/2008 5:57 PM masaüstü resimleri

very good

# mercedes yedek parçaları 8/16/2008 6:00 PM Mercedes Yedek Parçaları

very good

# autocad kursu 8/16/2008 6:02 PM autocad kursu

very good

# müzik dinle 8/16/2008 6:02 PM müzik dinle

very good

# Bay 8/16/2008 6:03 PM Havuz

very good

# yemek tarifleri 8/16/2008 6:04 PM yemek tarifleri

very good

# Bay 8/16/2008 6:05 PM havuz

very good

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 8/16/2008 6:05 PM gaziosmanpaşa

very good

# re: SharePoint Portal Server and SSL (Secure Sockets Layer) 8/16/2008 6:06 PM ilahi dinle

very good

Title  
Name  
Url
CAPTCHA
Protected by Clearscreen.SharpHIPEnter the code you see:
Comments