Home | SSL Certificate Products | FAQ | Support | Resellers | International | About Us | News | Contact Us |
Copy your web server certificate into a text editor such as
notepad and save as yourdomain.cer.
Installing your web server certificate:
1. Start IIS and right click Default Web Site and select Properties
from the menu.
2. When the Properties appear, click on the Directory Security
tab.
3. Click on Server Certificate and follow the on screen wizard:
Ensure that you select Process the pending request
and install the certificate. Click Next.
Locate the yourdomain.cer file when prompted to
locate your webserver certificate. Click Next.
Review the summary screen and ensure that you are
processing the correct certificate. Click Next.
Click Next on the confirmation screen.
4. Make sure that you have assigned Port 443 as the SSL port for https for your site. To do this, right click Properties for your website and make sure that 443 has been entered into the SSL port box:

Now activate SSL for your Exchange Virtual Directory:
1. Using the Internet Services Manager, open the properties
for the Exchange virtual directory.
2. Select the Directory Security tab and the click on the Edit
button in the Secure Communication section.
3. In the Secure Communications dialogue box, check the box Require
Secure Channel (SSL), you could also check the box Require 128-bit encryption,
if you do check the 128-bit checkbox, any browsers that do not support 128-bit
encryption will be unable to connect to OWA.
Now when users enter http://www.yourdomain.com/exchange, they will receive an
"HTTP 403.4 - Forbidden: SSL required Internet Information Services"
error message, because we have configured OWA to require SSL. SSL uses the HTTPS
protocol, so users would need to enter the url as https://www.yourdomain.com/exchange.
More information to force SSL only connections:
Microsoft has written an article about forcing the use of SSL with OWA: http://support.microsoft.com/search/preview.aspx?scid=kb;en-us;Q279681
One final step that you may need to take is to ensure
that your Firewall / router is configured to allow HTTPS (port 443 by default)
to pass through.
Certificate Snap-in consoles (MMC) are not preconfigured. You will need to configure the Snap-in before you can perform any Export/Import functionality. To configure your Snap-in, follow the steps below. The system administrator will have to create the console.
Warning: If you lose the password, you must purchase another
certificate.
Save the file to a disk or other form of media. You should choose a form
of media that you would be able to recover if your system has to be rebuilt.
Save this file in a secure location.
*** Microsoft has an alert addressing a problem with exporting and importing
certificates.***
Service Pack 2 is intended to correct this problem. There is also a hotfix that
may be obtained from Microsoft that must be run prior to exporting and importing
your certificate. Please go to the following URL for more information or email
us at support@rapidssl.com.
http://support.microsoft.com/support/kb/articles/Q261/6/55.ASP