[THIN] 2-way browser SSL and CSG

  • From: "Jay Moock" <jmoock@xxxxxxxxxxxxxxxxxxxxxx>
  • To: <thin@xxxxxxxxxxxxx>
  • Date: Tue, 7 Dec 2004 15:48:00 -0500

Trying to test client SSL certs on our CSG server as an alternative to
SafeWord or RSA.  I'm running into a problem with it though.  Currently, I
have both CSG and WI on the same box.  CSG listens on 443 and IIS listens on
444.  If I enable client SSL in IIS then it apparently is trying to get a
cert from CSG (which of course fails).  If I go straight to port 444 on the
CSG/WI box then the client SSL works as it should, but of course then you're
bypassing CSG, sort of.  If I go in to CSG Admin my session does show up,
which doesn't quite make sense, but I'm willing to accept it if it doesn't
create any issues.

Is anyone else doing anything like this?  If I flip the ports (change IIS to
443 and CSG to 444) and have users go straight to 443 am I opening myself up
to any potential problems?

Thanks,
Jay

********************************************************
This Weeks Sponsor Activaeon.com
Reduce licensing costs with activAeon XA and 
get one month completely free.
http://www.activaeon.com
********************************************************** 
Useful Thin Client Computing Links are available at:
http://thin.net/links.cfm
ThinWiki community
http://www.thinwiki.com
***********************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thin.net/citrixlist.cfm

Other related posts: