{"id":2382,"date":"2014-02-28T05:00:00","date_gmt":"2014-02-28T08:00:00","guid":{"rendered":"http:\/\/www.radians.com.ar\/blog\/?p=2382"},"modified":"2014-02-27T17:10:33","modified_gmt":"2014-02-27T20:10:33","slug":"windows-server-como-implementar-un-caroot-y-un-certificado-web-parte-2-howto","status":"publish","type":"post","link":"https:\/\/www.radians.com.ar\/blog\/?p=2382","title":{"rendered":"Windows Server: Como Implementar un CAroot y un certificado Web &ndash; Parte 2 {HowTo}"},"content":{"rendered":"<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/fa6c0be60eaa_F02F\/popup_ssl.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; float: left; padding-top: 0px; padding-left: 0px; margin: 5px; border-left: 0px; display: inline; padding-right: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/fa6c0be60eaa_F02F\/popup_ssl_thumb.jpg\" width=\"240\" align=\"left\" height=\"207\" \/><\/a>Hoy vemos la ultima parte de la nota de ayer: <a href=\"http:\/\/www.radians.com.ar\/blog\/?p=2379\">Windows Server: Como Implementar un CAroot y un certificado Web \u2013 Parte 1 {HowTo}<\/a>; estos son los pasos finales para terminar con nuestra implementaci\u00f3n. Primero veremos como esta nuestro request en el servidor <strong><em>Certificate Autorithy<\/em><\/strong>, para ello hacemos lo siguiente vamos a <a href=\"http:\/\/localhost\/certsrv\">http:\/\/localhost\/certsrv<\/a> y seleccionamos <strong><em>request a certificate<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_21.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_21_thumb.jpg\" width=\"540\" height=\"387\" \/><\/a><\/p>\n<p align=\"justify\">Seleccionamos <strong><em>Advanced Certificate Request<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_22.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_22_thumb.jpg\" width=\"540\" height=\"441\" \/><\/a><\/p>\n<p align=\"justify\">Hacemos un clic en <strong><em>Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_23.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_23_thumb.jpg\" width=\"540\" height=\"393\" \/><\/a><\/p>\n<p align=\"justify\">En este punto necesitamos copiar el contenido de nuestro archivo <strong><em>cert.txt <\/em><\/strong>que creamos anteriormente. Abrimos un notepad, copiamos el contenido y hacemos un clic en <strong><em>Submit<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_24.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_24_thumb.jpg\" width=\"540\" height=\"361\" \/><\/a><\/p>\n<p align=\"justify\">Hacemos un check en <strong><em>Base 64 encoded<\/em><\/strong> y seleccionamos <strong><em>Download Certificate<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_25.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_25_thumb.jpg\" width=\"540\" height=\"360\" \/><\/a><\/p>\n<p align=\"justify\">Hacemos un clic en <strong><em>Save<\/em><\/strong> y ahora podemos cerrar el <strong><em>Internet Explorer<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_26.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte3HOWTO_BB3B\/SSL_26_thumb.jpg\" width=\"540\" height=\"353\" \/><\/a><\/p>\n<p align=\"justify\">El pr\u00f3ximo paso es realizar el&#160; <strong><em>Append <\/em><\/strong>de nuestro certificado al&#160; <strong><em>Default Website<\/em><\/strong>.<\/p>\n<p align=\"justify\">Abrimos la consola del <strong><em>Internet Information Services Manager<\/em><\/strong>, y seleccionamos las propiedades de <strong><em>Websites<\/em><\/strong>, dentro de la solapa <strong><em>Directory Security<\/em><\/strong>, en la parte de <strong><em>Secure Communications<\/em><\/strong>, selecionamos <strong><em>Server Certificate<\/em><\/strong>, y se ejecutara el <strong><em>Web Server Certificate Wizard<\/em><\/strong>.<\/p>\n<p align=\"justify\">Hacemos un clic en <strong><em>Next<\/em><\/strong>, y seleccionamos <strong><em>Process the pending request and install the certificate<\/em><\/strong>. Hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_27.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_27_thumb.jpg\" width=\"540\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\">Ahora seleccionamos el archivo <strong><em>certnew.cer<\/em><\/strong> que hab\u00edamos creado con anterioridad, y hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_28.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_28_thumb.jpg\" width=\"540\" height=\"411\" \/><\/a><\/p>\n<p align=\"justify\">Como no queremos cambiar el puerto de comunicacion SSL, dejamos el default 443, y hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_29.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_29_thumb.jpg\" width=\"540\" height=\"401\" \/><\/a><\/p>\n<p align=\"justify\">Ahora veremos un resumen de las tareas que realizaremos, chequeamos si esta todo bien y hacemos un clic en <strong><em>Next<\/em><\/strong> y luego en <strong><em>Finish<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_30.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_30_thumb.jpg\" width=\"540\" height=\"401\" \/><\/a><\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_31.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_31_thumb.jpg\" width=\"540\" height=\"404\" \/><\/a><\/p>\n<h4 align=\"justify\">Enable SSL on the Default Website.<\/h4>\n<p align=\"justify\">En este punto ya tenemos instalado el <strong><em>root CA certificate<\/em><\/strong>, creamos el request del certificado, tomamos ese request de nuestro CA y lo instalamos en el servidos. El pr\u00f3ximo paso es habilitar SSL al sitio web.<\/p>\n<p align=\"justify\">Para hacer esto, sobre la consola <strong><em>IIS Manager<\/em><\/strong>, seleccionamos las propiedades de <strong><em>Default Website<\/em><\/strong>, dentro de la solapa <strong><em>Directory Security<\/em><\/strong>, en la secci\u00f3n <strong><em>Secure Communications<\/em><\/strong>, hacemos un clic en <strong><em>Edit<\/em><\/strong>.<\/p>\n<p align=\"justify\">Seleccionamos el checkbox <strong><em>Require secure channel (SSL)<\/em><\/strong>, y el checkbox <strong><em>Require 128-bit encryption<\/em><\/strong> como vemos en el screenshoot, y hacemos un clic en el bot\u00f3n <strong><em>OK<\/em><\/strong> dos veces.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_32.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_32_thumb.jpg\" width=\"540\" height=\"484\" \/><\/a><\/p>\n<h4 align=\"justify\">Testeamos nuestro trabajo y vemos como funciona OWA con SSL<\/h4>\n<p align=\"justify\">Ya hemos hecho todo el trabajo, ahora probaremos que todo funcione correctamente. Abrimos un <strong><em>Internet Explorer<\/em><\/strong> y abrimos el OWA con la direcci\u00f3n antigua <a href=\"http:\/\/srve2003.radians.com.ar\/exchange\"><strong><\/strong><\/a><a href=\"http:\/\/srve2003.radians.com.ar\/exchange\">Http:\/\/srve2003.radians.com.ar\/exchange<\/a>, podemos ver el siguiente mensaje:<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_33.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_33_thumb.jpg\" width=\"540\" height=\"364\" \/><\/a><\/p>\n<p align=\"justify\">El error nos indique que debemos utilizar <strong><em>Secure Sockets Layer (SSL) <\/em><\/strong>entonces lo intentamos nuevamente usando <a href=\"Http:\/\/srve2003.radians.com.ar\/exchange\"><strong>Http:\/\/srve2003.radians.com.ar\/exchange<\/strong><\/a> y vemos que nos muestra el siguiente mensaje, el cual aceptamos haciendo un clic en el bot\u00f3n <strong><em>Yes<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_34.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_34_thumb.jpg\" width=\"540\" height=\"417\" \/><\/a><\/p>\n<p align=\"justify\">Aparecer\u00e1 una ventana donde nos pide las credenciales (user y password), completamos los campos y hacemos un clic en el bot\u00f3n <strong><em>OK<\/em><\/strong>.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_35.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_35_thumb.jpg\" width=\"540\" height=\"344\" \/><\/a><\/p>\n<p align=\"justify\">Y, ya esta todo listo. Tenemos nuestro OWA a trav\u00e9s de certificado SSL.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_36.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"www.radians.com.ar \u00a9 2014\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; margin: 5px; border-top-width: 0px\" border=\"0\" alt=\"www.radians.com.ar \u00a9 2014\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/ImplementandounCertificadoSSLParte4Appen_9A14\/SSL_36_thumb.jpg\" width=\"540\" height=\"395\" \/><\/a><\/p>\n<p align=\"justify\">Espero que les sea de utilidad. Cualquier cosa consulten.<\/p>\n<p align=\"justify\">Saludos a todos, Roberto Di Lello.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hoy vemos la ultima parte de la nota de ayer: Windows Server: Como Implementar un&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4291,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12,11,158],"tags":[266,194,195,243],"class_list":["post-2382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-2003-r2","category-2008-r2","category-windows-server-2012","tag-certificados","tag-windows-server-2003-r2","tag-windows-server-2008-r2","tag-windows-server-2012-r2"],"_links":{"self":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2382"}],"version-history":[{"count":1,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2382\/revisions"}],"predecessor-version":[{"id":2383,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2382\/revisions\/2383"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/media\/4291"}],"wp:attachment":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}