In both IIS and Apache, you receive a certificate file from the certification authority, which you must configure on the computer. Apache reads the certificate from its source file by using the SSLCACertificateFile directive. However, in IIS, you can configure and manage certificates by using the Directory Security tab of the Web site or folder properties.
You can migrate certificates from Apache to IIS; however, Microsoft recommends that you re-create or obtain a new certificate for IIS.
- Log on to the Web server computer as an administrator.
- Click Start, point to Settings, and then click Control Panel.
- Double-click Administrative Tools, and then double click Internet Services Manager.
- Select the Web site from the list of different served sites in the left pane.
- Right-click the Web site, folder, or file for which you want to configure SSL communication, and then click Properties.
- Click the Directory Security tab.
- Click Edit.
- Click Require secure-channel (SSL) if you want the Web site, folder, or file to require SSL communications.
- Click Require 128-bit encryption to configure 128-bit (instead of 40-bit) encryption support.
- To allow users to connect without supplying their own certificate, click Ignore client certificates.
Alternatively, to allow a user to supply their own certificate, use Accept client certificates.
- To configure client mapping, click Enable client certificate mapping, and then click Edit to map client certificates to users.
If you configure this functionality, you can map client certificates to individual users in Active Directory. You can use this functionality to automatically identify a user according to the certificate they supplied when they access the Web site. You can map users to certificates on a one-to-one basis (one certificate identifies one user) or you can map many certificates to one user (a list of certificates is matched against a specific user according to specific rules. The first valid match becomes the mapping).
- Click OK.
For additional information about securing IIS for a migration from UNIX to Windows, click the article number below to view the article in the Microsoft Knowledge Base:
Article ID: 324069 - Last Review: Nov 21, 2006 - Revision: 1