Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IIS 6, OWA 2003

Status
Not open for further replies.
Mar 25, 2004
2
US
I found a similar thread, I have my own certificate that I created for the SSL connection to my OWA server. I have some users that the page loads quickly and others that take 30 seconds or more. The difference is Im running IIS 6. KB 295070 applies to this problem on IIS 5 but not 6.

I would prefer not to have to install the certificate locally like was suggested in other threads.

 
(I'll be redundant & re-post my answer on this thread)

We had trouble with Outlook Web Access because of using a self-generated certificate. Internet Explorer insists on verifying the cert back to the root Certificate Authority, so when we took our root CA offline (the subordinate CA was still online), the dialogue wouldn't open until the root CA check timed out. The cert still worked fine, we just had an annoying lag before it timed out.

You can check to see if this is your issue by using Netscape to log in; it doesn't do the hierarchy check that IE does, so there's no lag while waiting for the timeout. I'm pretty sure there's a Microsoft KB article on this somewhere, but it escapes me now.

If this is the problem, you'll need to make sure your web server can talk to your root CA. If you get the same lag time using Netscape, you can probably ignore this issue.

One more note-- We had this issue over a year ago; I don't know if the current IE version still has the same "bug" as the version we were dealing with then.
 
I had this problem with IIS 5 on Windows 2000 Server. To fix it, I had to change my distribution points in the Certificate Authority. I unchecked LDAP as an option, leaving only HTML. Then I had to create a new certificate, since one cannot be changed once it is created. I revoked the first one and created a new one. Now my page loads in a few seconds.

This took me a couple of weeks to figure out. There does not seem to be much specific information on this problem.
 
Do you know of a reference that tells me (or can you post) how you "unchecked LDAP as an option, leaving only HTML" in your CA settings? I can't seem to find a dialogue with this option, and so far, Microsoft's "help" isn't helping.

TIA
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top