无法从 Hyper V 虚拟机上的 Web 浏览器访问 LDAPS
我们有一个测试环境,其中物理 AD 服务器设置为 LDAPS 连接,并且 Hyper V 虚拟机运行 Web 服务器,并加载了我们的 AD 管理 Web 应用程序。我们已在物理 AD 服务器和虚拟 Web 服务器上设置了 x509 证书。我们可以通过 Ldap.exe 使用 SSL 链接到 AD 服务器,没有任何问题。当我们尝试通过网络浏览器访问时,它无法连接。事件日志显示 Schannel 事件
“从远程服务器收到的证书是由 不受信任的证书颁发机构。正因为如此,没有任何数据 可以验证证书中包含的内容。 SSL 连接 请求失败。附件数据包含服务器 证书。”
盒子尝试同样的事情,它工作得很好,同样,如果我们尝试从虚拟机访问 AD 服务器而不使用 LDAPS,它工作得很好。
我已经进入服务器并通过证书管理单元删除了 Hyper V 虚拟机管理的自签名可信根证书并重新启动了服务,没有任何更改,我找不到与我们的设置相关的任何其他内容来尝试
。导致这个失败?
We have an test environmnet where the physical AD server is set up for LDAPS connections and a Hyper V virtual machine running the webserver with our AD management web app loaded up. We have set up the x509 certs on both the physical AD server and on the virtual webserver. We are able to link to the AD server using SSl via Ldap.exe with no problems. When we try to access through the web browser it fails to connect. The event logs show an Schannel event with
"The certificate received from the remote server was issued by an
untrusted certificate authority. Because of this, none of the data
contained in the certificate can be validated. The SSL connection
request has failed. The attached data contains the server
certificate."
If we try the same thing from two phyisical boxes it works fine and likewise if we try to access the AD server from a virtual machine without using LDAPS it works fine.
I have gone on to the server and via the certificate snap in deleted the hyper v virtual machine management's self signed trusted root cert and restarted the service with no change. I can't find anything else relevent to our setup to try.
Anyone have any insight in to what we are missing on the virtual machine that is causing this failure?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
根据我的说法,该消息是:
“从远程服务器收到的证书是由不受信任的证书颁发机构颁发的。因此,证书中包含的任何数据都无法验证。SSL 连接请求失败。附加的数据包含服务器证书。”
表示您未在客户端(虚拟 Web 服务器)证书存储库上安装证书颁发机构的公钥证书。
尝试将其安装在计算机存储库上,同时也安装在负责启动 IIS 的用户的存储库上。
According to me the message :
"The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate."
Indicates that you do not intstall the public key certificate of the certificate authority on your client (Virtual Web server) certificate repository.
Try to install it on computer repository, but also on the reposository of the user which is in charge to start IIS.