Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

You cannot enter a port number in the SSL port box in the Identification dialog box for a secondary HTTP protocol server in Exchange Server 2003


View products that this article applies to.

Symptoms

Consider the following scenario. You use Exchange System Manager to create a secondary HTTP protocol server in Microsoft Exchange Server 2003. Then, you enter a port number in the TCP port box in the Identification dialog box. In this scenario, you cannot enter a port number in the SSL port box in the Identification dialog box. The SSL port box is unavailable.

↑ Back to the top


Cause

This issue occurs because you cannot enter the TCP port and the SSL port at the same time in the Identification dialog box.

↑ Back to the top


Resolution

To resolve this issue, follow these steps:
  1. Start Exchange System Manager.
  2. Expand Administrative Groups, expand Administrative_Group_Name, expand Servers, and then expand Your_Server_Name.
  3. Expand Protocols, expand HTTP, right-click the secondary HTTP virtual server that you created, and then click Properties.
  4. Click Advanced, and then click Add.
  5. If you want to add a specific IP address binding, click the appropriate IP address in the IP address list.

    Do not type anything in the Host name box.
  6. Delete the number in the TCP port box. The SSL port box is now available.
  7. In the SSL port box, type 443, and then click OK.
  8. Click Yes, and then click OK two times.
  9. Quit Exchange System Manager.
After you perform this procedure, the SSL definition is set in Active Directory. The SSL definition is contained in the msExchSecureBinding attribute. To make SSL functional, you must use Microsoft Internet Information Services (IIS) Manager to apply the appropriate Web server certificate to the new HTTP protocol virtual server.

Important The SSL binding may be removed if either of the following conditions is true:
  • You do not use Exchange System Manager to set the msExchSecureBinding attribute in Active Directory.
  • You do not use a tool such as the Active Directory Service Interfaces (ADSI) editor to directly set the msExchSecureBinding attribute in Active Directory.
The SSL binding is removed if you use IIS Manager to set the msExchSecureBinding attribute. After the Exchange server is restarted or after an Exchange service is restarted, the value in the metabase is overwritten with the value in Active Directory.

↑ Back to the top


More information

This issue also applies to the default HTTP protocol servers that are created for use in an Exchange Server 2003-based cluster environment. In an Exchange Server 2003-based cluster environment, the default HTTP protocol servers are implemented as secondary HTTP protocol virtual servers.

The SSL settings on HTTP protocol servers that depend on the default Web site are configured in IIS Manager and not in Exchange System Manager. Therefore, these servers are not affected by this issue.

↑ Back to the top


References

For more information about how to configure SSL for Exchange virtual servers, click the following article numbers to view the articles in the Microsoft Knowledge Base:
234022 Configuring Exchange OWA to use SSL
320291 Turning on SSL for Exchange 2000 Server Outlook Web Access

↑ Back to the top


Keywords: KB904785, kbprb, kbtshoot

↑ Back to the top

Article Info
Article ID : 904785
Revision : 4
Created on : 10/25/2007
Published on : 10/25/2007
Exists online : False
Views : 274