{"id":16548,"date":"2016-07-04T09:38:26","date_gmt":"2016-07-04T01:38:26","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=16548"},"modified":"2024-07-05T11:42:22","modified_gmt":"2024-07-05T03:42:22","slug":"how-to-bind-an-ssl-certificate","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/server-resources\/how-to-bind-an-ssl-certificate\/","title":{"rendered":"How to Bind an SSL Certificate"},"content":{"rendered":"\n<h2 class=\"page-subheading\">Overview<\/h2>\n<p class=\"intro-text\">Since IFS OI Server only supports HTTPS, it must be deployed to a Web Site with an HTTPS binding configured. The Default Web Site in IIS will not work.<\/p>\n<p class=\"intro-text\">This section assumes that you have deployed the SSL certificate and created an SSL website as part of the installation of IFS OI Security. If this is not the case, see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/server-resources\/configuring-ssl\/\">Configuring SSL<\/a>\u00a0before proceeding.<\/p>\n<p class=\"intro-text\">For IFS OI Server to work correctly, the SSL certificate for your domain needs to be bound to two ports:<\/p>\n<ul class=\"intro-text\">\n<li>One to the SSL website in IIS (usually 443).<\/li>\n<li>One for the ServicePort specified in the configuration file (defaults to 8080).<\/li>\n<\/ul>\n<p class=\"intro-text\">When setting up the website in IIS, the certificate will automatically be bound by IIS to the port configured for that website. However, there is no user interface to bind the certificate to the ServicePort, so this has to be done through the command line. The following command shows the current SSL bindings:<\/p>\n<pre>netsh http show sslcert<\/pre>\n<p class=\"intro-text\">The command to bind a certificate to the port is:<\/p>\n<pre>netsh http add sslcert ipport=0.0.0.0:8080 certhash=f0fdac6d8dd1ea9dcec72bd33ed7cc1ccdc06008 \r\nappid={daf2e53d-2c3b-4fce-9d74-a5b618c52562}<\/pre>\n<p class=\"intro-text\">Where:<\/p>\n<ul class=\"intro-text\">\n<li><strong>ipport<\/strong> specifies the port to bind to.\u00a0Note: It is recommended to use <em>0.0.0.0<\/em> for the IP address as this will bind to any IPv4 address.<\/li>\n<li><strong>appip<\/strong> is a GUID that can be used to identify the owning application<\/li>\n<li><strong>certhash<\/strong> specifies the thumbprint of the certificate<\/li>\n<\/ul>\n<h2 class=\"page-subheading\">How to Get the Thumbprint (certhash)<\/h2>\n<ol class=\"intro-text\">\n<li>Open the Microsoft Management Console (<em>Start &gt; mmc.exe<\/em>).<\/li>\n<li>In the Console Root, select <strong>Add\/Remove Snap-in<\/strong> from the <strong>File<\/strong> menu (<em>File &gt; Add\/Remove Snap-in<\/em>).<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-16574\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013.png\" alt=\"image013\" width=\"688\" height=\"484\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013.png 688w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013-150x106.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013-24x17.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013-36x25.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image013-48x34.png 48w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/a><br \/>\n\u00a0<\/li>\n<li>In the <strong>Add or Remove Snap-ins<\/strong> dialog box, click <strong>Certificates<\/strong> and then click <strong>Add<\/strong>, to move it to the <strong>Selected snap-ins<\/strong>.<strong><br \/>\n<\/strong>A message appears, asking which account to manage the snap-in for.<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-16575\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015.png\" alt=\"image015\" width=\"534\" height=\"395\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015.png 534w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015-150x111.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015-24x18.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015-36x27.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image015-48x36.png 48w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><br \/>\n\u00a0<\/a><\/li>\n<li>Select <strong>Computer account<\/strong>, and then click <strong>Next<\/strong>.<\/li>\n<li>Select the <strong>Local computer<\/strong>, and then click <strong>Finish<\/strong>.<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-16576\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017.png\" alt=\"image017\" width=\"534\" height=\"395\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017.png 534w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017-150x111.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017-24x18.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017-36x27.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image017-48x36.png 48w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><\/a><br \/>\n\u00a0<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>In the Console Root, expand the <strong>Certificates<\/strong> node, then expand the <strong>Personal<\/strong> node and click <strong>Certificates<\/strong>.<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-16578 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019.png\" width=\"960\" height=\"384\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019.png 960w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019-768x307.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019-150x60.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019-24x10.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019-36x14.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2016\/07\/image019-48x19.png 48w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><br \/>\n\u00a0<\/a><\/li>\n<li>Right-click on the SSL certificate issued to your domain (e.g. <strong>*.petroleumplace.com<\/strong>), and select <strong>Properties<\/strong>.<br \/>\n<em>Note: If there is no Details tab in the Properties dialog, double-click the certificate instead.<br \/>\n<\/em>\u00a0<\/li>\n<li>Click the <strong>Details<\/strong> tab, and copy the <strong>Thumbprint<\/strong> value to the clipboard.<\/li>\n<li>Use this for the <strong>certhash<\/strong> value in the certificate binding command.<\/li>\n<\/ol>\n<h2 class=\"page-subheading\">Instructions for Binding<\/h2>\n<p class=\"intro-text\">Before proceeding, ensure you have the correct <strong>ipport<\/strong> number, and copy the <strong>appid<\/strong> from the example below. However, you will need to obtain the correct thumbprint (<strong>certhash<\/strong>) of the certificate (see above).<\/p>\n<ol class=\"intro-text\">\n<li>Open a command prompt.<\/li>\n<li>Bind the SSL certificate to the ServicePort by typing the following command:<\/li>\n<\/ol>\n<pre>netsh http add sslcert <span style=\"color: #0000ff;\">ipport<\/span>=0.0.0.0:8080 <span style=\"color: #0000ff;\">certhash<\/span>=cd0a103f58b6e43c01254d6229ef5050cf189ea4 \r\n<span style=\"color: #0000ff;\">appid<\/span>={daf2e53d-2c3b-4fce-9d74-a5b618c52562}<\/pre>\n<p class=\"intro-text\">For more details on configuring a port with an SSL certificate, go to <a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/ms733791(v=vs.110).aspx\">https:\/\/msdn.microsoft.com\/en-us\/library\/ms733791(v=vs.110).aspx<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since IFS OI Server only supports HTTPS, it must be deployed to a Web Site with an HTTPS binding configured. This article describes how to bind an SSL certificate to the ports required for IFS OI Server.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/server-resources\/how-to-bind-an-ssl-certificate\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":16555,"parent":3655,"menu_order":4,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[9],"tags":[465],"class_list":["post-16548","page","type-page","status-publish","has-post-thumbnail","hentry","category-tech-ref","tag-ssl","Product-srv"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/16548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=16548"}],"version-history":[{"count":3,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/16548\/revisions"}],"predecessor-version":[{"id":67845,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/16548\/revisions\/67845"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3655"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/16555"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=16548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=16548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=16548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}