Quantcast
Channel: Internet Explorer 8, 9, 10 Forum
Viewing all articles
Browse latest Browse all 1908

SplitSSL vs Mixed Zone

$
0
0

Hi folks.

This is quite a tricky problem; I'll try to be as clear as possible.

I think it may be an issue with SplitSSL and Mixed Zones.

Using: Windows 7, IE8 or IE9.

We installed the SplitSSL hotfix/patch when it was released (February?). This seemed to break a website for payments. We are aware of the information out there regarding SplitSSL; to ensure it is on all severs that require it (which it is). We know we can disable it using the registry, but we want to keep it enabled.

We present a payment page through our intranet (payments.oursite.com). *.oursite.com is regarded as an intranet zone (zone 1).

However, this passes data to the secure payment servers held off site (paynow.oursite.com). Although this server has our domain name, it is held outside our Class B network. It does have an alias set in DNS.

If I attempt to set both sites (payments.oursite.com and paynow.oursite.com) to intranet zone, IE says that it's intranet but the webpage doesn't work correctly. If I set payments.oursite.com to intranet, but paynow.ouriste.com to trusted zone, it says mixed and still doens't work. If I set both to trusted zone, then it works fine (but we lose the intranet functions, such as SSO etc).

Can anyone shed any light on this?

I'm thinking that SplitSSL may have issues when dealing with a mixed zone (me be "on purpose" for security reasons), but I suppose our main problem is getting the paynow.oursite.com being recognised as the intranet zone, which it is not.

Thanks.



Viewing all articles
Browse latest Browse all 1908

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>