Re: Secure access to RPC over HTTPs

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Fri, 21 Oct 2005 13:44:04 -0700, "RB"
<RB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

>Hi,
>
>We are running Exchange 2003 FE + BE. ISA 2004 will be used to publish RPC
>over HTTP.
>
>We have one problem: only username + password is not compliant with our
>security policy.
>
>1) We would like some kind of additional authentication beside username +
>password, for instance the requirement of a user certificate. Is it possible
>to successfully configure RPC over HTTP + the require user certificate option
>on ISA or IIS? I understand a setup with RSA Secure ID is out of the
>question.
>
>2) If above is not possible we would like to restrict users to access RPC
>over HTTP from domain member computers only. Is it possible to force the ISA
>2004, RPC proxy or IIS to accept only users logged on to the domain (our
>users will be working with cached credentials on their laptops)?
>Do any settings exist in NTLM we can implement to allow users with cached
>credentials on their laptops to logon while preventing other users to logon
>interactively?
>
>
There are loads of resources for this one, the easiest MS solution is
to put the FE behind an ISA and use the RSA capabilities in ISA 2004
to pre-authenticate at the gateway and then gain access to the
network.

What you say RSA is out of the question, who is it out of the question
for? You, or your understanding of the question?
.



Relevant Pages

  • Re: HTTPS Using Web Proxy
    ... The ISA log displays the following on the error. ... HTTP Method = ... I created a HTPPS 444 protocol set to TCP port 444 and assigned it to my ... At first I was getting a error code: 502 Proxy Error and fixed that by ...
    (microsoft.public.isa)
  • Re: ADFS, ISA and SSL offloading
    ... I finally enabled logging on the ADFS ... Looking at this made me perform Link Translation in ISA and that's it, ... about it that is different than any normal SSL web app. ... embedded within the HTTP protocol. ...
    (microsoft.public.windows.server.active_directory)
  • Re: FrontEnd/BackEnd Vs ISA (reverse proxy)
    ... This is called SSL-bridging and you can configure it to be either HTTP or HTTPS ... A2 - Since ISA can cache some portion of the OWA pages, you get a performance gain by placing ISA between the ... site and a few remote site with a very a poor ... I have in DMZ an ISA Server used for reverse proxy. ...
    (microsoft.public.exchange.connectivity)
  • Re: FrontEnd/BackEnd Vs ISA (reverse proxy)
    ... This is called SSL-bridging and you can configure it to be either HTTP or HTTPS ... A2 - Since ISA can cache some portion of the OWA pages, you get a performance gain by placing ISA between the ... site and a few remote site with a very a poor ... I have in DMZ an ISA Server used for reverse proxy. ...
    (microsoft.public.isaserver)
  • Re: FrontEnd/BackEnd Vs ISA (reverse proxy)
    ... This is called SSL-bridging and you can configure it to be either HTTP or HTTPS ... A2 - Since ISA can cache some portion of the OWA pages, you get a performance gain by placing ISA between the ... site and a few remote site with a very a poor ... I have in DMZ an ISA Server used for reverse proxy. ...
    (microsoft.public.exchange2000.connectivity)