Re: SSL sign in to OWA

Tech-Archive recommends: Fix windows errors by optimizing your registry



> Can you post the entire solution that you developed. I'd be interested in
> understanding what you did.
>
> Nue
>
I'm going to start this with a down note: After 4 or so hours of
getting this to work in the lab, I installed sharepoint services 2, and
basically buggered it all up, oh well, got it working again, but I
learn lots whenever I try something new!!
Anyone know if they got the sharepoint and exchange 2003 to work yet,
It's ideal for me, sharepoint takes the root of the site, cert services
and exchange take subdirs, as this is only internal for my staff I'd
love to be able to do it.

Right the whole solution as I have it now:

Install FE and BE servers for exchange 2003.
Disable FBA on the FE server
In IIS r/click the exchange directory > properties > directory security
under authentication and access control, clear basic authentication,
clear anon access
enable integrated windows authentication
OK
Secure communications
check Require SSL > check Require 128bit
check Require client certificates

Under client certificate mapping > 1-to-1 map the user certificate to
the AD user account

*In order to do this I exported all of the users certificates to a
shared folder, IIS just requires a certificate to get the data from, I
used *.cer files, if the user changes the certificate you have to do
this again, and I had to do it a lot of times, really only recommended
for small numbers of users, unless you can come up with a script that
does the mapping for you, I havn't had time yet
**You can't do many-to-1 because the certificate contains the UPN and
you add the password when you add the cert, so many to 1 can't work in
this

Restart IIS

http://www.yourdomain.com/exchange/
you get a prompt to select the certificate from your certs, click it,
bingo, accessed, and working.

***If you use multiple machines, and get a cert from the CA seperately
for each one, you WILL have problems, thhaat's why I mentioned about
the profiles and taking certss with them, but I will have to look into
this some more.
But the concept appears to be flawless.

But with all good concepts either you ot Microsoft are going to come in
tell me why this is wrong, which is why I'm testing it for a few weeks
in a lab, and while I try and find a way to do this for hundreds of
users without getting RSI.

Hope this helps, all feedback welcome, you can post to my email if you
want
Regards
Shaine

.



Relevant Pages

  • Re: Outlook 2007 Certificate Error
    ... I did not get the UC/SAN cert since I didn't know what that meant, ... I know you can probably get away with a standard cert, such as what was used in Exchange 2003, and a few folks may respond that it works. ... Exchange 2007 UC/SAN Certificate ... If you name the internal domain the same as your Internet public domain name, in some time domain internal client will get the domain external IP. ...
    (microsoft.public.windows.server.sbs)
  • Re: Confusion RE: Transport Security Layer
    ... If you choose not to use Cert ... there are plenty of public certificate authorities out there. ... > server that requires TSL. ... >>>does this apply to Exchange 2K3. ...
    (microsoft.public.exchange.admin)
  • Re: Outlook 2007 Certificate Error
    ... I guess one of the problems is that the cert is for mail. ... Exchange 2007 needs a UC/SAN cert. ... Exchange 2007 UC/SAN Certificate ... If you name the internal domain the same as your Internet public domain ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2008 Port Forward Question
    ... What is a good source to understand the differences between SSL and UC/SAN certs and what I should be looking to buy vs. my $27 GoDaddy cert. ... How to Add a GoDaddy SSL Certificate in SBS ... Exchange 2007 does not work with such a certificate. ... internalname ...
    (microsoft.public.windows.server.sbs)
  • Re: Pocket PC 2003 - Can access OMA etc, but cannot sync with ActiveSync
    ... I think I originally imported the wrong cert from the workstation. ... of problem on SBS2k and Win2k where Exchange is in the default site and the ... I tried to install the certificate yesterday ...
    (microsoft.public.windows.server.sbs)