Are user certs broken when used on a front end server?

Tech-Archive recommends: Fix windows errors by optimizing your registry



Does a front end exchange 2003 SP2 server support requiring a user
certificate? On the back end server requiring user certs works fine
(but breaks Treo syncing). I therefore set up a front end server and
two virtual servers (one just SSL for treos and the other for Outlook
Web Access).

If I require a cert on the front end virtual directory I want to use
for Outlook Web Access and try it, IE presents a blank box for the user
certificate (when it should present one of the installed user
certificates). If the backend is configured the same way and a client
connects, their user certs are displayed and work fine.

In each case the same root CA (my own) has been installed and has
issued both the front end server and the back end server their SSL
certs. If I disable mandatory certs on the front end server and just
require ssl everything works fine. Are user certs broken on a front end
server?

-M

.



Relevant Pages

  • How do you get mandatory user certs to work on a front end virtual server?
    ... Does a front end exchange 2003 server support using required user ... exchange virtual directory structure so that I now have two websites ... If I make User Certs mandatory on a virtual server none of the user ...
    (microsoft.public.exchange.setup)
  • Re: Are user certs broken when used on a front end server?
    ... If you enable SSL on the FE server, you must turn off SSL on your BE Server. ... certificate (when it should present one of the installed user ... their user certs are displayed and work fine. ...
    (microsoft.public.exchange.admin)
  • Question on chnaging the expiration date of certificates
    ... year to a different value on a standlone Sub-ordinate CA server. ... When I initiallythe installed the Standalone sub-ordinate CA server, ... After following the suggestion in the document Q254632, the user certs and ... the CA cert still has the same validity of 1 year. ...
    (microsoft.public.win2000.security)
  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)