Re: IIS Permissions

Tech-Archive recommends: Fix windows errors by optimizing your registry



You also have SSL installed, and you only allow SSL through as you
previously mentioned.

So even if it is clear text it isn't because it's encrypted.

/o


<trent.queen@xxxxxxxxx> wrote in message
news:1157966016.218241.179150@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I just want to make sure that my security is set correctly on OWA (I
dont think it is, but it works).

Things you should know:
Windows 2003 SP1
Exchange 2003 SP2 - just upgraded
I use FBA
I only accept connections on HTTPS (Port443)

---Here is what the folders are set at currently (IIS Authentications
Modes)---

Exadmin - Intergrated Windows authentication

Exchange - Basic authentication (password is sent in clear text) - IS
THIS RIGHT?

ExchWeb - Enable anonymous access - IS THIS RIGHT?

Microsoft-Server-ActiveSync - Basic authentication (password is sent in
clear text) - IS THIS RIGHT?

OMA - Basic authentication (password is sent in clear text) - IS THIS
RIGHT?

OWAAdmin - Intergrated Windows authentication

Public - Basic authentication (password is sent in clear text) - IS
THIS RIGHT?


Again, It works atm, but I dont like the idea of send in the clear even
with HTTPS.

Please let me know what is should be or your thoughts!

Thanks very much, Trent. :)



.



Relevant Pages

  • Re: IIS Permissions
    ... Your security is exactly the same as what I have on on of my FE Exchange ... Exchange - Basic authentication - IS ... OWAAdmin - Intergrated Windows authentication ...
    (microsoft.public.exchange.admin)
  • Re: IIS Permissions
    ... Your security is exactly the same as what I have on on of my FE Exchange ... Exchange - Basic authentication - IS ... OWAAdmin - Intergrated Windows authentication ...
    (microsoft.public.exchange.admin)
  • OWA: IIS Permissions
    ... I only accept connections on HTTPS ... Exchange - Basic authentication - IS ... OWAAdmin - Intergrated Windows authentication ... Again, It works atm, but I dont like the idea of send in the clear even ...
    (microsoft.public.exchange.admin)
  • Re: IIS Permissions
    ... Your security is exactly the same as what I have on on of my FE Exchange ... Servers in my test lab, and this is an Out of the box configuration. ... Exchange - Basic authentication - IS ... OWAAdmin - Intergrated Windows authentication ...
    (microsoft.public.exchange.admin)
  • Re: IIS Permissions
    ... ExchWeb - Enable anonymous access - IS THIS RIGHT? ... Microsoft-Server-ActiveSync - Basic authentication (password is sent ... OWAAdmin - Intergrated Windows authentication ... In Basic Auth, the passwords are sent Base64 encoded, which is easy ...
    (microsoft.public.exchange.admin)