Re: OWA Issues



Integrated authentication = Kerberos, which doesn't usuallly work over the
Internet.

Note that I didn't say that it was a "security" issue to have Integrated
enabled for internal access. The only security hole would be if an admin
leaves their workstation unlocked, and if that is happening, you have more
serious problems than OWA automatically logging you in!

As for your question, if you are only using Basic auth, then yes, passwords
are transmitted in plain text. However, if you are using an SSL certificate
(which would be recommended), then the entire connection is encrypted, so
it's a rather moot point, as you'd have to break the encryption key in order
to see the contents of the packets.

--
Ben Winzenz
Exchange MVP
MessageOne
Read my blog!
http://winzenz.blogspot.com
http://feeds.feedburner.com/winzenz (RSS Feed)


"George Schneider" <georgedschneider@xxxxxxxxxxxxxx> wrote in message
news:B04EFF99-1343-4D73-AE44-0E0D9D35F8ED@xxxxxxxxxxxxxxxx
wouldn't it be a security risk not to use integrate authentication.
wouldn't
the passwords be sent in clear text?

"Ben Winzenz [Exchange MVP]" wrote:

Huh? How about one more time in English, please.

Normally, the issue here is that either Integrated authentication is
enabled
on the Exchange vdir, or someone has saved their password in IE's
password
cache. Both can be fixed, albeit by different methods.

Forms-based authentication doesn't necessarily fix this.

--
Ben Winzenz
Exchange MVP
MessageOne
Read my blog!
http://winzenz.blogspot.com
http://feeds.feedburner.com/winzenz (RSS Feed)


"dk" <darshan.kolambkar@xxxxxxxxx> wrote in message
news:1158341687.211525.277470@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello
See the users having rights on mail boxes will get direct access will
no more prompt for any password check mailbox rights. I can say u this
issue resolved by owa with form base authentication.

Darshan


Chad Mahoney wrote:

George Schneider wrote:
I've been having this ssssue for some time. When any user thta is a
member
of the Domain Admins group attempts to check thir mail via OWA they
go
right
into their mail without being prompted for a user name or password.
This
almost sounds like its a rights issue somewhere. Any help will be
greatly
appreciated.


I would check the IE settings, goto tools Internet options and to the
security tab. If you hit custom level and scroll to the bottom you
will
see an option about user authentication, it will probably be set to
use
current user name and password for users automatically logging into
OWA
and probally set to prompt for users having to enter there
credentials.






.



Relevant Pages

  • Testimony of Jeff Schmidt, CEO, Authis
    ... Examining the Security Implications of Proposed Online Gambling Regulation ... recognized expert on issues related to online identification and authentication, ... authentication, and age verification. ... individual using The Internet. ...
    (rec.gambling.poker)
  • Re: Authentication problem
    ... am just dealing with my own experience with multi-purposed .NET security ... forms authentication - is any more secure than a single instance ... config method based on which site you are deploying than you are setting ... such as the internet) or windows authentication (if ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Integrated authentication and IE proxy settings
    ... This behavior is governed by the security settings of IE. ... IE by default will not provide integrated authentication to sites that are ... If "Automatically detect setting" option is checked on the internet ...
    (microsoft.public.isa.clients)
  • Spoofing an IP over the internet
    ... I'm fairly new to this list and I'm very interested in security. ... authentication with PHP and MySQL. ... It would be easy for a hacker to just set UserAgent to an incrementing ... address at will over the internet before opening a TCP/IP connection? ...
    (Security-Basics)
  • Solaris Security Summary
    ... Administering Security on the Solaris OE ... Configuration control, facility management, and system ... Authentication: The ability to prove who you are. ...
    (comp.unix.solaris)