Re: OWA Basic not possible without SSL?

From: Tim Hackbart [MSFT] (Timhack_at_online.microsoft.com)
Date: 03/19/04


Date: Fri, 19 Mar 2004 13:57:10 -0600

There is no FBA in Exchange 2000, only 2003.

So the only option would be the registry key to force all clients to have a
down-level experience.

Hope it helps.

-- 
Tim Hackbart M.C.S.E.
This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send email directly to this alias. This alias is for newsgroup
purposes only.
"Matt Yurek" <matt.NO.yurek@SPcommwebAMworks.com> wrote in message
news:#B6nnmdDEHA.712@tk2msftngp13.phx.gbl...
> It all makes sense now...  :-)
>
> So as far as Exchange 2000 SP2 is concerned - is there a forms-based
screen
> for OWA or just the registry option to force everyone to basic?
>
> Thanks very much,
> Matt
>
> "Tim Hackbart [MSFT]" <Timhack@online.microsoft.com> wrote in message
> news:uJYJst6CEHA.2824@TK2MSFTNGP12.phx.gbl...
> > Matt
> >
> > You are referring to Forms Bases Authentication(FBA), which does require
> > SSL.  That is what gives you that Blue Logon screen with the options you
> are
> > looking for.
> > The "forms" is the logon.asp page that we render when you connect to
that
> > server with SSL.
> >
> > To enable FBA you would drill down to your Server object in the Exchange
> > System Manager, then Protocols, then HTTP and then Right Click on the
> > Exchange Virtual Server and Properties then the Settings Tab and click
in
> > the "Enable Forms Based Authentication"
> >
> > After you do this, nothing will change for users who access OWA with
just
> > HTTP, only users who access OWA with HTTPS will get the FBA page.
> > The following article may help as well
> > http://support.microsoft.com/default.aspx?scid=kb;en-us;830827
> >
> > You could issue a Cert from a Windows 2000 RootCA, but then your clients
> > would get a prompt that this Certificate is not trusted.
> > To get rid of the prompt you could Export your Windows2000 RootCA and
then
> > import it on your client machines.
> > I realize that would not be the easiest thing to do, but it would keep
> your
> > clients from getting that prompt
> >
> > Hope this helps
> >
> > -- 
> > Tim Hackbart M.C.S.E.
> > This posting is provided "AS IS" with no warranties, and confers no
> rights.
> >
> > Please do not send email directly to this alias. This alias is for
> newsgroup
> > purposes only.
> >
> > "Matt Yurek" <matt.NO.yurek@SPcommwebAMworks.com> wrote in message
> > news:OIiS7P1CEHA.580@TK2MSFTNGP11.phx.gbl...
> > > I guess my problem is this:  when I look at screenshots of OWA2003 in
> > > action, I see a screen that allows people to select the basic or
premium
> > > version during login.  I'd like to implement this, but I can't seem to
> > find
> > > a way to set this option.  Right now, when I go to
> > > http://mail.domain.com/exchange all I get is an HTTP authentication
> pop-up
> > > and the premium version of OWA.  I don't need to implement SSL right
> now,
> > > but I don't want to force people to Basic just because SSL isn't
> > available.
> > >
> > > I guess I could do a self-signed cert, but I'd like to avoid the SSL
> > > warnings if possible.
> > >
> > > I've googled on this and can't find much - maybe I'm just calling it
> > > something else and so searches are coming up empty...
> > >
> > > Does "form-based" refer to Exchange forms, or web forms like the login
> > > screen, or both?
> > >
> > > Thanks,
> > > Y
> > >
> > > "Tim Hackbart [MSFT]" <Timhack@online.microsoft.com> wrote in message
> > > news:#4tR4SHCEHA.1140@TK2MSFTNGP10.phx.gbl...
> > > > Matt
> > > >
> > > > You may have been reading the information regarding Exchange 2003
and
> > > Forms
> > > > Based Authentication, which does require SSL and gives the user a
> choice
> > > of
> > > > Premium or Basic OWA.
> > > >
> > > > You do have one alternative, which is a server side setting that
would
> > > force
> > > > ALL users to have a Basic OWA experience.  This was implemented in
> > > Exchange
> > > > 2000 SP2 and is available in Exchange 2003 as well.
> > > > 311342 XCCC: Exchange 2000 Server SP2 Server-Side OWA Registry Keys
> > > > http://support.microsoft.com/?id=311342
> > > >
> > > > Basically you set a registry key on the OWA server
> > "forceclientsdownlevel"
> > > > and now ALL users will have a Basic OWA experience.
> > > >
> > > > Hope this helps.
> > > >
> > > > -- 
> > > > Tim Hackbart M.C.S.E.
> > > > This posting is provided "AS IS" with no warranties, and confers no
> > > rights.
> > > >
> > > > Please do not send email directly to this alias. This alias is for
> > > newsgroup
> > > > purposes only.
> > > >
> > > > "Matt Yurek" <matt.NO.yurek@SPcommwebAMworks.com> wrote in message
> > > > news:OBeUUTFCEHA.2592@TK2MSFTNGP12.phx.gbl...
> > > > > Is it true that I read that OWA Basic is not available without
SSL?
> > Is
> > > > > there any way around this?
> > > > >
> > > > > Thanks,
> > > > > Matt
> > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> >
> >
>
>


Relevant Pages

  • Re: OWA Form Based Authentication now working
    ... Does the SSL site work if you aren't using FBA? ... we have a two server exchange environment. ...
    (microsoft.public.exchange.admin)
  • Re: Do I have to implement OWA using HTTPS?
    ... Do I HAVE to use SSL for OWA? ... Exchange 2000 Server and we didn't have to use SSL for OWA access. ... FBA, basic, integrated? ...
    (microsoft.public.isaserver)
  • Re: Autodiscover
    ... John I highly reccomend that you go the route of using only one cert. ... Having clients pointing to two seperate addresses will really screw ... There is a whole host of docs available for exchange 2007/sp1 ... internal exchange server. ...
    (microsoft.public.exchange.admin)
  • Re: Proper DNS configuration for hub-and-spoke replication topolog
    ... each contiguous with one of the child domains. ... we'd like to limit domain controllers to receiving login ... requests from *only* clients in their domain, ... > Once the change to 9 VLANs is complete, a client workstation or an Exchange ...
    (microsoft.public.windows.server.active_directory)
  • Re: Info Store Help!!!
    ... Exchange in SBS is that it is the same as Exchange 2003 Standard. ... The clients are all Outlook 2003 Cached mode. ... The clients are still getting the "Exchange Server cannot be ... Offline Defrag against both the Public and Private stores. ...
    (microsoft.public.exchange.admin)