Re: OWA Security Alert Prompt Question

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Ben Winzenz [Exchange MVP] (benwinzenz_at_NOSPAM.gardnerwhite.com)
Date: 02/23/04


Date: Mon, 23 Feb 2004 13:51:14 -0500

Yes - ALL clients need to install the cert and place it in the Trusted Root
Certification Authority cert store. This is the only way to get rid of that
message about the untrusted company. That, or break down and spend the
~$200 for a commercial cert from Thawte.

-- 
Ben Winzenz
MVP - Exchange
Network Engineer
Gardner & White
http://www.techtidbits.net
Exchange FAQ's: http://www.swinc.com/resource/exch_faq.htm
Exchange 2000 FAQ's: http://www.swinc.com/resource/e2kfaq.htm
"Tim Adams" <tim_4h@hotmail.com> wrote in message
news:d5140f12.0402230936.2d587a54@posting.google.com...
> Thanks for the reply..here's some more info:
> It's my own CA.  It is listed under the 'Trusted Root Cert
> Authorities' on the server. Do you mean all the clients need to
> install the certificate??
>
> The subject of the SSL DOES match the FQDN of the Exchange Server
> (only one server, not a front end/back end)
>
> The security alert I am referring to has the following warnings:
> - The certificate was issued by a company you have not chosen to trust
> - The name of the security certificate is invalid or does not match
> the name of the site.
>
> Thanks Again!
>
>
> "Piotr Trochimiuk" <ptr@nospamplease_vulcan.pl> wrote in message
news:<emwcKSf#DHA.1392@tk2msftngp13.phx.gbl>...
> > Your clients must first trust your root CA.
> > Where did you get SSL certificate from? Did you buy it for example from
> > Verisign? Or maybe used your own CA? If it's own CA, all of your clients
> > should add your root's CA certificate to trusted roots.
> > Check also:
> > Is your certificate valid?
> > Does the subject of SSL certificate match FQDN of your Exchange server?
> >
> > Or at least give us more info, what exactly says 'Security Alert'?
> > -- 
> > Piotr Trochimiuk
> > MCSE, MCSA:Messaging
> >
> >
> > Użytkownik "Tim Adams" <tim_4h@hotmail.com> napisał w wiadomości
> > news:d5140f12.0402222130.7cf8db94@posting.google.com...
> > > I recently implemeted Forms Based Authenication in Exchange 2003.
> > > Being new to SSL, I would like to stop the 'Security Alert' banner
> > > from appearing when clients log into their webmail.  I've known people
> > > from other companies who get their email via SSL OWA, without the
> > > prompt.  Does anyone have any ideas on how to disable this??
> > >
> > > Thanks in Advance....Tim


Relevant Pages

  • Ex2K7 - Certificate errors for internal clients using Outlook 2007
    ... Ex2K7 server and they are all getting certificate errors when Outlook 2007 ... starts up on domain joined machines (internal clients). ... Our internal/private AD domain name is nearly identical to ... ended up purchasing a Digicert UCC cert that had only our external FQDNs for ...
    (microsoft.public.exchange.connectivity)
  • Re: Multiple vulnerabilites in vendor IKE implementations, including Cisco,
    ... > in a concentrator and configure the clients to only talk ... > to a server with that certificate. ... I've seen clients that support it, so I assume concentrators from the ... You _could_ dole out a single cert to all clients, ...
    (Bugtraq)
  • Re: certificate authority
    ... Should the Certificate Service be running? ... > Just FYI, in SBS2003, CEICW will auto generate a cert without CA. ... > (Assuming you setup the clients via the SBS client seutp wizard). ...
    (microsoft.public.windows.server.sbs)
  • Re: authentication (SRP*, DH, TLS)
    ... B masternode offers core services and every nodeconnects to ... C as long as all clients connect to the master node only ... Make a CA that issues itself a self-signed certificate (CA root ... Install the CA root cert on all nodes and on all clients. ...
    (sci.crypt)
  • Re: How to Get IE to Trust My Certificate?
    ... You can download the CA cert from the /certsrv pages on the CA. (If it ... > way it's supposed to work when importing the site cert is ... >>trusted root to make that go away. ... >>> trust the certificate I have created with my own ...
    (microsoft.public.inetserver.iis.security)