Enabling STARTTLS in Exchange 2003 IMAP service?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Andrew Biggs (dreamcoder_at_yahoo.com)
Date: 01/11/05


Date: Tue, 11 Jan 2005 09:35:01 -0700

Hello,

I'm hoping someone with experience setting up IMAP on Exchange 2003
might be able to advise me on getting it correctly administered to
support the STARTTLS capability. I have E2K3 installed on a W2K3
server, which it itself administered as the (only) domain controller.
Here is what I have done so far:

1) Created a certificate request using the Exchange System Manager's
"Web Server Certificate Wizard" in the IMAP4 virtual server properties.

2) Used the Windows CA on the same server to issue a certificate based
on the request. Exported the binary certificate.

3) Went back to the "Web Server Certificate Wizard" in the IMAP4 virtual
server properties to import the binary certificate.

4) Checked the "Require SSL/TLS encryption" box under "Authentication"
in the IMAP4 virtual server properties.

5) Stopped/Started the IMAP4 virtual server.

At this point, I was expecting to be able to connect to port 143 on the
server, submit a CAPABILITY command, and get something back that would
at least include STARTTLS. Unfortunately, it still doesn't.

Any thoughts on what I may be missing here? I'd appreciate any
suggestions at all, even sketchy ones :-).

Thanks!
Andrew



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Enabling STARTTLS in Exchange 2003 IMAP service?
    ... support the STARTTLS capability. ... "Web Server Certificate Wizard" in the IMAP4 virtual server properties. ...
    (microsoft.public.exchange.admin)