Re: SSL cert in ISA 2006



I think you're confusing different things:
** SSL = an encryption protocol that can be applied to any application
protocol (HTTP, SMRP, POP3, IMAP, etc.) to provide session-level encryption.
** HTTP an application protocol most commonly used by browsers, but this is
changing rapidly.
** OWA = Exchange mail using a browser. It uses HTTP and *should be*
protected using SSL/TLS encryption; thus it is commonly referred to as
HTTPS.
** RPC over HTTP = Exchange mail using Outlook 2003 or 2007. It uses a
"special" form of RPC known as MAPI (not to be confused with IMAP). As of
WS03 and XP SP2, a new mechanism within RPC that allows it so use HTTP as an
alternate transport. RPC over HTTP should also be encrypted using SSL/TLS.

HTH,

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"Daniel" <danieltbt04@xxxxxxxxx> wrote in message
news:OPc5gPb3HHA.4584@xxxxxxxxxxxxxxxxxxxxxxx
What is the purpose of SSL used in ISA for ? Thanks

Daniel

"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:BCCD00DB-ECBF-423F-8409-10A1A6F8FED4@xxxxxxxxxxxxxxxx
No; OWA is Exchange using a browser.

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"Daniel" <danieltbt04@xxxxxxxxx> wrote in message
news:ODabDVC3HHA.5164@xxxxxxxxxxxxxxxxxxxxxxx
Can be used for OWA ? Thanks

Daniel

"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:96C4E6A7-8DC5-4668-A437-13589D1B9DD0@xxxxxxxxxxxxxxxx
RPC over HTTP is for Outlook 2003 and later clients.
It's a more secure and efficient way to connect outlook to Exchange over
the
Internet.
Lotsa docs on this over at Technet...

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"Daniel" <danieltbt04@xxxxxxxxx> wrote in message
news:O$Bs8112HHA.5116@xxxxxxxxxxxxxxxxxxxxxxx
Jim, what is RPC/HTTP traffic for ? I've enabled SSL in OWA does it means
that RPC/HTTP also in SSL now ? Thanks

Daniel

"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:CE98620A-52F3-4F56-BB23-811A1F2F1817@xxxxxxxxxxxxxxxx
Yes, you can, but this leaves all your OWA & RPC/HTTP traffic and
authentication open to traffic sniffing.
..not a great choice, IOW.

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"Andrew" <andrew@xxxxxx> wrote in message
news:urjTTR7zHHA.3564@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

Does anyone know if it's possible to get ISA 2006 Working with OWA and
outlook anywhere without using an SSL certificate?

Thanks,

Andrew







.



Relevant Pages

  • Re: ISA 2004 Server Errors
    ... Tunneling SSL Through a WWW Proxy ... CONNECT is really a lower-level function than the rest of the HTTP methods, ... Through ISA Server ...
    (microsoft.public.isa)
  • Re: ADFS, ISA and SSL offloading
    ... I finally enabled logging on the ADFS ... Looking at this made me perform Link Translation in ISA and that's it, ... about it that is different than any normal SSL web app. ... embedded within the HTTP protocol. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADFS, ISA and SSL offloading
    ... Assuming it is a very short, secure segment between your LB and web server, the risk of running that segment unencrypted is likely be very low but still deserving of caution. ... The other aspect of this is that SSL is not likely to be that big of a deal in terms of absolute performance here, so I'm not sure if you gain much by doing this. ... leave all HTTP on 80 and all SSL on 443. ... ISA is going ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA allowing non-SSL traffic on 443
    ... 443 is the port address that SSL uses... ... I don't think ISA can define what is or isn't encrypted traffic or not. ... No SSL encryption is used. ...
    (microsoft.public.isa.configuration)
  • Re: ADFS, ISA and SSL offloading
    ... HTTP Application Filter in ISA is a "proxying" filter,...this means that the ... Now this is not unique to ISA ... ISA is extremely picky and is very strick about following all RFCs ... the reason I say to leave the SSL intact from end-to-end and not ...
    (microsoft.public.windows.server.active_directory)