Re: SSL connecting on OWA 2003



You need a certificate for any connection that is over HTTPS. You already
have one for the connection from ISA Server to the OWA server. Since your
clients will connect to ISA Server over HTTPS, you need another certificate
on ISA Server. The name on the certificate will have to match the name that
the user uses to connect to the site (the published, public name). Also,
each client computer will require the root certificate for that certificate.
If you can meet those conditions, you could theoretically use the same
certificate as the one on the OWA server, but it doesn't seem too likely.

See the document "Digital Certificates for ISA Server 2004"
(http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/digitalcertificates.mspx).
Most of the information will be relevant for ISA Server 2000.

--
Nathan Bigman
ISA Server Product Team

Please do not send email directly to this alias. This alias is for newsgroup
purposes only.

This posting is provided "AS IS" with no warranties, and confers no rights.
"2Tian" <cmchong20@xxxxxxxxx> wrote in message
news:O%239gNQbUGHA.2156@xxxxxxxxxxxxxxxxxxxxxxx
Windows server 2003, Exchange 2003, ISA 2000.
I have created a Windows own Certificate in front-end (OWA server).
Internal client users have no problem access OWA via https , but not
external client users. I was told that i have to configure certificate for
ISA 2000 server as well.Can i use the same certificate in front-end or
create a Windows own CA ? What should i do ?
Below is the draft diagram of my network config:

internet-->FW-->DMZ-->ISA2000-->DMZ--->FW--->FE(CA)domain
member--->BE(domain member)




.



Relevant Pages

  • Re: How do I require a client certificate when publishing a Web se
    ... I've exactly the same problem as Bill - ISA returns Error 401 and the HTTP ... I've noticed that in "Choose certificate" dialog there is bad name od the ... ISA server, there is correct name of the certificate in the dialog. ... SSL listener to SSL Client Certificate Authentication, ...
    (microsoft.public.isa.publishing)
  • Re: Publishing SSL Server with certificate on host server
    ... can also install that same certificate on the ISA server? ... I figured publishing the SSL webserver on the proxy and having it ... I'm stopped though at the web listener, ...
    (microsoft.public.isaserver)
  • Unable to redirect requests to SSL port in ISA
    ... HTTP port or SSL port. ... Select to choose the appropriate certificate, ... correct certificate store on the ISA Server computer. ... The ISA Server computer happens to be the system where the certificate ...
    (microsoft.public.isa)
  • Re: Masive access external website app with a single personal certific
    ... identify and authenticate a client) for many different clients, ... ISA server is a security gateway in first place and I do not think that the ... The certificate is common for all my company users. ... the client connects directly to the app website and for sign the ...
    (microsoft.public.isa)
  • RE: Security Alert
    ... How can I do a separete certificate for ISA? ... > I have a OWA server behind a ISA server. ... > the site's security certificate - The name on the security certificate is ...
    (microsoft.public.isa.configuration)