Re: getting confused with OWA and ISA 2006 over SSL



For anyone who has this issue in the future and has tried just about
everything else then the solution was ...

rather than export the certificate from IIS 6.0 (which gave me no export
options), I exported the certificate from the MMC snap in which then allowed
me to select 'Include all certificates in the certification path if
possible'. I then imported that one onto the ISA 2006 machine into its
personal cert store and trusted root certification authorities store and
then voila it all started working \o/

"Alex" <nospam@xxxxxxxxx> wrote in message
news:uou%23x8p8GHA.3264@xxxxxxxxxxxxxxxxxxxxxxx
All servers are windows 2003. I have an exchange 2003 server as the
backend server but I'm currently playing around trying to connect to an
Exchange 2003 front end server on SSL. I am using ISA 2006.

I've got a (trial) certificate from Verisign for my front end exchange
server and have it installed. internally on my LAN going to
https://exchangeserver/exchange works as expected.

I've exported the certificate from the front end exchange server to a pfx
file and used the mmc snap in on my ISA 2006 server to import it into the
local computer (personal).

I've created a SSL Listener and been able to select the certificate.

I've then used the OWA 2006 wizard to create a new Exchange Publishing
rule for Outlook Web Access selecting the option 'Use SSL to connect to
the published Web server or server farm' so (I think I'm correct) that
it's SSL from the client to the ISA server to the Front end Exchange
server.

Then on a client machine I connect to the https url for web mail and after
providing my outlook username and password for the HTML form the ISA 2006
server gives me it gives me a 'the page cannot be displayed' error;

Error Code: 500 Internal Server Error. The certificate chain was issued by
an authority that is not trusted. (-2146893019)

NB When I first goto my OWA url it comes up with a Security Alert saying
'This security certificate was issued by a company you have not chosen to
trust. View the certificate to determine whether you want to trust the
certifying authority.' but I can view and and chose to install it and this
doesn't help in any way :/


If I try a different approach and create a OWA connection using HTTP and
my SSL listener with the certificate installed (i.e. client to the ISA
2006 server is SSL but the connection from ISA 2006 to the Exchange server
is not) then it appears to work just fine.


Where am I going wrong? Do I even need to go SSL all that way (I want to
be able to enable change passwords in OWA)?



.



Relevant Pages

  • Re: SharePoint 3.0: problems with external access
    ... Here are the steps to publish a WSS 3.0 application behind ISA Server. ... Let's assume that you created a new WSS 3.0 application, that listens to port 80, and the host header is 'Intranet'. ... Go to IIS Manager and make sure that the IP address of the site is set to the IP address of the server. ... Run the wizard to create a new SSL certificate for the site. ...
    (microsoft.public.windows.server.sbs)
  • RE: SSL MITM not on port 443
    ... Have you ever done what you're trying to do on a "normal" SSL web ... My recommendation would be to set up a web server in your lab ... hopes that the client will accept that certificate. ... SSL MITM not on port 443 ...
    (Pen-Test)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... If the Exchange 2007 box is hosting mailboxes, it won't work as a front-end equivalent. ... We are making this a virtual server and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)

Loading