Re: Pre-Authentication on a Secure Web publishing Rule using Clien

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Have a read in the ISA help and here:
http://www.microsoft.com/technet/isa/2006/authentication.mspx
for "certificate authentication".

ISA *MUST* be a domain member in order for cert auth to work.

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.



"Navi" <Navi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E835FE5C-415C-43E6-A88C-88291C1E97AC@xxxxxxxxxxxxxxxx
Thank you for your reply Jim.

We are currently trying to implment cert-based auth just at the ISA server
and seem to be failing. The ISA is in a workgroup and all the certificates
we
are using are valid, but it still seems to be failing.

Any tips or points we may be overlooking?

Thanks in advance

"Jim Harrison (ISA SE)" wrote:

You cannot perform cert-based authenticate at the ISA and the upstream
server simultaneously.
Cert auth will be limited to ISA (ok for web publishing) or the server
itself (server publishing).
--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.



"Navi" <Navi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:931E4C28-3323-4F6C-892C-7B9D27DCAF79@xxxxxxxxxxxxxxxx
Afternoon all,

I know its a hell of a long subject title but i can't seem to get this to
work!

The problem is we have a standalone ISA 2004 box publishing a website from
a
standalone IIS 6 standalone machine, both these machines use
client/server
certificate auth to communicate over SSL. The root standalone CA is in the
same subnet as the IIS machine and communication between the IIS and ISA
machines are fine.

What we are trying to acheive on top of this is pre-authentication between
the internet client and the ISA Server using client/server certificate
Auth.
We have another standalone root CA in the same subnet as the ISA box to
provide for the certificates for the front end certificates.

I hope i haven't lost you with all this but we can't seem to make it work
so
that the ISA requires a valid client certificate before it will forward on
the request to the IIS machine.

We have placed a valid server certificate in the web listener and a valid
CA
and client cert on the client but keep getting authorisation errors. The
back
end of the system work fine but we can't seem to configure the ISA
correctly
to pre-authenticate users.

Any ideas would be greatly appreciated and if you require any more
information or clarification of any of the above please ask away!

Thanks in advance

Navi


.



Relevant Pages

  • Re: SharePoint 3.0: problems with external access
    ... Here are the steps to publish a WSS 3.0 application behind ISA Server. ... Let's assume that you created a new WSS 3.0 application, that listens to port 80, and the host header is 'Intranet'. ... Go to IIS Manager and make sure that the IP address of the site is set to the IP address of the server. ... Run the wizard to create a new SSL certificate for the site. ...
    (microsoft.public.windows.server.sbs)
  • Re: SharePoint 3.0: problems with external access
    ... In one of the tabs of the publishing rule there is an option to set that the requests come from the client and not from the ISA computer. ... Do you have an email address you can post for me to send you some screen shots of my ISA rule and Web Certificate for you to look at. ... When it comes down to selecting the Web Listener, create a new one, using the certificate you just created at port 8889. ... Click on delete pending request and then start the wizard again. ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... If the Exchange 2007 box is hosting mailboxes, it won't work as a front-end equivalent. ... We are making this a virtual server and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: How do I require a client certificate when publishing a Web se
    ... I've exactly the same problem as Bill - ISA returns Error 401 and the HTTP ... I've noticed that in "Choose certificate" dialog there is bad name od the ... ISA server, there is correct name of the certificate in the dialog. ... SSL listener to SSL Client Certificate Authentication, ...
    (microsoft.public.isa.publishing)