Re: RSA with OWA and FBA



This might indicate that Microsoft might not be that happy about RSA SecurID
on ISA 2004 to authenticate - before FBA.
At the same time it indicates that they do support it:

http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/unsupportedconfigs.mspx
Troubleshooting Unsupported Configurations in ISA Server 2004
Microsoft Internet Security and Acceleration Server 2004
Published: November 2, 2005
Problem: There are a number of limitations to be aware of when enabling RSA
SecurID authentication on ISA Server:

• When you configure RSA SecurID on a Web publishing rule, no other form of
authentication can be enabled.

• Outlook Web Access cannot be configured to use SecurID credentials. ISA
Server can forward the cookie to the Outlook Web Access server, but the
server will not do anything with it.


Cause: When you publish an Outlook Web Access server and enable RSA SecurID
on ISA Server, with forms-based authentication on the Exchange server, the
following occurs:

• Users will be prompted for an RSA SecurID password and PIN by ISA Server.

• After being authenticated by ISA Server, users will be prompted by
Exchange with the forms-based authentication page.


But maybe it is not that good a combination with 2 cookies.... from the ISA
2004 Help manual:

- On the RSA SecurID tab, verify that Send SecurID cookie to upstream server
is selected.

If you do not select this option, ISA Server removes the SecurID cookie from
the header, and invalid cookies are forwarded to the Outlook Web Access
server that is being published.
When ISA Server is configured to use SecurID authentication, forms-based
authentication will not function as expected, because forms-based
authentication requires its own cookie to identify the client. After the
client successfully authenticates to ISA Server and to the Outlook Web Access
server, Internet Explorer sends both cookies to ISA Server, on the same
cookie header. ISA Server removes the SecurID cookie from the header and
alters the remaining cookies so that they are invalid. The Outlook Web Access
server does not receive the required credentials, and presents the
forms-based authentication form to the client again.



--
LAN Hotfixer


"Henk Steunenberg (Ms)" wrote:

Hello,

isa 2004
only support FBA with exchange and OWA and does not support customizing of
owa and
rsa page.


regards,

Henk Steunenberg

"admin ken" <none@xxxxxxxxxxxxx> wrote in message
news:uraHt$PEGHA.3920@xxxxxxxxxxxxxxxxxxxxxxx
Can the integrated RSA features work with OWA w/ forms based
authentication in ISA 2004?

I know there is an issue with RADIUS and OWA FBA but there is a fix from
Microsoft, I wonder if there is any issue using RSA with OWA and FBA.




.



Relevant Pages

  • Re: RSA with OWA and FBA
    ... So RSA SecurID running on ISA doesn't support SSO. ... Troubleshooting Unsupported Configurations in ISA Server 2004 ... SecurID authentication on ISA Server: ...
    (microsoft.public.isa)
  • Re: ISA2000 + Remote Outlook Web Access (Exchange 2003) - Multiple Login Prompts
    ... It turns out that under the Site and Content rules of my ISA ... If your ISA server is setup that way (as to allow ... specific people or groups access to the internet) it looks like it has ... an authentication layer it examines in the hosts' packets. ...
    (microsoft.public.isaserver)
  • Re: Beginner problems
    ... Be careful with users requiring authentication (rules that specify certain ... corresponding traffic needs to be properly authenticated, in other words ISA ... Firewall Client on the users' workstations, ... > * In which port runs the ISA server? ...
    (microsoft.public.isaserver)
  • Re: How do I require a client certificate when publishing a Web se
    ... I've exactly the same problem as Bill - ISA returns Error 401 and the HTTP ... I've noticed that in "Choose certificate" dialog there is bad name od the ... ISA server, there is correct name of the certificate in the dialog. ... SSL listener to SSL Client Certificate Authentication, ...
    (microsoft.public.isa.publishing)
  • RE: OWA Publishing problem for ISA 2006- using SecurID
    ... They are getting this when connecting from an ISA Server labeled page: ... On the ISA server I did test connectivity to the RSA server using their test ... Authentication Delegation: No delegation, but client may authenticate ...
    (microsoft.public.isa.publishing)