Re: ISA2006 (No SP1) Single NIC Workgroup DMZ Client Certificate Auth



You can't "proxy" a certificate.
You'll have to use Server Publishing for this site if you insist on cert
auth at the web server itself.

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"NTNEWS" <NTNEWS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:01A4D978-A3D2-406D-8B49-68541F9B8039@xxxxxxxxxxxxxxxx
I have an ISA2006 workgroup stand alone computer in my DMZ with a single NIC
to the Internet. Another firewall handles all routing to my internal
network
and I am using the proxy server as a reverse web proxy only. I have hosted
Exchange OWA and many other web sites without issues. I am now trying to
publish a web site that uses a Client Certificate for authorization and
that's it. It works seemlessly from the inside and prompts for which cert to
use in your browser. When I try to publish this through the proxy server, I
cannot make it prompt me for a cert, and only get "HTTP Error 403.7 -
Forbidden: SSL client certificate is required. Internet Information Services
(IIS)". I have the private cert installed in my browser and everything works
fine locally. Is there anything special about letting Client Certificate
Auth through a Web Proxy rule? I am NOT trying to have my proxy server
authenticate the client certificate, but rather the destination web site. I
have "No Delegation allow client to authenticate directly" selected.
Additionally on my Web Listener have "No Authentication" set, such that the
receiving web server can authenticate it. I have tried it with SSL Client
Certificate auth with no success, but my understanding of that is that the
proxy server is the one authenticating the client cert which is not what we
want. I have read mixed reveiws on whether or not this is supported and
that
it may be supported in the new SP1 for ISA2006 especially seeing the setting
I just talked about. Any information on this would be appreciated.

Thanks
NTNEWS

.



Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)