Question

OWA Prompts for Login Twice

Asked by: PDiddyHix

I am logging into OWA on my Exchange 2007 server and it is working...however, it is asking for me to login twice.  The first page looks like the ISA Server form and the second looks like the Exchange OWA form.  I am guessing that something is wrong with ISA passing the Auth to Exchange but I am not sure exactly where it is breaking down.  In ISA, under Auth Delegation it is set to "No Auth - but the client can Auth Directly" and in the listener, it is set to HTML form Authentication with Windows (AD) selected below that.  Any advice?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-16 at 00:08:07ID24735458
Tags

ISA Server 2006

,

Exchange 2007

Topics

MS Forefront-ISA

,

Exchange Email Server

Participating Experts
3
Points
500
Comments
57

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. OWA requires client authentication twice
    I'm running OWA in IIS 5.1 w/ Exchange 2000 on Win2k Server. Yesterday I ran the IIS Lockdown Tool and messed up my OWA (not a single mention in the interface about SSL, but it destroyed my SSL settings nevertheless). I have seen both of the following KB articles: 327843 32...
  2. exchange 2003 owa prompts twice for username and p…
    we are using exchange 2003 and we have enabled owa. when a user was inside our network it would not ask for a password, it would open the mailbox of the person that was logged in to the computer. when a user was outside the network, it would prompt for the username and passow...
  3. Exchange 2007 OWA published through ISA 2006, …
    Hopefully somebody here has come across this problem or can throw some light on it for me. I've got an ISA 2006 server in a workgroup in the DMZ. I also have an Exchange 2007 server on the LAN. Using the wizard in ISA and some Microsoft guides I have OWA published through ...
  4. OWA requires authentication twice
    We recently enabled SSL and Forms Based Authentication. FBA is published on ISA. Internally it is secure but does not use the FBA page. However occasionally you are required to authenticate twice. Also when accessing externally you occasionally have to authenticate on the ol...
  5. Login twice when access OWA
    Hi I have one exchange server called exchange1 running Exchange 2000. Currently it hosts all the mail stores and OWA. We are planning to install an additional exchange 2003 server and move half of users on it. I installed a test machine to take this role. Users are able to op...
  6. Sharepoint and Exchange 2007 OWA have to login twice
    I have store registers which are running on Windows XP Pro. The registers are domain joined and all log in using the same AD account. Each store has its own separate AD account which they use to access Sharepoint. Inside Sharepoint the stores access OWA using the same acco...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: ahmedabdelbasetPosted on 2009-09-16 at 00:21:42ID: 25342782

Hi,
    Use basic authentication/integrated  on Exchange server and Form based on ISA server .

 

by: PDiddyHixPosted on 2009-09-16 at 00:26:47ID: 25342810

Maybe I am missing something but I think this is what I already have in place...  Basic and Windows are enabled in IIS on the OWA directory.

 

by: demazterPosted on 2009-09-16 at 00:27:13ID: 25342815

In exchange management console under server configuration right click the owa virtual directory and make sure integrated authentication is enabled and forms based authentication is turned off

 

by: PDiddyHixPosted on 2009-09-16 at 00:48:43ID: 25342933

I turned off Forms based login on the OWA server and that didn't work.  It prompted for my username and password again in a Windows Login Box.

 

by: PDiddyHixPosted on 2009-09-16 at 00:49:24ID: 25342937

Also...I checked out the other question and that didn't seem to work either.  I am going directly to the HTTPS site...

 

by: saakar_raoPosted on 2009-09-16 at 01:18:35ID: 25343106

Make sure that you have FBA enabled on any one of the applications i.e ISA or Exchange, I would recommend to disable it from the ISA server and check

 

by: demazterPosted on 2009-09-16 at 01:18:50ID: 25343107

Can you check in the Exchange Management Console > Server Configuration > Client Access and right click on OWA and select properties.
Check Authentication Make sure Integrated and Basic Authentication is enabled. Windows Authentication will prompt.

 

by: demazterPosted on 2009-09-16 at 01:19:28ID: 25343113

I use ISA to publish my Exchange 2007 and it works fine with the config.

 

by: ahmedabdelbasetPosted on 2009-09-16 at 01:22:00ID: 25343127

 

by: ahmedabdelbasetPosted on 2009-09-16 at 01:22:44ID: 25343129

please ignore last one.it sent by accedent

 

by: PDiddyHixPosted on 2009-09-16 at 01:36:16ID: 25343228

How do you disable it from the ISA server?

 

by: demazterPosted on 2009-09-16 at 01:44:39ID: 25343278

Are you ISA2006?

There is no need to disable forms based authentication on ISA of you are.

 

by: PDiddyHixPosted on 2009-09-16 at 01:59:30ID: 25343351

Yes...ISA 2006.

 

by: saakar_raoPosted on 2009-09-16 at 02:02:54ID: 25343366

The issue is if you FBA enabled on both Exchange and ISA, to disable FBA on ISA you can goto the OWA listener and disable it from there

 

by: PDiddyHixPosted on 2009-09-16 at 02:05:08ID: 25343376

When I do that, I get a 403 Forbidden Error...

 

by: demazterPosted on 2009-09-16 at 02:05:50ID: 25343384

I use FBA on ISA 2006 with Exchange 2007 and there is no need to disable FBA on ISA just disable it on the Exchange Server.

 

by: PDiddyHixPosted on 2009-09-16 at 02:07:03ID: 25343389

When I disable it on Exchange it prompts a second time for my creditials (not in the form but in a Windows Dialoug)

 

by: ahmedabdelbasetPosted on 2009-09-16 at 02:10:46ID: 25343407

 

by: demazterPosted on 2009-09-16 at 02:16:47ID: 25343450

Can you capture the authentication screen on the OWA directory from the exchange management console and post it?

 

by: PDiddyHixPosted on 2009-09-16 at 02:21:03ID: 25343483

I tried that but it isn't working...

 

by: PDiddyHixPosted on 2009-09-16 at 02:26:02ID: 25343511

See attached...

 

by: ahmedabdelbasetPosted on 2009-09-16 at 02:30:36ID: 25343529

OPEN IIS Console

Expand your "Web Sites"
2) Right click on "OWA" => "Properties" and select the "Directory Security Tab". Click on "Edit" under "Access control and authentication control" (Should be the first box)
3) Make sure ONLY anonymous access is selected.
4) Expand "OWA"virtual directory.
5) Right Click on the "bin" => "Properties" and select "Directory Security" tab. Click on "Edit" under "Access control and authentication control" (Should be the first box)
6) Make sure ONLY anonymous access is selected.

 Let me know what you find and if this helps. You may need to restart IIS after making the changes...

from cmd iisreset

 

by: demazterPosted on 2009-09-16 at 02:37:33ID: 25343572

If youy have been making lots of changes to the directory then you need to restart iis by running the followin:  iisreset

Have you checked those boxes recently?

 

by: demazterPosted on 2009-09-16 at 02:38:25ID: 25343581

If it's a default installation then there should be no need to change IIS settings.

 

by: PDiddyHixPosted on 2009-09-16 at 05:29:46ID: 25344826

I am running IIS on Windows Server 2008.  I don't see a properties on the OWA directory... and I did an IISReset after every change.

 

by: demazterPosted on 2009-09-16 at 05:45:35ID: 25344956

is this your only exchange server?

 

by: PDiddyHixPosted on 2009-09-16 at 05:48:19ID: 25344979

Not sure if this makes a difference but I acctually have another ISA Server and another Exchange server in another site on another IP address.  It is working fine.  This one, for some reason, has all the same settings (that I can tell) (I moved my Exchange Server back to forms based Auth since that is what the one that is working is as well) but it is prompting for two loggins.  Something have to be different.

 

by: ahmedabdelbasetPosted on 2009-09-16 at 05:51:46ID: 25345015

Okay, I suggest to restart exchange and isa server and check .

 

by: demazterPosted on 2009-09-16 at 05:52:37ID: 25345018

Is the mailbox you are trying to access by any chance on the other exchange server?

 

by: PDiddyHixPosted on 2009-09-16 at 05:54:35ID: 25345036

No...the mailbox is on the server I am going to.  I am having an issue where the CAS server is not working so I can't get to mailboxes on the other servers.  But if I go to the external URL associated with the ISA / Exchange config, it works.  I just have to log in twice on the one pair that I am trying to fix.

 

by: demazterPosted on 2009-09-16 at 05:58:44ID: 25345067

Tha CAS server cannot have a mailbox role, if it does (without very carefull planning) it will not proxy mailbox roles.

Interestingly my configuration is ISA server > CAS Server > 2 Mailbox Servers

 

by: PDiddyHixPosted on 2009-09-16 at 06:08:11ID: 25345141

I rebooted both servers and it is still not working...

 

by: demazterPosted on 2009-09-16 at 06:09:58ID: 25345154

Do you have a seperate CAS server?
Does this server have a mailbox store on it?

 

by: PDiddyHixPosted on 2009-09-16 at 06:11:35ID: 25345171

No...the server I am hitting is the CAS and Mailbox server...

Looking deeper into one of the posts, it looks like I need to setup the external name in the Hosts file on my ISA server.  Maybe that will resolve it?

 

by: ahmedabdelbasetPosted on 2009-09-16 at 06:16:47ID: 25345213

May be and you may add it in OWA publishing rule :

<meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="ProgId" content="Word.Document"><meta name="Generator" content="Microsoft Word 12"><meta name="Originator" content="Microsoft Word 12"><link rel="File-List" href="file:///C:%5CUsers%5CAABDEL%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"><!--[if gte mso 9]><xml> <o:OfficeDocumentSettings>  <o:RelyOnVML/>  <o:AllowPNG/> </o:OfficeDocumentSettings></xml><![endif]--><link rel="themeData" href="file:///C:%5CUsers%5CAABDEL%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"><link rel="colorSchemeMapping" href="file:///C:%5CUsers%5CAABDEL%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"><!--[if gte mso 9]><xml> <w:WordDocument>  <w:View>Normal</w:View>  <w:Zoom>0</w:Zoom>  <w:TrackMoves/>  <w:TrackFormatting/>  <w:PunctuationKerning/>  <w:ValidateAgainstSchemas/>  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>  <w:DoNotPromoteQF/>  <w:LidThemeOther>EN-US</w:LidThemeOther>  <w:LidThemeAsian>X-NONE</w:LidThemeAsian>  <w:LidThemeComplexScript>AR-SA</w:LidThemeComplexScript>  <w:Compatibility>   <w:BreakWrappedTables/>   <w:SnapToGridInCell/>   <w:WrapTextWithPunct/>   <w:UseAsianBreakRules/>   <w:DontGrowAutofit/>   <w:SplitPgBreakAndParaMark/>   <w:DontVertAlignCellWithSp/>   <w:DontBreakConstrainedForcedTables/>   <w:DontVertAlignInTxbx/>   <w:Word11KerningPairs/>   <w:CachedColBalance/>   <w:UseFELayout/>  </w:Compatibility>  <m:mathPr>   <m:mathFont m:val="Cambria Math"/>   <m:brkBin m:val="before"/>   <m:brkBinSub m:val="&#45;-"/>   <m:smallFrac m:val="off"/>   <m:dispDef/>   <m:lMargin m:val="0"/>   <m:rMargin m:val="0"/>   <m:defJc m:val="centerGroup"/>   <m:wrapIndent m:val="1440"/>   <m:intLim m:val="subSup"/>   <m:naryLim m:val="undOvr"/>  </m:mathPr></w:WordDocument></xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267">  <w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>  <w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>  <w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/>  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>  <w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>  <w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>  <w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>  <w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/>  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>  <w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>  <w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>  <w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>  <w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>  <w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>  <w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/>  <w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>  <w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>  <w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>  <w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>  <w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>  <w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>  <w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>  <w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>  <w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/>  <w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>  <w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>  <w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>  <w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>  <w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>  <w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>  <w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>  <w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/> </w:LatentStyles></xml><![endif]--><style><!-- /* Font Definitions */ @font-face      {font-family:"Cambria Math";      panose-1:2 4 5 3 5 4 6 3 2 4;      mso-font-charset:0;      mso-generic-font-family:roman;      mso-font-pitch:variable;      mso-font-signature:-1610611985 1107304683 0 0 415 0;}@font-face      {font-family:Verdana;      panose-1:2 11 6 4 3 5 4 4 2 4;      mso-font-charset:0;      mso-generic-font-family:swiss;      mso-font-pitch:variable;      mso-font-signature:-1593833729 1073750107 16 0 415 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal      {mso-style-unhide:no;      mso-style-qformat:yes;      mso-style-parent:"";      margin-top:0cm;      margin-right:0cm;      margin-bottom:10.0pt;      margin-left:0cm;      line-height:115%;      mso-pagination:widow-orphan;      font-size:10.0pt;      mso-bidi-font-size:11.0pt;      font-family:"Verdana","sans-serif";      mso-fareast-font-family:"Times New Roman";      mso-fareast-theme-font:minor-fareast;      mso-bidi-font-family:Arial;      mso-bidi-theme-font:minor-bidi;}.MsoChpDefault      {mso-style-type:export-only;      mso-default-props:yes;      mso-ascii-font-family:Calibri;      mso-ascii-theme-font:minor-latin;      mso-fareast-font-family:"Times New Roman";      mso-fareast-theme-font:minor-fareast;      mso-hansi-font-family:Calibri;      mso-hansi-theme-font:minor-latin;      mso-bidi-font-family:Arial;      mso-bidi-theme-font:minor-bidi;}.MsoPapDefault      {mso-style-type:export-only;      margin-bottom:10.0pt;      line-height:115%;}@page Section1      {size:612.0pt 792.0pt;      margin:72.0pt 90.0pt 72.0pt 90.0pt;      mso-header-margin:36.0pt;      mso-footer-margin:36.0pt;      mso-paper-source:0;}div.Section1      {page:Section1;}--</style>Note: If you cannot properly resolve the internal site name, you can select Usea computer name or IP address to connect to the published server, and thentype the required IP address or name that is resolvable by the ISA Servercomputer.


 

by: PDiddyHixPosted on 2009-09-16 at 06:19:22ID: 25345233

OK...I may need some help understanding what that last post is and what I do with it.

 

by: PDiddyHixPosted on 2009-09-16 at 06:19:53ID: 25345239

Also...I updated the Hosts file and it still isn't working.

 

by: ahmedabdelbasetPosted on 2009-09-16 at 06:20:48ID: 25345249

Sorry for that ,

I mean ISA cannot properly resolve the internal site name, you can select Usea computer name or IP address to connect to the published server, and then type the required IP address or name that is resolvable by the ISA Server computer. in OWA publishing rule.

 

by: demazterPosted on 2009-09-16 at 06:22:55ID: 25345277

I think it is more related to the CAS & Mailbox being on the same server?

 

by: PDiddyHixPosted on 2009-09-16 at 06:23:24ID: 25345284

I think I already had that setup that way (in the publishing rule).  I just saw in a post that someone put the external name in the hosts file anyway.  Not sure why...

 

by: PDiddyHixPosted on 2009-09-16 at 06:27:52ID: 25345324

So can I make this server a CAS only or Mailbox only server without completely rebuilding it?

 

by: demazterPosted on 2009-09-16 at 06:29:47ID: 25345347

You can remove roles without rebuilding. http://technet.microsoft.com/en-us/library/bb124115.aspx
If it's a mailbox server I would suggest removing the CAS role and creating a new server with the CAS role only and then publish this with ISA

 

by: ahmedabdelbasetPosted on 2009-09-16 at 06:30:43ID: 25345354

please

What happens when you do this:

 Test-OwaConnectivity URL https://url.com/owa -MailboxCredential (Get-Credential domain\user) -TrustAnySSLCertificate -Verbose

and


Test-WebServicesConnectivity MailboxCredential (Get-Credential domain\user) -TrustAnySSLCertificate

 

by: ahmedabdelbasetPosted on 2009-09-16 at 06:32:40ID: 25345377

I have more time CAS with Mailbox and it works fine.

try to enable listener for internal network and add (A) record in internal DNS to much public name mail.test.com like internal and see .

 

by: saakar_raoPosted on 2009-09-16 at 13:58:53ID: 25350068

+ The mailbox that we are trying to access is that a E2K3 mailbox?
+ When we try to browse OWA do we use /owa or /exchange to browse?
+ FBA should be enabled on any one of the servers ISA/E2K7
+ Do you have any E2K3 servers in your ORG??
+ If yes, check with the authentication setting for ExchWeb as well it should be Anonymous

Please check with the above questions and let us know

 

by: PDiddyHixPosted on 2009-09-16 at 17:06:28ID: 25351627

Does this tell you anything:


[PS] C:\Windows\System32> Test-OwaConnectivity https://tismail.ldichina.com/owa
-MailboxCredential (Get-Credential ldi\test1) -TrustAnySSLCertificate -Verbose
VERBOSE: Test-OwaConnectivity : Beginning processing.
VERBOSE: The TrustAnySSLCertificate flag has been set. The task will not verify
that the server certificate is valid before it sends the user requests and
credentials to this server.
User credentials will be used for user: ldi\test1
Do you want to test Outlook Web Access connectivity on Client Access server
LDI-MSG-02.LDi.LDiChina.com?
VERBOSE: Test-OwaConnectivity : The Test-OwaConnectivity cmdlet is adding the
test instance for URL 'https://tismail.ldichina.com/owa' specified with the
-URL argument.
VERBOSE: Test-OwaConnectivity : Starting test. Target URL =
'https://tismail.ldichina.com/owa/'.
VERBOSE: Test-OwaConnectivity : The TrustAnySSLCertificate flag was specified.
Therefore, any certificate will be trusted.
VERBOSE: Test-OwaConnectivity : The Test-OwaConnectivity cmdlet is sending an
HTTP GET logon request without credentials for authentication type
verification.
VERBOSE: Test-OwaConnectivity : The HTTP request succeeded with result code 200
(OK).
VERBOSE: Test-OwaConnectivity : The logon page is from Microsoft Internet
Security and Acceleration (ISA) Server, not Outlook Web Access.
VERBOSE: Test-OwaConnectivity : Microsoft Exchange reported that it supports
authentication method FBA.
VERBOSE: Test-OwaConnectivity : This virtual directory URL type is External or
Unknown. Therefore, the authentication type will not be checked.
VERBOSE: Test-OwaConnectivity : The Test-OwaConnectivity cmdlet is sending an
HTTP request for logon page
'https://tismail.ldichina.com/CookieAuth.dll?Logon'.
VERBOSE: Test-OwaConnectivity : Trying logon with method 'Fba'.
VERBOSE: Test-OwaConnectivity : The HTTP request succeeded with result code 200
(OK).
WARNING: The test was unable to log on to Outlook Web Access because of an
authentication failure.
WARNING: The test for URL 'https://tismail.ldichina.com/owa/' failed.
WARNING: column "Error" does not fit into the display and was removed.
ClientAccessServer MailboxServer URL                     Scenario Result  Laten
                                                                         cy (m
                                                                         s)
------------------ ------------- ---                     -------- ------  -----
                                https://tismail.ldichin Logon    Skipped -1
                                a.com/owa/
VERBOSE: Test-OwaConnectivity : Ending processing.
 

 

by: PDiddyHixPosted on 2009-09-16 at 23:18:31ID: 25353224

ahmedabdelba -- not sure I understood what you were saying.  I may need more detail.

saakar_rao -

+ The mailbox that we are trying to access is that a E2K3 mailbox? No, everything is Exchange 2007 running on Windows Server 2008 (execpt ISA 2006 running on Windows Server 2003 R2)
+ When we try to browse OWA do we use /owa or /exchange to browse? I have an automatic redirect to /owa.  Either way I access it is the same result.
+ FBA should be enabled on any one of the servers ISA/E2K7 - I think it is enabled on both
+ Do you have any E2K3 servers in your ORG?? - No
+ If yes, check with the authentication setting for ExchWeb as well it should be Anonymous

 

by: PDiddyHixPosted on 2009-09-16 at 23:19:04ID: 25353225

I am starting to process of removing the CAS role from the server and setting up a new CAS server.  We will see if this helps.

 

by: ahmedabdelbasetPosted on 2009-09-16 at 23:23:44ID: 25353249

FBA should be  enabled on one only either ISA or exchange server and other side of both will be basic authentication

 

by: saakar_raoPosted on 2009-09-17 at 00:57:51ID: 25353665

If you have just AIO server and NO exchange 2003 and you are trying to access OWA using /owa and not /exchange then you don't need to have CAS on a different server it is suppose top work.
The only concern that I can find is the FBA enabled on both you just have to make sure that FBA is enabled on one of the servers either ISA or Exchange
Check with Scenario 4 & 5
http://technet.microsoft.com/en-us/library/bb885041.aspx

 

by: PDiddyHixPosted on 2009-09-18 at 00:11:02ID: 25363422

OK...I got it working with FBA on ISA and Basic Auth only on Exchange.  The only problem there is that /exchange /exchweb /public don't work in the rule.  What do I need to change?

 

by: saakar_raoPosted on 2009-09-18 at 00:37:15ID: 25363541

When you will access an Exchange 2007 mailbox using /exchange it will prompt you for password twice, and redirect to /owa. If you have just E2K7 in your domain why you want /exchange to work?? do you have any Entourage clients?? If not then you don't need /exchange.
/exchweb is also a legacy VDIR.
/public >> what is the error that you get when u try to access /public??

 

by: PDiddyHixPosted on 2009-09-18 at 01:22:36ID: 25363738

I do have Entourage Clients...

Public says:

Testing URL https://XXX.XXX.com:443/public/
Category: General error
Error details: The authentication delegation method defined in the rule does not match the authentication method selected for the published directory on the server hosting the site. Publishing rule authentication delegation method: Basic. Published server authentication methods: Forms-Based Authentication.
Action: You can change the authentication method on the published server or select "No delegation, but client may authenticate directly" in the Authentication Delegation tab of the publishing rule.

 

by: saakar_raoPosted on 2009-09-18 at 01:25:36ID: 25363756

Check the below TechNet link
Authentication in ISA Server 2006
http://technet.microsoft.com/en-us/library/bb794722.aspx

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...