OWA HTTPS redirection

Posted on 2004-08-10
Last Modified: 2007-12-19
I am following KB article 839357 to redirect http: to
https: for OWA access. I have also setup a URL redirection
on the Defualt Web site to redirect to Exchange so the
users need only type the OWA URL (
without the \exchange to access OWA as IIS is dedicated
to this purpose.  The problem is the Https redirection
does not work with this configuration.  If I type the url
with the \exchange I am redirected properly, but typing
the URL only with the URL redirection configured it does
not work.  Hope this makes sense.  Any help would be
appreciated. Thanks, Doug
Question by:dhlemasurier
  • 5
  • 3
  • 2

Accepted Solution

bgoins earned 250 total points
ID: 11765926
If you are using Exchange 2003 this might help:;en-us;555053

Good luck
LVL 12

Expert Comment

ID: 11767618
Redirect an HTTP connection to HTTPS for Outlook Web Access (OWA) in Exchange 2003 Server;en-us;555126

Microsoft recommends that you require a Secure Sockets Layer (SSL) connection for your Outlook Web Access users to encrypt the information that is sent to or received from Microsoft Exchange 2003 Server.
When you configure IIS 6.0 (Windows 2003 Server) to require SSL for all incoming Outlook Web Access requests, Outlook Web Access users who try to connect by using HTTP receive the following error message:
HTTP 403.4 - Forbidden: SSL required Internet Information Services.
Some administrators may want to have this accomplished automatically for the user so that any time a request comes in using HTTP://, it is redirected to HTTPS:// automatically. This eliminates any user interaction for the client and verifies that all incoming connections are SSL enabled.
This article explains how to implement this solution with IIS 6.0 and OWA 2003 with little to no impact on the user experience and server.

After receiving the error message, the Outlook Web Access user must manually type HTTPS://at the beginning of the URL to connect to the Exchange 2003 computer.

To configure IIS 6.0 to automatically redirect HTTP requests as HTTPS requests, follow these steps:
1. create OWAasp directory under Inetpub\Wwwroot directory.
2. Create an ASP page named Owahttps.asp that contains the following data, and then save the file at Inetpub\Wwwroot\OWAasp directory:
<%     If Request.ServerVariables("SERVER_PORT")=80 Then         Dim strSecureURL         strSecureURL = "https://"         strSecureURL = strSecureURL & Request.ServerVariables("SERVER_NAME")         strSecureURL = strSecureURL & "/exchange"         Response.Redirect strSecureURL     End If   %>
NOTE: Do not replaceSERVER_PORT and SERVER_NAME in the code. They are variables and the code snippet should be copy/pasted as it is shown without modification.
3. Start Internet Services Manager.
4. Expand Computer Name, and then expand the Web site that your Outlook Web Access users use to access Exchange 2003.
    For example, expand Web Sites.
5. Right-click this Web site, point to New, and then click Virtual Directory.
6. Click Next, type OWA_Redirect in the Alias box, and then click Next.
7. In the Directory box, click Browse and point to c:\inetpub\wwwroot\owaasp.
8. Click Next, leave the default check boxes selected on the Access Permissions page, click Next, and then click Finish.
9. Right-click the Exchange virtual directory, and then click Properties.
10. Click the Custom Errors tab, and then double-click 403.4.
11. In the Message Type list, click URL.
12. In the URL box, type /owa_redirect/owahttps.asp, and then click OK.
13. Click the Directory Security tab.
14. Under Secure Communications, click Edit.
15. Click to select the Require secure channel (SSL) check box.
Note If you want to require 128-bit encryption, click to select the Require 128-bit encryption check box.
16. Click OK two times.
Note The Exchange virtual directory and the Public virtual directory are the only virtual directories that you have to configure to require SSL. If you have other virtual directories where you want to require SSL, enable SSL on each virtual directory individually.To allow an initial HTTP request from an Outlook Web Access user, make sure that you do not require SSL on the OWA_Redirect IIS virtual directory. If you require SSL on the OWA_Redirect Virtual directory, the initial HTTP connection cannot be established. Additionally, do not require SSL on the root Web site that contains the OWA_Redirect application.
17. Right-click the OWA_Redirect IIS virtual directory and then click Properties.
18. On the bottom, under the Application Pool, choose ExchangeApplicationPool.
19. Restart the server, or restart the IIS Admin Service. To restart the IIS Admin Service:
20. Click Start, click Run, type services.msc in the Open box, and then click OK.
21. In the list of services, right-click IIS Admin Service, and then click Restart.
22. Click Yes to confirm that you want to restart all the dependent services.
23. Test for functionality.

Author Comment

ID: 11771538
Thanks for the responses.

I have tried 555126 kb article and am getting the same results, the https edirection works fine if I do not redirect all requests to the /excnage directory.

I tried following the 555053 kb article this morning and am stuck on Step 8.  Sorry for the ignorance, but it says in "IIS admin" go to the properties of the owasp folder.....  What/Where is IIS admin?  I do not see the folder in IIS Manager.

Thanks again, Doug
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Expert Comment

ID: 11771838
IIS admin is the same thing as IIS Manager.  You should see that owasp folder you created in there.


Author Comment

ID: 11772186
OK I was able to make the changes in Step 8.  Now when I hit the URL i get a page with the word "redirect".  I checked steps 3 and 4 and all looks OK.  Is step 3 correct the redirect.htm file just has the word redirect in it?


Expert Comment

ID: 11772906
Yes, I think this is the most important part though:

Save the file with the name redirect.htm into the default web site directory.  Now go to the properties of this file from within IIS Manager, and under the option The content for this resource should come from: choose A redirection to a URL.  In the redirect to: box that is now able to be filled it, type /exchange


Expert Comment

ID: 11772923
This is also important:

*Note:  If you have additional content on the default web site of your Exchange server and/or host other websites, be aware that after completing this step, requests to the default website will result in automatic redirection to the /exchange virtual directory.  Make sure that you understand the impact of this change.


Author Comment

ID: 11773269
OK I got it working now.  I cleared the temporary files/history and it worked.  

Thanks for the assistance!

LVL 12

Expert Comment

ID: 11773434
Very nice ... Congrats!

You might want to check out a few of these links now that you have it up and running -

Expert Comment

ID: 11773483
Glad to help and glad it is working!


Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to:…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question