Solved

How to improve security to my IIS and Exchange folders?

Posted on 2006-07-13
2
759 Views
Last Modified: 2012-06-21
Hi,

I have been modifying a lot of things and permissions trying to configure correctly OWA with SSL, OMA, and Microsoft-Active-Sync for PDAs, etc... Even I have modified some root properties today by error and obviously it affects of all the rest of the folders. I am worried about it and I would like to learn some basic "must to know" about this secure procedures. I would like to secure these folders of my IIS server.

I only want to allow OWA access (SSL), OMA Access (to one PDA without SSL support) I know that each service requires a default properties, but I would like to find a all-in-one, able and secure way... Anyone could help or recommend me a basic things to know about this? I have all these options but I am not sure at all if these are correct or huge unsecure...

/root default server: Anonymous and basic ONLY + SSL require
/exadmin: Integrated ONLY + SSL require
/exchange: Integrated and Basic ONLY + SSL require
/exchweb: Anonymous ONLY + SSL require
/Microsoft-Server-ActiveSync: Integrated and Basic ONLY (no SSL)
/OMA: Basic ONLY (no SSL)
/rpc: Integrated and Basic ONLY + SSL require (no SSL)
/rpcwithCert: Integrated and Basic ONLY + SSL require (no SSL)
/certcontrol: Integrated ONLY + SSL require
/certEnroll: Anonymous ONLY + SSL require
/certServ: Integrated ONLY + SSL require
/public: Integrated and Basic ONLY + SSL require
/asp_client

Any web info or recommendations? Thank you very much for this
0
Comment
Question by:isaacmateo
2 Comments
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 17102117
If you have require SSL on the /exchange virtual directory then OMA/EAS will not work.
I don't tend to both with require SSL on any folder in the default web site.

Authentication settings look fine.
You could always reset the whole lot: http://support.microsoft.com/default.aspx?kbid=883380

Simon.
0
 

Author Comment

by:isaacmateo
ID: 17107080
Thanks again Simon. I tried the method 1 of your link and I am feeling better about our security
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange Cluster Requirements 8 35
find the Exchange server name that Outlook is connected to. 6 31
EXCHANGE, OUTLOOK, CALENDAR 12 41
office 365 5 23
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question