?
Solved

How to improve security to my IIS and Exchange folders?

Posted on 2006-07-13
2
Medium Priority
?
761 Views
Last Modified: 2012-06-21
Hi,

I have been modifying a lot of things and permissions trying to configure correctly OWA with SSL, OMA, and Microsoft-Active-Sync for PDAs, etc... Even I have modified some root properties today by error and obviously it affects of all the rest of the folders. I am worried about it and I would like to learn some basic "must to know" about this secure procedures. I would like to secure these folders of my IIS server.

I only want to allow OWA access (SSL), OMA Access (to one PDA without SSL support) I know that each service requires a default properties, but I would like to find a all-in-one, able and secure way... Anyone could help or recommend me a basic things to know about this? I have all these options but I am not sure at all if these are correct or huge unsecure...

/root default server: Anonymous and basic ONLY + SSL require
/exadmin: Integrated ONLY + SSL require
/exchange: Integrated and Basic ONLY + SSL require
/exchweb: Anonymous ONLY + SSL require
/Microsoft-Server-ActiveSync: Integrated and Basic ONLY (no SSL)
/OMA: Basic ONLY (no SSL)
/rpc: Integrated and Basic ONLY + SSL require (no SSL)
/rpcwithCert: Integrated and Basic ONLY + SSL require (no SSL)
/certcontrol: Integrated ONLY + SSL require
/certEnroll: Anonymous ONLY + SSL require
/certServ: Integrated ONLY + SSL require
/public: Integrated and Basic ONLY + SSL require
/asp_client

Any web info or recommendations? Thank you very much for this
0
Comment
Question by:isaacmateo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 104

Accepted Solution

by:
Sembee earned 2000 total points
ID: 17102117
If you have require SSL on the /exchange virtual directory then OMA/EAS will not work.
I don't tend to both with require SSL on any folder in the default web site.

Authentication settings look fine.
You could always reset the whole lot: http://support.microsoft.com/default.aspx?kbid=883380

Simon.
0
 

Author Comment

by:isaacmateo
ID: 17107080
Thanks again Simon. I tried the method 1 of your link and I am feeling better about our security
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question