Solved

How to setup OWA securely

Posted on 2007-11-27
9
232 Views
Last Modified: 2010-03-06
Hi
i have exchange 2003 and OWA works internally using http. i want to set it up to work externally using https. how do i do this??? i have a checkpoint firewall
0
Comment
Question by:mikeleahy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 20356976
Purchase an SSL certificate - you can get a 30 day trial certificate from RapidSSL.com - they also have instructions on their web site.
Once you have done that, enable forms based authentication on the HTTP protocol under Servers in ESM. Open port 443 on your firewall and ensure that you have a good password policy. Not really a great deal to it.

Simon.
0
 
LVL 31

Expert Comment

by:merowinger
ID: 20356999
Sembee is right....he's always right :)
AddOn: When u have a own certificate authority u can create your own certificate....but its not trusted on each user browsers,
as rapidssl certificates
0
 
LVL 104

Expert Comment

by:Sembee
ID: 20357038
I would not call an OWA deployment using a self or home generated SSL certificate secure.

Simon.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 31

Expert Comment

by:merowinger
ID: 20357053
yes its not the best solution, but you dont have to pay something!
0
 

Author Comment

by:mikeleahy
ID: 20357054
is it secure using a 3rd party cert?? how do i enable forms based authentication on the http protocol . i have only 1 exchange server
0
 
LVL 104

Expert Comment

by:Sembee
ID: 20357062
When you can get SSL certificates for US$20 a year, the "savings" of a home grown certificate become noting, once you have trained your staff to accept the SSL certificate and worried about the fall out from the security warnings. A commercial SSL certificate does not have that problem. It also looks more professional.

I gave you the path to forms based authentication in ESM. You simply enable the option.

Simon.
0
 

Author Comment

by:mikeleahy
ID: 20993497
what cert would do for me i.e. rapidssl, rapidssl wildcard or rapidssl + platinum support.

i have enabled forms based support in ESM. does the certificate have to be installed on each laptop or whats the story ? if forms are enabled, and a cert is on the pc and port is opened then all they have to do is open https:\\mail.xxx.ie\exchange

am i correct

0
 
LVL 104

Accepted Solution

by:
Sembee earned 125 total points
ID: 20997186
A standard SSL certificate will be fine - so a standard RapidSSL certificate will be fine. If you purchase a commercial trusted SSL certificate then you don't have to install the certificate on to every device - that is part off the point.

Simon.
0
 

Author Comment

by:mikeleahy
ID: 21548248
worked great. thanks
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question