Solved

How to setup OWA securely

Posted on 2007-11-27
9
229 Views
Last Modified: 2010-03-06
Hi
i have exchange 2003 and OWA works internally using http. i want to set it up to work externally using https. how do i do this??? i have a checkpoint firewall
0
Comment
Question by:mikeleahy
  • 4
  • 3
  • 2
9 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 20356976
Purchase an SSL certificate - you can get a 30 day trial certificate from RapidSSL.com - they also have instructions on their web site.
Once you have done that, enable forms based authentication on the HTTP protocol under Servers in ESM. Open port 443 on your firewall and ensure that you have a good password policy. Not really a great deal to it.

Simon.
0
 
LVL 31

Expert Comment

by:merowinger
ID: 20356999
Sembee is right....he's always right :)
AddOn: When u have a own certificate authority u can create your own certificate....but its not trusted on each user browsers,
as rapidssl certificates
0
 
LVL 104

Expert Comment

by:Sembee
ID: 20357038
I would not call an OWA deployment using a self or home generated SSL certificate secure.

Simon.
0
 
LVL 31

Expert Comment

by:merowinger
ID: 20357053
yes its not the best solution, but you dont have to pay something!
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Author Comment

by:mikeleahy
ID: 20357054
is it secure using a 3rd party cert?? how do i enable forms based authentication on the http protocol . i have only 1 exchange server
0
 
LVL 104

Expert Comment

by:Sembee
ID: 20357062
When you can get SSL certificates for US$20 a year, the "savings" of a home grown certificate become noting, once you have trained your staff to accept the SSL certificate and worried about the fall out from the security warnings. A commercial SSL certificate does not have that problem. It also looks more professional.

I gave you the path to forms based authentication in ESM. You simply enable the option.

Simon.
0
 

Author Comment

by:mikeleahy
ID: 20993497
what cert would do for me i.e. rapidssl, rapidssl wildcard or rapidssl + platinum support.

i have enabled forms based support in ESM. does the certificate have to be installed on each laptop or whats the story ? if forms are enabled, and a cert is on the pc and port is opened then all they have to do is open https:\\mail.xxx.ie\exchange

am i correct

0
 
LVL 104

Accepted Solution

by:
Sembee earned 125 total points
ID: 20997186
A standard SSL certificate will be fine - so a standard RapidSSL certificate will be fine. If you purchase a commercial trusted SSL certificate then you don't have to install the certificate on to every device - that is part off the point.

Simon.
0
 

Author Comment

by:mikeleahy
ID: 21548248
worked great. thanks
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now