How to publish Outlook Anywhere 2007 using TMG 2010 ?
Hi All,
I'm having problem in publishing the Outlook Anywhere on my Exchange Server 2007 SP1 with TMG 2010 Standard
The error log:
Checking the IIS configuration for client certificate authentication. Client certificate authentication was detected. AdditionalDetails [b]Accept/Require client certificates were found. Set the IIS configuration to Ignore Client Certificates if you aren't using this type of authentication[/b].
In my current setting (see the attached powersheel result)
I have successfully published Exchange Activesync using TMG 2010 externally by using KCD security single Publishing rule and Single Listener (Activesync only because my TMG 2010 only have one NIC attached) and the Exchange Server 2007 CAS is the same machine of course.
I can't add another listener to the publishing rule just for Outlook Anywhere.
Any help and guidance will be greatly appreciated.
please go to testexchangeconnectivity.com and run an outlook anywhere test and give me the errors please
Akhater
i also just noticed you have ssl offloading set to true ! Do you have an ssl hardware solution ? if not this should be set to false on your cas servers
jjoz
ASKER
implementation due to the security issue as well. Outlook Anywhere cannot be enabled just for select few people, it will be enabled for the whole mailbox users, I just realized that I must use certificate that I generated from the self signed / my domain CA, so I guess that is the reason it failed in the "testexchangeconnectivity.com" ? because that website doesn't have my certificate ? cmiiw ?
ssl offloading --> no I use TMG 2010 can that be SSL accelerator ?
You mean you have your exchange running on self signed certificates ?
nop this cannot be an SSL accelerator turn these off
jjoz
ASKER
'You mean you have your exchange running on self signed certificates ?"
no my Exchange uses 3rd party trusted SSL SAN certs. but for the people to have access into Activesync I must issue self signed cert.
I wonder if OA can work with this type of security implementation.
oh.. so TMG 2010 is not SSL Offloading device / server ?
OK, I'll uncheck that from my CAS server option.
Akhater
i still don't get it !
What do you mean by
>>no my Exchange uses 3rd party trusted SSL SAN certs. but for the people to have access into Activesync I must issue self signed cert.<<
you are issuing client certificates for the activesync devices ??
what errors did testexchangeconnectivity give you ?
Many thanks for the reply Akhater, I have created my user certificate (from the internal CA server in my domain) and imported to the User certificate in the MMC console, however in my PC outlook 2007, when I select the certificate from dropdown it always failed ?
as well as typing DOMAIN\myusername also failed to connect (same as in the website too), I am under the imporession that the websitefailed is of course legitimate error and that is expected since the testexchangeconnectivity.com doesn't have my username certificate, that is why it failed.
jjoz
ASKER
from my laptop: https://server.domain.com/RPC --> result timed out ? no response back
from the TMG 2010 standard server: https://server.domain.com/RPC --> continuously prompted for credentials and then when I press ESC button, it failed with 401 ?
from the Exchange server CAS role itself: https://server.domain.com/RPC --> Page Cannot be Displayed 404 ?
from the external internet: https://Activesync.domain.com/RPC --> I got prompted for credentials and then You do not have permission to view this directory or page.
Akhater
I have to say you lost me !
1. I thought you said that ActiveSync was working
2. in all your config you have given me above where did you set the "require certificates" part ? how are you using these client certificates ? in your config all the virtual direcotries have the client certificate set to ignore
3. testexchangeconnectivity is failing oon which step and what is the error
1. yes Activesync is working since last year I deployed and never got into problem, the only problem here is the OA
2."require certificates" part ? --> that is why I don't know where to look for since I'm not the one who setup the Exchange Server and TMG initially (the person has left the company).
3.Test Exchange website failed because in this case it doesn't have the certificate that is issued by my AD-CA to identify me as the user of my company domain, the SSL SAN cert. has been installed successfully for Activesync and to certify the Exchange Servers + my Autodiscover domain.
Akhater
and you are totally sure that the activesync will not work without certificate ? with this config I doubt they are being used
you pointed on the IIS config but I see you have 2 CAS servers is it the same on both ?
if you don't mind I have a way to contact me in my profile can you send me a test user / pass so i can do some tests from my side ?
jjoz
ASKER
Hi, sorry for the delay, I was off the office during my weekend.
unfortunately I'm not allowed to disclose that Akhater, but thanks for your willingness to help so far.
so in this case my goal here is impossible since I want to use User generated certificate (User certificate) from Internal CA so that the user can just select the certificate from the drop down list rather than typing the password ?
Thanks for your help Akhater, the management has voted to roll back the changes now since the user gets random credentials pop up with Autodiscover issue in the entire world.