Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Self signed certificate

Posted on 2013-06-17
12
Medium Priority
?
351 Views
Last Modified: 2013-07-23
Hi experts

if i generate self assigned certificate from server 2008, will that work for https over proxy service.

If yes kindly send me links to to this task.

Thanks in advance.
Gagan
0
Comment
Question by:GaganRawat
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
12 Comments
 
LVL 80

Expert Comment

by:arnold
ID: 39252852
Please Explain.  
Are you looking to setup a proxy for secure connections and would like to use a self-signed certificate to auth the proxy?

Your users will be warned every time they access a secure site they have not added an exception that "a man in the middle" attack is going since the certificate presented by the proxy does not match the URL to which the user is going.
0
 

Author Comment

by:GaganRawat
ID: 39252964
Would like to use a self assigned certificate to auth the proxy.

Thanks
0
 
LVL 80

Expert Comment

by:arnold
ID: 39254709
What do you mean?
You can not proxy secure sites.
are you looking to access your proxy as https://yourownproxy?
In this case, you have to use stunnel and have the self signed certificate on it which will then forward the requests to your squid proxy.

Often, people use certificates to auth clients to the proxy.

http://www.squid-cache.org/mail-archive/squid-users/200310/1013.html
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:GaganRawat
ID: 39255192
in simple language i need my people to stay connected with exchange server even outside the office.
0
 
LVL 80

Assisted Solution

by:arnold
arnold earned 600 total points
ID: 39255229
Opening up a port on your firewall is required unless you have the option to setup VPN connections from each user into your network.

You need to either open your firewall to access OWA's site directly. WAN IP port 443 https://www.yourdomain.com/OWA or a variation there of.

Your other option is to setup a reverse proxy
The reverse proxy will have the certificate for www.yourdomain.com (https://www.yourdomain.com) and the reverse proxy will direct the requests to the internal system where the OWA interface is.
Both provide direct access to the OWA interface, but the reverse proxy provides some "added security" by reducing the attack vector against IIS.

Are you looking to provide users access to the IMAP protocol on your Exchange server remotely?
A reverse proxy on port 143, 993 might be the way to secure those communications.
993 will be either a direct path to exchange or
143 and 993 will be a reverse squid proxy with 993 having a certificate with the requests proxied internaly to port 143 of exchange.
0
 

Author Comment

by:GaganRawat
ID: 39307199
I've requested that this question be deleted for the following reason:

Dont need it any more
0
 
LVL 80

Expert Comment

by:arnold
ID: 39307200
Information and possible implementations included.
0
 
LVL 11

Accepted Solution

by:
NetoMeter Screencasts earned 1400 total points
ID: 39321672
I've stumbled upon this post and I am really unpleasantly surprised by the change in the level of the experts - been awhile since posting here (member since 2004).

To start with - Gagan is asking about Rpc over HTTPS (or Outlook Anywhere).

The answers provided:

1. Have nothing to do with the question asked.
2. Are totally misleading and incorrect ex. "You can not proxy secure sites", "provide users access to the IMAP protocol" etc.

The short answer to Gagan's question is - Yes.

When you run the Setup Internet Address wizard, a Certificate is requested and issued by the SBS Certificate Authority. In addition, a certificate package is generated automatically in the Public folder. You need to install this package on the remote clients, before they can start using RPC over HTTP(S).

Best Regards,

:)

PS: Southmod, it would be really nice if you elaborate on the line of thoughts that brought you to this remarkable conclusion "It would seem that you have been given valid suggestions and advice".
0
 
LVL 80

Expert Comment

by:arnold
ID: 39342799
Each person approaches a question in different ways. As NetoMeter pointed out a direct answer of yes provides a limited set of info in my opinion.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever visit a website where you spotted a really cool looking Font, yet couldn't figure out which font family it belonged to, or how to get a copy of it for your own use? This article explains the process of doing exactly that, as well as showing how…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question