Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Self signed certificate

Posted on 2013-06-17
12
346 Views
Last Modified: 2013-07-23
Hi experts

if i generate self assigned certificate from server 2008, will that work for https over proxy service.

If yes kindly send me links to to this task.

Thanks in advance.
Gagan
0
Comment
Question by:GaganRawat
  • 5
  • 3
12 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 39252852
Please Explain.  
Are you looking to setup a proxy for secure connections and would like to use a self-signed certificate to auth the proxy?

Your users will be warned every time they access a secure site they have not added an exception that "a man in the middle" attack is going since the certificate presented by the proxy does not match the URL to which the user is going.
0
 

Author Comment

by:GaganRawat
ID: 39252964
Would like to use a self assigned certificate to auth the proxy.

Thanks
0
 
LVL 77

Expert Comment

by:arnold
ID: 39254709
What do you mean?
You can not proxy secure sites.
are you looking to access your proxy as https://yourownproxy?
In this case, you have to use stunnel and have the self signed certificate on it which will then forward the requests to your squid proxy.

Often, people use certificates to auth clients to the proxy.

http://www.squid-cache.org/mail-archive/squid-users/200310/1013.html
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:GaganRawat
ID: 39255192
in simple language i need my people to stay connected with exchange server even outside the office.
0
 
LVL 77

Assisted Solution

by:arnold
arnold earned 150 total points
ID: 39255229
Opening up a port on your firewall is required unless you have the option to setup VPN connections from each user into your network.

You need to either open your firewall to access OWA's site directly. WAN IP port 443 https://www.yourdomain.com/OWA or a variation there of.

Your other option is to setup a reverse proxy
The reverse proxy will have the certificate for www.yourdomain.com (https://www.yourdomain.com) and the reverse proxy will direct the requests to the internal system where the OWA interface is.
Both provide direct access to the OWA interface, but the reverse proxy provides some "added security" by reducing the attack vector against IIS.

Are you looking to provide users access to the IMAP protocol on your Exchange server remotely?
A reverse proxy on port 143, 993 might be the way to secure those communications.
993 will be either a direct path to exchange or
143 and 993 will be a reverse squid proxy with 993 having a certificate with the requests proxied internaly to port 143 of exchange.
0
 

Author Comment

by:GaganRawat
ID: 39307199
I've requested that this question be deleted for the following reason:

Dont need it any more
0
 
LVL 77

Expert Comment

by:arnold
ID: 39307200
Information and possible implementations included.
0
 
LVL 11

Accepted Solution

by:
NetoMeter Screencasts earned 350 total points
ID: 39321672
I've stumbled upon this post and I am really unpleasantly surprised by the change in the level of the experts - been awhile since posting here (member since 2004).

To start with - Gagan is asking about Rpc over HTTPS (or Outlook Anywhere).

The answers provided:

1. Have nothing to do with the question asked.
2. Are totally misleading and incorrect ex. "You can not proxy secure sites", "provide users access to the IMAP protocol" etc.

The short answer to Gagan's question is - Yes.

When you run the Setup Internet Address wizard, a Certificate is requested and issued by the SBS Certificate Authority. In addition, a certificate package is generated automatically in the Public folder. You need to install this package on the remote clients, before they can start using RPC over HTTP(S).

Best Regards,

:)

PS: Southmod, it would be really nice if you elaborate on the line of thoughts that brought you to this remarkable conclusion "It would seem that you have been given valid suggestions and advice".
0
 
LVL 77

Expert Comment

by:arnold
ID: 39342799
Each person approaches a question in different ways. As NetoMeter pointed out a direct answer of yes provides a limited set of info in my opinion.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question