Solved

Self signed certificate

Posted on 2013-06-17
12
345 Views
Last Modified: 2013-07-23
Hi experts

if i generate self assigned certificate from server 2008, will that work for https over proxy service.

If yes kindly send me links to to this task.

Thanks in advance.
Gagan
0
Comment
Question by:GaganRawat
  • 5
  • 3
12 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 39252852
Please Explain.  
Are you looking to setup a proxy for secure connections and would like to use a self-signed certificate to auth the proxy?

Your users will be warned every time they access a secure site they have not added an exception that "a man in the middle" attack is going since the certificate presented by the proxy does not match the URL to which the user is going.
0
 

Author Comment

by:GaganRawat
ID: 39252964
Would like to use a self assigned certificate to auth the proxy.

Thanks
0
 
LVL 77

Expert Comment

by:arnold
ID: 39254709
What do you mean?
You can not proxy secure sites.
are you looking to access your proxy as https://yourownproxy?
In this case, you have to use stunnel and have the self signed certificate on it which will then forward the requests to your squid proxy.

Often, people use certificates to auth clients to the proxy.

http://www.squid-cache.org/mail-archive/squid-users/200310/1013.html
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 

Author Comment

by:GaganRawat
ID: 39255192
in simple language i need my people to stay connected with exchange server even outside the office.
0
 
LVL 77

Assisted Solution

by:arnold
arnold earned 150 total points
ID: 39255229
Opening up a port on your firewall is required unless you have the option to setup VPN connections from each user into your network.

You need to either open your firewall to access OWA's site directly. WAN IP port 443 https://www.yourdomain.com/OWA or a variation there of.

Your other option is to setup a reverse proxy
The reverse proxy will have the certificate for www.yourdomain.com (https://www.yourdomain.com) and the reverse proxy will direct the requests to the internal system where the OWA interface is.
Both provide direct access to the OWA interface, but the reverse proxy provides some "added security" by reducing the attack vector against IIS.

Are you looking to provide users access to the IMAP protocol on your Exchange server remotely?
A reverse proxy on port 143, 993 might be the way to secure those communications.
993 will be either a direct path to exchange or
143 and 993 will be a reverse squid proxy with 993 having a certificate with the requests proxied internaly to port 143 of exchange.
0
 

Author Comment

by:GaganRawat
ID: 39307199
I've requested that this question be deleted for the following reason:

Dont need it any more
0
 
LVL 77

Expert Comment

by:arnold
ID: 39307200
Information and possible implementations included.
0
 
LVL 11

Accepted Solution

by:
NetoMeter Screencasts earned 350 total points
ID: 39321672
I've stumbled upon this post and I am really unpleasantly surprised by the change in the level of the experts - been awhile since posting here (member since 2004).

To start with - Gagan is asking about Rpc over HTTPS (or Outlook Anywhere).

The answers provided:

1. Have nothing to do with the question asked.
2. Are totally misleading and incorrect ex. "You can not proxy secure sites", "provide users access to the IMAP protocol" etc.

The short answer to Gagan's question is - Yes.

When you run the Setup Internet Address wizard, a Certificate is requested and issued by the SBS Certificate Authority. In addition, a certificate package is generated automatically in the Public folder. You need to install this package on the remote clients, before they can start using RPC over HTTP(S).

Best Regards,

:)

PS: Southmod, it would be really nice if you elaborate on the line of thoughts that brought you to this remarkable conclusion "It would seem that you have been given valid suggestions and advice".
0
 
LVL 77

Expert Comment

by:arnold
ID: 39342799
Each person approaches a question in different ways. As NetoMeter pointed out a direct answer of yes provides a limited set of info in my opinion.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Know what services you can and cannot, should and should not combine on your server.
An article on effective troubleshooting
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question