• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 354
  • Last Modified:

Self signed certificate

Hi experts

if i generate self assigned certificate from server 2008, will that work for https over proxy service.

If yes kindly send me links to to this task.

Thanks in advance.
Gagan
0
GaganRawat
Asked:
GaganRawat
  • 5
  • 3
2 Solutions
 
arnoldCommented:
Please Explain.  
Are you looking to setup a proxy for secure connections and would like to use a self-signed certificate to auth the proxy?

Your users will be warned every time they access a secure site they have not added an exception that "a man in the middle" attack is going since the certificate presented by the proxy does not match the URL to which the user is going.
0
 
GaganRawatAuthor Commented:
Would like to use a self assigned certificate to auth the proxy.

Thanks
0
 
arnoldCommented:
What do you mean?
You can not proxy secure sites.
are you looking to access your proxy as https://yourownproxy?
In this case, you have to use stunnel and have the self signed certificate on it which will then forward the requests to your squid proxy.

Often, people use certificates to auth clients to the proxy.

http://www.squid-cache.org/mail-archive/squid-users/200310/1013.html
0
Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

 
GaganRawatAuthor Commented:
in simple language i need my people to stay connected with exchange server even outside the office.
0
 
arnoldCommented:
Opening up a port on your firewall is required unless you have the option to setup VPN connections from each user into your network.

You need to either open your firewall to access OWA's site directly. WAN IP port 443 https://www.yourdomain.com/OWA or a variation there of.

Your other option is to setup a reverse proxy
The reverse proxy will have the certificate for www.yourdomain.com (https://www.yourdomain.com) and the reverse proxy will direct the requests to the internal system where the OWA interface is.
Both provide direct access to the OWA interface, but the reverse proxy provides some "added security" by reducing the attack vector against IIS.

Are you looking to provide users access to the IMAP protocol on your Exchange server remotely?
A reverse proxy on port 143, 993 might be the way to secure those communications.
993 will be either a direct path to exchange or
143 and 993 will be a reverse squid proxy with 993 having a certificate with the requests proxied internaly to port 143 of exchange.
0
 
GaganRawatAuthor Commented:
I've requested that this question be deleted for the following reason:

Dont need it any more
0
 
arnoldCommented:
Information and possible implementations included.
0
 
NetoMeter ScreencastsCommented:
I've stumbled upon this post and I am really unpleasantly surprised by the change in the level of the experts - been awhile since posting here (member since 2004).

To start with - Gagan is asking about Rpc over HTTPS (or Outlook Anywhere).

The answers provided:

1. Have nothing to do with the question asked.
2. Are totally misleading and incorrect ex. "You can not proxy secure sites", "provide users access to the IMAP protocol" etc.

The short answer to Gagan's question is - Yes.

When you run the Setup Internet Address wizard, a Certificate is requested and issued by the SBS Certificate Authority. In addition, a certificate package is generated automatically in the Public folder. You need to install this package on the remote clients, before they can start using RPC over HTTP(S).

Best Regards,

:)

PS: Southmod, it would be really nice if you elaborate on the line of thoughts that brought you to this remarkable conclusion "It would seem that you have been given valid suggestions and advice".
0
 
arnoldCommented:
Each person approaches a question in different ways. As NetoMeter pointed out a direct answer of yes provides a limited set of info in my opinion.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

  • 5
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now