Solved

Accepting Exchange 2010 ActiveSync Basic Authentication OR Certificate Based Authentication

Posted on 2013-11-29
4
1,199 Views
Last Modified: 2013-11-29
Hey,

I would like to implement Exchange 2010 EAS Certificate Based Authentication along with still being able to use Basic Authentication. Reason being is we are testing CBA and a small subset of people will use it at first.  When configure CBA, Certificates need to be set to accept or require in the EAS properties of the CAS server along with unchecking Basic Authentication which would prohibit EAS from accepting the basic usernames and passwords. What is the best way of me trying to accomplish having both authentication methods work?  Would I need a second ActiveSync virtual directory, one with a URL pointing the virtual directory that accepts BASIC authenticaiton, and another URL pointing to a second virtual direction that accepts Certificates only?
0
Comment
Question by:digitalhitman00
  • 2
  • 2
4 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39685668
That is probably the only way you can do it.
You can only ignore or accept client certificates.

You would need two web sites, two host names. The one with basic authentication should be left on the default web site.

However clients would need to be configured manually because you have no way of telling Exchange which clients use which address.

Simon.
0
 

Author Comment

by:digitalhitman00
ID: 39685784
Ok,  I just tried creating a second EAS website, but it yelled at me.  I tried running:

New-ActiveSyncVirtualDirectory -websiteName "EAS CBA" - Error: The web site doesnt Exist.
New-ActiveSyncVirtualDirectory  - Error, the AD Configuration for virtual directory 'Microsoft-Server-ActiveSync' already exists, please fremote this AD config manually.

I saw this listed: Only one Exchange ActiveSync virtual directory can exist in each Exchange ActiveSync website. Microsoft Site

Any ideas on adding a second eas instance on a computer that already has a first one?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39685793
I presume you have created the web site in IIS manager? Did you run IISRESET after doing so?

Is the name of the site exactly as you have put in the command?

You can only have one ActiveSync virtual directory per web site, but you can multiple web sites on the server.

Simon.
0
 

Author Comment

by:digitalhitman00
ID: 39685822
Ah, no I did not.  Ok I have to create a completely second website outside of the Default.  I think I get it now. let me try.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now