<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Publishing Exchange 2007 Autodisover in ISA 2006</title>
	<atom:link href="http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Fri, 12 Mar 2010 09:57:15 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Outlook 2007 Certificate Error - Persian Networks</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-9691</link>
		<dc:creator>Outlook 2007 Certificate Error - Persian Networks</dc:creator>
		<pubDate>Thu, 25 Feb 2010 12:14:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-9691</guid>
		<description>[...] Communication Certificate. You can read more about these certificates in one of my other articles here. So let’s say we have a simple regular common certificate. A certificate with a Common Name (CN) [...]</description>
		<content:encoded><![CDATA[<p>[...] Communication Certificate. You can read more about these certificates in one of my other articles here. So let’s say we have a simple regular common certificate. A certificate with a Common Name (CN) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fixing outlook certificate errors - The IT Tech-Archive</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-9511</link>
		<dc:creator>Fixing outlook certificate errors - The IT Tech-Archive</dc:creator>
		<pubDate>Fri, 08 Jan 2010 04:29:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-9511</guid>
		<description>[...] Well, when we install a new certificate, there are a few tasks we want to do. Obviously, we install the certificate for a purpose. This purpose is till allow us to use Exchange services securely. So how do we enable Exchange to use these services? If you are planning to do a very simple configuration and do not care about external Autodiscover access, you do not need to use a Unified Communication Certificate. You can read more about these certificates in one of my other articles here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Well, when we install a new certificate, there are a few tasks we want to do. Obviously, we install the certificate for a purpose. This purpose is till allow us to use Exchange services securely. So how do we enable Exchange to use these services? If you are planning to do a very simple configuration and do not care about external Autodiscover access, you do not need to use a Unified Communication Certificate. You can read more about these certificates in one of my other articles here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-7613</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Thu, 06 Aug 2009 22:56:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-7613</guid>
		<description>Depends on the environment.  Take this for example:
You&#039;re using webmail.domain.com.  You don&#039;t have ISA and you&#039;re allowing connections going directly to your Exchange server from the internet.  So your CN on your cert is webmail.domain.com so you change all your InternalURLs for webmail.domain.com.  You have internal machines not domain joined but the internal DHCP gives them internal DNS which is on a DC.  The domain.com DNS is going to be going to your DCs and not your Exchange servers.  It&#039;s this reason alone you should be using autodiscover.domain.com.  That autodiscover will not be going to a DC and you will point it to Exchange.

Anytime you talk autodiscover with people, they just say autodiscover.domain.com.  It appears to be the norm and what I always end up using. 

If you had ISA, you could do what you mention and internally, you could just use a different certificate with autodiscover.domain.com. 

But keep in mind, if you use http://shudnow.net/autodiscover/autodiscover.xml, you&#039;ll need to make sure your certificate can work with just shudnow.net since your certificate will have a CN of webmail.domain.com.

Make sense?</description>
		<content:encoded><![CDATA[<p>Depends on the environment.  Take this for example:<br />
You&#8217;re using webmail.domain.com.  You don&#8217;t have ISA and you&#8217;re allowing connections going directly to your Exchange server from the internet.  So your CN on your cert is webmail.domain.com so you change all your InternalURLs for webmail.domain.com.  You have internal machines not domain joined but the internal DHCP gives them internal DNS which is on a DC.  The domain.com DNS is going to be going to your DCs and not your Exchange servers.  It&#8217;s this reason alone you should be using autodiscover.domain.com.  That autodiscover will not be going to a DC and you will point it to Exchange.</p>
<p>Anytime you talk autodiscover with people, they just say autodiscover.domain.com.  It appears to be the norm and what I always end up using. </p>
<p>If you had ISA, you could do what you mention and internally, you could just use a different certificate with autodiscover.domain.com. </p>
<p>But keep in mind, if you use <a href="http://shudnow.net/autodiscover/autodiscover.xml" rel="nofollow">http://shudnow.net/autodiscover/autodiscover.xml</a>, you&#8217;ll need to make sure your certificate can work with just shudnow.net since your certificate will have a CN of webmail.domain.com.</p>
<p>Make sense?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blake</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-7612</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Thu, 06 Aug 2009 16:34:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-7612</guid>
		<description>I don&#039;t understand... Why can&#039;t you just use one domain name (i.e. shudnow.net) and one cert without the extra SAN&#039;s, and just publish all the services by using the directories for the address. I&#039;ve seen in multiple articles that autodiscover will also check https://shudnow.net/autodiscover/autodiscover.xml (no subdomain there)
So why can&#039;t it just work by publishing the one domain? (no subdomain of autodiscover.shudnow.net)</description>
		<content:encoded><![CDATA[<p>I don&#8217;t understand&#8230; Why can&#8217;t you just use one domain name (i.e. shudnow.net) and one cert without the extra SAN&#8217;s, and just publish all the services by using the directories for the address. I&#8217;ve seen in multiple articles that autodiscover will also check <a href="https://shudnow.net/autodiscover/autodiscover.xml" rel="nofollow">https://shudnow.net/autodiscover/autodiscover.xml</a> (no subdomain there)<br />
So why can&#8217;t it just work by publishing the one domain? (no subdomain of autodiscover.shudnow.net)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saad</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-7389</link>
		<dc:creator>Saad</dc:creator>
		<pubDate>Sat, 18 Jul 2009 01:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-7389</guid>
		<description>that very nice
i&#039;m sorry i have 1 question 
i remove getway from TCP\IP and make instal to outlook 2007 to see our exchange in domain
but never install 
i had masage said &quot; u must have getway to install mail &quot;
what can i do 
some computer don&#039;t have Getway</description>
		<content:encoded><![CDATA[<p>that very nice<br />
i&#8217;m sorry i have 1 question<br />
i remove getway from TCP\IP and make instal to outlook 2007 to see our exchange in domain<br />
but never install<br />
i had masage said &#8221; u must have getway to install mail &#8221;<br />
what can i do<br />
some computer don&#8217;t have Getway</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-6695</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Mon, 06 Apr 2009 14:34:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-6695</guid>
		<description>I&#039;ve published only once since both SP1 for ISA 2006 and Exchange 2007 were out and I did it the same way as I wrote in my article.  However, I have seen others not have to do that such as the following video demonstration:
http://www.pro-exchange.be/modules.php?name=News&amp;file=article&amp;sid=1040</description>
		<content:encoded><![CDATA[<p>I&#8217;ve published only once since both SP1 for ISA 2006 and Exchange 2007 were out and I did it the same way as I wrote in my article.  However, I have seen others not have to do that such as the following video demonstration:<br />
<a href="http://www.pro-exchange.be/modules.php?name=News&#038;file=article&#038;sid=1040" rel="nofollow">http://www.pro-exchange.be/modules.php?name=News&#038;file=article&#038;sid=1040</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Hodgson</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-6694</link>
		<dc:creator>Andrew Hodgson</dc:creator>
		<pubDate>Mon, 06 Apr 2009 08:13:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-6694</guid>
		<description>Hi Elan,

In your original article you wrote:

&quot;The final change to the Autodiscover rule that is needed is to modify authentication. Click on the Users tab and remove All Authenticated Users. Add the All Users group. There is currently a bug in Exchange 2007 that does not allow ISA 2006 to publish the Exchange 2007 Autodiscover when All Registered Users is selected. Look out for a fix in Exchange 2007 SP1&quot;.

Was this ever sorted?

I currently have an issue with publishing the autodiscover only (everything else is working including Outlook Anywhere), whereby the ISA server is requesting authentication, but the Outlook client is not giving this.  I think this may have something to do with forms based authentication (though I always thought that it went back to basic if specific User Agent strings were provided).


Thanks,
Andrew.</description>
		<content:encoded><![CDATA[<p>Hi Elan,</p>
<p>In your original article you wrote:</p>
<p>&#8220;The final change to the Autodiscover rule that is needed is to modify authentication. Click on the Users tab and remove All Authenticated Users. Add the All Users group. There is currently a bug in Exchange 2007 that does not allow ISA 2006 to publish the Exchange 2007 Autodiscover when All Registered Users is selected. Look out for a fix in Exchange 2007 SP1&#8243;.</p>
<p>Was this ever sorted?</p>
<p>I currently have an issue with publishing the autodiscover only (everything else is working including Outlook Anywhere), whereby the ISA server is requesting authentication, but the Outlook client is not giving this.  I think this may have something to do with forms based authentication (though I always thought that it went back to basic if specific User Agent strings were provided).</p>
<p>Thanks,<br />
Andrew.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-5944</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 09 Dec 2008 20:00:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-5944</guid>
		<description>Keep in mind that the SCP is only for internal Autodiscover access.  For external access, Autodiscover round robin can work, but round robin does not check the state of a server as NLB would.  Because of this, if one CAS goes down or ISA server goes down, the DNS mechanism will still give out a bad DNS record to an ISA box that is unreachable.

To achieve better redundancy, you should make that site that is going to be hosting the Autodiscover a lot more redundancy.  For instance, there&#039;s a doc out there which talks about Microsoft&#039;s Exchange 2007 design.  They have Autodiscover centralized.  And my assumption, since it&#039;s MS and they have a ton of $$$, is that they have multiple internet connections going to this site and everything is redundant as possible (multiple load balancers), multiple ISA servers, etc....  That way the chance of Autodiscover going down short of a meteor destroying their entire datacenter is pretty slim.</description>
		<content:encoded><![CDATA[<p>Keep in mind that the SCP is only for internal Autodiscover access.  For external access, Autodiscover round robin can work, but round robin does not check the state of a server as NLB would.  Because of this, if one CAS goes down or ISA server goes down, the DNS mechanism will still give out a bad DNS record to an ISA box that is unreachable.</p>
<p>To achieve better redundancy, you should make that site that is going to be hosting the Autodiscover a lot more redundancy.  For instance, there&#8217;s a doc out there which talks about Microsoft&#8217;s Exchange 2007 design.  They have Autodiscover centralized.  And my assumption, since it&#8217;s MS and they have a ton of $$$, is that they have multiple internet connections going to this site and everything is redundant as possible (multiple load balancers), multiple ISA servers, etc&#8230;.  That way the chance of Autodiscover going down short of a meteor destroying their entire datacenter is pretty slim.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hong</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-5933</link>
		<dc:creator>Hong</dc:creator>
		<pubDate>Tue, 09 Dec 2008 00:15:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-5933</guid>
		<description>Hi Elan,

We have two Exchange servers and two sets of ISA arrays (separate WAN connections) at two physical locations belongs two different logical sites.

When we&#039;re setting up autodiscover, we have to configure one autodiscover site (round robin DNS balanced) which is https:///autodiscover.  My question is for this one site, is it possible to create SCP info in autodiscover.xml to redirect users&#039; Outlook to use the ISA servers at their home site based on the site info of the requesting mailbox&#039;s server?

I should admit that I am still not 100% understand autdiscover.  But I have the feeling that it won&#039;t fly.  If this is true, what is my next option?  Should I try to make the ISA servers in one location talking to the CAS servers in another location (they are not now) so that no matter which ISA server a user is connecting to, this user can access the home site CAS server (use Use Site Affinity?)  and then the Mailbox server?

Could you please let me know?

Thank you in advance,

Hong</description>
		<content:encoded><![CDATA[<p>Hi Elan,</p>
<p>We have two Exchange servers and two sets of ISA arrays (separate WAN connections) at two physical locations belongs two different logical sites.</p>
<p>When we&#8217;re setting up autodiscover, we have to configure one autodiscover site (round robin DNS balanced) which is <a href="https:///autodiscover" rel="nofollow">https:///autodiscover</a>.  My question is for this one site, is it possible to create SCP info in autodiscover.xml to redirect users&#8217; Outlook to use the ISA servers at their home site based on the site info of the requesting mailbox&#8217;s server?</p>
<p>I should admit that I am still not 100% understand autdiscover.  But I have the feeling that it won&#8217;t fly.  If this is true, what is my next option?  Should I try to make the ISA servers in one location talking to the CAS servers in another location (they are not now) so that no matter which ISA server a user is connecting to, this user can access the home site CAS server (use Use Site Affinity?)  and then the Mailbox server?</p>
<p>Could you please let me know?</p>
<p>Thank you in advance,</p>
<p>Hong</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Exchange 2007 -- The Monopologue</title>
		<link>http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/comment-page-1/#comment-1110</link>
		<dc:creator>Exchange 2007 -- The Monopologue</dc:creator>
		<pubDate>Wed, 16 Jan 2008 10:12:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=4#comment-1110</guid>
		<description>[...] Publishing Exchange 2007 Autodisover in ISA 2006 [...]</description>
		<content:encoded><![CDATA[<p>[...] Publishing Exchange 2007 Autodisover in ISA 2006 [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
