<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Publishing Symantec Enterprise Vault in ISA 2006</title>
	<atom:link href="http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Thu, 09 Feb 2012 12:04:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: @AaronJAnderson</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-10072</link>
		<dc:creator>@AaronJAnderson</dc:creator>
		<pubDate>Sun, 02 May 2010 19:28:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-10072</guid>
		<description>Rainy day update:  
 
Executives do not want to type passwords. I will reference this thread later in the future when I tell team-members things like this :) So now it&#039;s time to re-engineer some things on the TMG and join it to the domain. I will also be setting up NTLM authentication for Outlook Anywhere so this should be an interesting event.  </description>
		<content:encoded><![CDATA[<p>Rainy day update:  </p>
<p>Executives do not want to type passwords. I will reference this thread later in the future when I tell team-members things like this :) So now it&#039;s time to re-engineer some things on the TMG and join it to the domain. I will also be setting up NTLM authentication for Outlook Anywhere so this should be an interesting event.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alogic</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-10067</link>
		<dc:creator>Alogic</dc:creator>
		<pubDate>Fri, 30 Apr 2010 12:07:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-10067</guid>
		<description>Hi Elan, 
Great article btw. My dilema is probably a misconfiguration on my part. I was wondering if you had time to check my config. 
I posted my issue on the EV forum which explains my issue.  &lt;a href=&quot;https://www-secure.symantec.com/connect/forums/isa-2006-exchange-2007-ev-sp4&quot; rel=&quot;nofollow&quot;&gt;https://www-secure.symantec.com/connect/forums/is...&lt;/a&gt; 
 
It seems like after logging into OWA, ISA tries to fetch the EV icons and scripts from the EV server instead of using the CAS RPC extensions. 
where did I go wrong? 
 
Thanks for your help. 
-S 
 </description>
		<content:encoded><![CDATA[<p>Hi Elan,<br />
Great article btw. My dilema is probably a misconfiguration on my part. I was wondering if you had time to check my config.<br />
I posted my issue on the EV forum which explains my issue.  <a href="https://www-secure.symantec.com/connect/forums/isa-2006-exchange-2007-ev-sp4" rel="nofollow">https://www-secure.symantec.com/connect/forums/is&#8230;</a> </p>
<p>It seems like after logging into OWA, ISA tries to fetch the EV icons and scripts from the EV server instead of using the CAS RPC extensions.<br />
where did I go wrong? </p>
<p>Thanks for your help.<br />
-S</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Santiago</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9904</link>
		<dc:creator>Santiago</dc:creator>
		<pubDate>Thu, 08 Apr 2010 11:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9904</guid>
		<description>Thanks Elan for your attention </description>
		<content:encoded><![CDATA[<p>Thanks Elan for your attention</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eshudnow</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9866</link>
		<dc:creator>eshudnow</dc:creator>
		<pubDate>Fri, 02 Apr 2010 13:19:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9866</guid>
		<description>Santiago, I&#039;ve never really set up Enterprise Vault and have only published it via ISA for which I created the article for.  So I apologize, but I can&#039;t really provide you with any more information on this.  What I would suggest though, is to post in the Symantec EV forum section and ask how you can enable SSL on your IIS directories for Enterprise Vault.  You would then just have ISA bridge to the EV IIS directory over port 443 which is on the bridge tab on the ISA rule.  You would then want to set up the link translation rules to have the client go to https.  I have no tried this at all so try and test this in a lab before doing it in production.    </description>
		<content:encoded><![CDATA[<p>Santiago, I&#039;ve never really set up Enterprise Vault and have only published it via ISA for which I created the article for.  So I apologize, but I can&#039;t really provide you with any more information on this.  What I would suggest though, is to post in the Symantec EV forum section and ask how you can enable SSL on your IIS directories for Enterprise Vault.  You would then just have ISA bridge to the EV IIS directory over port 443 which is on the bridge tab on the ISA rule.  You would then want to set up the link translation rules to have the client go to https.  I have no tried this at all so try and test this in a lab before doing it in production.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Santiago</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9859</link>
		<dc:creator>Santiago</dc:creator>
		<pubDate>Thu, 01 Apr 2010 12:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9859</guid>
		<description>Hello Elan, 
I have some questions for you about this article... 
 
So, i&#039;m using Enterprise Vault 8.0 SP3 ver. with HTTP 80 port to access web application. In general, i have already published in ISA the following exchange 2007 services - OWA, Outlook Anywhere, ActiveSync,.... that&#039;s why we use HTTPS communication, also i need to publish EV in ISA 2006 and that the communication will be secure - encrypted.  
 
It is interested to me that if i change in EV site properties the &quot;Use TCP Port 80&quot; to &quot;Use HTTPS on SSL Port 443&quot; then i will also to implement SSL in IIS of Evault and that&#039;s why then configure the SSL certificate. 
 
Do you know what kind of certificate do i need to use to push then HTTPS on Enterprise Vault.. ? 
 
P.S  I&#039;m little bit confused with configuring SSL Port to Enterprise Vault entirely because i&#039;m using HTTP 80 port already, could you suggest me simply how to setup it  ? </description>
		<content:encoded><![CDATA[<p>Hello Elan,<br />
I have some questions for you about this article&#8230; </p>
<p>So, i&#039;m using Enterprise Vault 8.0 SP3 ver. with HTTP 80 port to access web application. In general, i have already published in ISA the following exchange 2007 services &#8211; OWA, Outlook Anywhere, ActiveSync,&#8230;. that&#039;s why we use HTTPS communication, also i need to publish EV in ISA 2006 and that the communication will be secure &#8211; encrypted.  </p>
<p>It is interested to me that if i change in EV site properties the &quot;Use TCP Port 80&quot; to &quot;Use HTTPS on SSL Port 443&quot; then i will also to implement SSL in IIS of Evault and that&#039;s why then configure the SSL certificate. </p>
<p>Do you know what kind of certificate do i need to use to push then HTTPS on Enterprise Vault.. ? </p>
<p>P.S  I&#039;m little bit confused with configuring SSL Port to Enterprise Vault entirely because i&#039;m using HTTP 80 port already, could you suggest me simply how to setup it  ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Santiago</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9858</link>
		<dc:creator>Santiago</dc:creator>
		<pubDate>Thu, 01 Apr 2010 11:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9858</guid>
		<description>Hello Elan,
I have some questions for you about this article...

So, i&#039;m using Enterprise Vault 8.0 SP3 ver. with HTTP 80 port to access web application. In general, i have already published in ISA the following exchange 2007 services - OWA, Outlook Anywhere, ActiveSync,.... that&#039;s why we use HTTPS communication, also i need to publish EV in ISA 2006 and that the communication will be secure - encrypted. 

It is interested to me that if i change in EV site properties the &quot;Use TCP Port 80&quot; to &quot;Use HTTPS on SSL Port 443&quot; then i will also to implement SSL in IIS of Evault and that&#039;s why then configure the SSL certificate.

Do you know what kind of certificate do i need to use to push then HTTPS on Enterprise Vault.. ?

P.S  I&#039;m little bit confused with configuring SSL Port to Enterprise Vault entirely because i&#039;m using HTTP 80 port already, could you suggest me simply how to setup it  ?</description>
		<content:encoded><![CDATA[<p>Hello Elan,<br />
I have some questions for you about this article&#8230;</p>
<p>So, i&#8217;m using Enterprise Vault 8.0 SP3 ver. with HTTP 80 port to access web application. In general, i have already published in ISA the following exchange 2007 services &#8211; OWA, Outlook Anywhere, ActiveSync,&#8230;. that&#8217;s why we use HTTPS communication, also i need to publish EV in ISA 2006 and that the communication will be secure &#8211; encrypted. </p>
<p>It is interested to me that if i change in EV site properties the &#8220;Use TCP Port 80&#8243; to &#8220;Use HTTPS on SSL Port 443&#8243; then i will also to implement SSL in IIS of Evault and that&#8217;s why then configure the SSL certificate.</p>
<p>Do you know what kind of certificate do i need to use to push then HTTPS on Enterprise Vault.. ?</p>
<p>P.S  I&#8217;m little bit confused with configuring SSL Port to Enterprise Vault entirely because i&#8217;m using HTTP 80 port already, could you suggest me simply how to setup it  ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: @AaronJAnderson</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9710</link>
		<dc:creator>@AaronJAnderson</dc:creator>
		<pubDate>Wed, 03 Mar 2010 00:26:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9710</guid>
		<description>Elan, Thanks for the reply! I think I&#039;m pretty much stuck right now with the extra authentication. My TMG server is not a domain member so constrained delegation is not an option for me. This is a security team decision. I&#039;m sure as soon as the higher ups get annoyed with typing their passwords so many times (Like I don&#039;t type mine in 300 times a day!) that they&#039;ll lighten up a little bit and just let us optimize our 2007 front ends with our F5 load balancers, which btw, make OWA really scream. This is an excellent article. Probably the most complete on the net in regard to the topic. </description>
		<content:encoded><![CDATA[<p>Elan, Thanks for the reply! I think I&#039;m pretty much stuck right now with the extra authentication. My TMG server is not a domain member so constrained delegation is not an option for me. This is a security team decision. I&#039;m sure as soon as the higher ups get annoyed with typing their passwords so many times (Like I don&#039;t type mine in 300 times a day!) that they&#039;ll lighten up a little bit and just let us optimize our 2007 front ends with our F5 load balancers, which btw, make OWA really scream. This is an excellent article. Probably the most complete on the net in regard to the topic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9703</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Sun, 28 Feb 2010 17:29:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9703</guid>
		<description>Not sure.  I&#039;ve only ever published the EV stuff through OWA as described in the article.  The first thought I have is that EnterpriseVault IIS directory authentication doesn&#039;t match the Authentication Delegation on the TMG Rule and you get prompted.  There are other things such as you may not be using NTLM on the listener with KCD to the IIS directory or Pre-Auth Bypass directly to the server to bypass authentication credentials as NTLM cannot have another auth provider in the middle. </description>
		<content:encoded><![CDATA[<p>Not sure.  I&#039;ve only ever published the EV stuff through OWA as described in the article.  The first thought I have is that EnterpriseVault IIS directory authentication doesn&#039;t match the Authentication Delegation on the TMG Rule and you get prompted.  There are other things such as you may not be using NTLM on the listener with KCD to the IIS directory or Pre-Auth Bypass directly to the server to bypass authentication credentials as NTLM cannot have another auth provider in the middle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: @AaronJAnderson</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9697</link>
		<dc:creator>@AaronJAnderson</dc:creator>
		<pubDate>Fri, 26 Feb 2010 14:47:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9697</guid>
		<description>I have this working with Exchange 2007, TMG 2010 (isa) and EV 8.0 sp2. I did this to get the EV extensions working in Outlook for Outlook Anywhere. Everything works but I am prompted for credentials the first time Outlook tries to do something with EV such as retrieve or store.  
 
Is there a way to avoid this? </description>
		<content:encoded><![CDATA[<p>I have this working with Exchange 2007, TMG 2010 (isa) and EV 8.0 sp2. I did this to get the EV extensions working in Outlook for Outlook Anywhere. Everything works but I am prompted for credentials the first time Outlook tries to do something with EV such as retrieve or store.  </p>
<p>Is there a way to avoid this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GAH</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-8499</link>
		<dc:creator>GAH</dc:creator>
		<pubDate>Tue, 03 Nov 2009 17:09:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-8499</guid>
		<description>I will update the existing rule and see how it will work.  
Thank you very much Elan.  </description>
		<content:encoded><![CDATA[<p>I will update the existing rule and see how it will work.<br />
Thank you very much Elan.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

