<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Publishing Symantec Enterprise Vault in ISA 2006</title>
	<atom:link href="http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Fri, 12 Mar 2010 09:57:15 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: @AaronJAnderson</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9710</link>
		<dc:creator>@AaronJAnderson</dc:creator>
		<pubDate>Wed, 03 Mar 2010 00:26:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9710</guid>
		<description>Elan, Thanks for the reply! I think I&#039;m pretty much stuck right now with the extra authentication. My TMG server is not a domain member so constrained delegation is not an option for me. This is a security team decision. I&#039;m sure as soon as the higher ups get annoyed with typing their passwords so many times (Like I don&#039;t type mine in 300 times a day!) that they&#039;ll lighten up a little bit and just let us optimize our 2007 front ends with our F5 load balancers, which btw, make OWA really scream. This is an excellent article. Probably the most complete on the net in regard to the topic. </description>
		<content:encoded><![CDATA[<p>Elan, Thanks for the reply! I think I&#039;m pretty much stuck right now with the extra authentication. My TMG server is not a domain member so constrained delegation is not an option for me. This is a security team decision. I&#039;m sure as soon as the higher ups get annoyed with typing their passwords so many times (Like I don&#039;t type mine in 300 times a day!) that they&#039;ll lighten up a little bit and just let us optimize our 2007 front ends with our F5 load balancers, which btw, make OWA really scream. This is an excellent article. Probably the most complete on the net in regard to the topic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9703</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Sun, 28 Feb 2010 17:29:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9703</guid>
		<description>Not sure.  I&#039;ve only ever published the EV stuff through OWA as described in the article.  The first thought I have is that EnterpriseVault IIS directory authentication doesn&#039;t match the Authentication Delegation on the TMG Rule and you get prompted.  There are other things such as you may not be using NTLM on the listener with KCD to the IIS directory or Pre-Auth Bypass directly to the server to bypass authentication credentials as NTLM cannot have another auth provider in the middle. </description>
		<content:encoded><![CDATA[<p>Not sure.  I&#039;ve only ever published the EV stuff through OWA as described in the article.  The first thought I have is that EnterpriseVault IIS directory authentication doesn&#039;t match the Authentication Delegation on the TMG Rule and you get prompted.  There are other things such as you may not be using NTLM on the listener with KCD to the IIS directory or Pre-Auth Bypass directly to the server to bypass authentication credentials as NTLM cannot have another auth provider in the middle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: @AaronJAnderson</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-9697</link>
		<dc:creator>@AaronJAnderson</dc:creator>
		<pubDate>Fri, 26 Feb 2010 14:47:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-9697</guid>
		<description>I have this working with Exchange 2007, TMG 2010 (isa) and EV 8.0 sp2. I did this to get the EV extensions working in Outlook for Outlook Anywhere. Everything works but I am prompted for credentials the first time Outlook tries to do something with EV such as retrieve or store.  
 
Is there a way to avoid this? </description>
		<content:encoded><![CDATA[<p>I have this working with Exchange 2007, TMG 2010 (isa) and EV 8.0 sp2. I did this to get the EV extensions working in Outlook for Outlook Anywhere. Everything works but I am prompted for credentials the first time Outlook tries to do something with EV such as retrieve or store.  </p>
<p>Is there a way to avoid this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GAH</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-8499</link>
		<dc:creator>GAH</dc:creator>
		<pubDate>Tue, 03 Nov 2009 17:09:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-8499</guid>
		<description>I will update the existing rule and see how it will work.  
Thank you very much Elan.  </description>
		<content:encoded><![CDATA[<p>I will update the existing rule and see how it will work.<br />
Thank you very much Elan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-8498</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 03 Nov 2009 17:04:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-8498</guid>
		<description>Don&#039;t think you will see anything in specific.  This article was written a while ago and it may work now.  When I wrote that, I heard of someone having this issue and that they used a regular website publishing rule which fixed the issue for them.  I didn&#039;t test it out myself. </description>
		<content:encoded><![CDATA[<p>Don&#039;t think you will see anything in specific.  This article was written a while ago and it may work now.  When I wrote that, I heard of someone having this issue and that they used a regular website publishing rule which fixed the issue for them.  I didn&#039;t test it out myself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GAH</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-8497</link>
		<dc:creator>GAH</dc:creator>
		<pubDate>Tue, 03 Nov 2009 16:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-8497</guid>
		<description>Tanks for a great blog Elan. 
 
One question for you Elan. 
 Regarding &quot;There is a bug that prevents you from setting up Link Translation rules that are needed to get Enterprise Vault to work&quot; how will I see the error occur. Or will I not see any error but it just will not work. 
The reason I ask is that I do not know whether the &#8220;Exchange Web Client Access publishing Rule&#8221; was used when the OWA rule was created or  &#8220;Web Site Publishing Rule.&#8221;   I do not want to reconstruct the rule unnecessarily. 
 
thanks </description>
		<content:encoded><![CDATA[<p>Tanks for a great blog Elan. </p>
<p>One question for you Elan.<br />
 Regarding &quot;There is a bug that prevents you from setting up Link Translation rules that are needed to get Enterprise Vault to work&quot; how will I see the error occur. Or will I not see any error but it just will not work.<br />
The reason I ask is that I do not know whether the &ldquo;Exchange Web Client Access publishing Rule&rdquo; was used when the OWA rule was created or  &ldquo;Web Site Publishing Rule.&rdquo;   I do not want to reconstruct the rule unnecessarily. </p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rami</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-7281</link>
		<dc:creator>Rami</dc:creator>
		<pubDate>Mon, 06 Jul 2009 21:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-7281</guid>
		<description>Thanks for this info.  We toyed with this solution.  But having all of our users go out to the ISA server when they are internal was something we weren&#039;t thrilled about due to high availability concerns.  
What we have done is we created a second website (with a different IP) on the CAS boxes, configuring it for basic authentication and creating the necessary CAS hooks with powershell.  We left the default CAS website as forms-based auth.  Then you can direct the ISA traffic to the secondary website using the second IP while leaving your internal OWA traffic to the primary website.  This guarantees FBA for both internal and external and the same namespace (if you want) while allowing internal traffic to not require the ISA to be up, etc.

This does make EVault config in web.config a little more interesting since both primary and secondary websites in CAS point to the same OWA dir and web.config.  So you have to point the EnterpriseVault_WebDAVRequestHost entry to the secondary website&#039;s IP address.  But it all seems to work. 
The next challenge was to make Evault in OWA and Outlook work correctly on kiosks (where the windows user is not necessarily the same as the user&#039;s mailbox).</description>
		<content:encoded><![CDATA[<p>Thanks for this info.  We toyed with this solution.  But having all of our users go out to the ISA server when they are internal was something we weren&#8217;t thrilled about due to high availability concerns.<br />
What we have done is we created a second website (with a different IP) on the CAS boxes, configuring it for basic authentication and creating the necessary CAS hooks with powershell.  We left the default CAS website as forms-based auth.  Then you can direct the ISA traffic to the secondary website using the second IP while leaving your internal OWA traffic to the primary website.  This guarantees FBA for both internal and external and the same namespace (if you want) while allowing internal traffic to not require the ISA to be up, etc.</p>
<p>This does make EVault config in web.config a little more interesting since both primary and secondary websites in CAS point to the same OWA dir and web.config.  So you have to point the EnterpriseVault_WebDAVRequestHost entry to the secondary website&#8217;s IP address.  But it all seems to work.<br />
The next challenge was to make Evault in OWA and Outlook work correctly on kiosks (where the windows user is not necessarily the same as the user&#8217;s mailbox).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: world free</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-6704</link>
		<dc:creator>world free</dc:creator>
		<pubDate>Tue, 07 Apr 2009 16:17:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-6704</guid>
		<description>update on my side.  this is required for the outlook anywhere rule (if you use outlook anywhere).</description>
		<content:encoded><![CDATA[<p>update on my side.  this is required for the outlook anywhere rule (if you use outlook anywhere).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-6703</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 07 Apr 2009 16:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-6703</guid>
		<description>1.  You&#039;re re-directing all the EV FQDN to the OWA FQDN to avoid the need to have the EV FQDN in the cert.  So no.
2.  No because again, you&#039;re re-directing the EV traffic to the OWA listener/rule.
3.  Depends on how your ISA to AD authentication is set up.</description>
		<content:encoded><![CDATA[<p>1.  You&#8217;re re-directing all the EV FQDN to the OWA FQDN to avoid the need to have the EV FQDN in the cert.  So no.<br />
2.  No because again, you&#8217;re re-directing the EV traffic to the OWA listener/rule.<br />
3.  Depends on how your ISA to AD authentication is set up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stan</title>
		<link>http://www.shudnow.net/2008/06/24/publishing-symantec-enterprise-vault-in-isa-2006/comment-page-1/#comment-6698</link>
		<dc:creator>Stan</dc:creator>
		<pubDate>Mon, 06 Apr 2009 20:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=119#comment-6698</guid>
		<description>Hi,

Great instructions! Now if I could only get it to work.

1.  Is a UC cert required for this method to work?
2.  What should the Authentication be set at on the OWA listener?
3.  I&#039;m assuming LDAP traffic must be allowed between the ISA server and the internal network?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Great instructions! Now if I could only get it to work.</p>
<p>1.  Is a UC cert required for this method to work?<br />
2.  What should the Authentication be set at on the OWA listener?<br />
3.  I&#8217;m assuming LDAP traffic must be allowed between the ISA server and the internal network?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
