<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exchange 2007 OWA via ISA RSA &#8211; Authentication Delegation</title>
	<atom:link href="http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Fri, 12 Mar 2010 09:57:15 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8318</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Fri, 09 Oct 2009 02:10:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8318</guid>
		<description>The listener is set to RSA, correct? When you set it to All Users, you&#039;re essentially bypassing pre-authentication for the listener for those other rules. When you have it set to Authenticated Users, you&#039;re forcing the client to perform pre-authentication which would fail due to those services not supporting RSA authentication. 
 
Whenever I bypass pre-authentication for a rule, I always do two things: 
1. Set the authentication delegation on the rule to have clients authenticate directly to Exchange. 
2. Set it to allow All Users.  </description>
		<content:encoded><![CDATA[<p>The listener is set to RSA, correct? When you set it to All Users, you&#039;re essentially bypassing pre-authentication for the listener for those other rules. When you have it set to Authenticated Users, you&#039;re forcing the client to perform pre-authentication which would fail due to those services not supporting RSA authentication. </p>
<p>Whenever I bypass pre-authentication for a rule, I always do two things:<br />
1. Set the authentication delegation on the rule to have clients authenticate directly to Exchange.<br />
2. Set it to allow All Users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8317</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Fri, 09 Oct 2009 02:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8317</guid>
		<description>The listener is set to RSA, correct?  When you set it to All Users, you&#039;re essentially bypassing pre-authentication for the listener for those other rules.  When you have it set to Authenticated Users, you&#039;re forcing the client to perform pre-authentication which would fail due to those services not supporting RSA authentication.   
 
Whenever I bypass pre-authentication for a rule, I always do two things: 
1. Set the authentication delegation on the rule to have clients authenticate directly to Exchange. 
2. Set it to allow All Users. 
 </description>
		<content:encoded><![CDATA[<p>The listener is set to RSA, correct?  When you set it to All Users, you&#039;re essentially bypassing pre-authentication for the listener for those other rules.  When you have it set to Authenticated Users, you&#039;re forcing the client to perform pre-authentication which would fail due to those services not supporting RSA authentication.   </p>
<p>Whenever I bypass pre-authentication for a rule, I always do two things:<br />
1. Set the authentication delegation on the rule to have clients authenticate directly to Exchange.<br />
2. Set it to allow All Users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Una</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8302</link>
		<dc:creator>Una</dc:creator>
		<pubDate>Tue, 06 Oct 2009 00:54:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8302</guid>
		<description>Hi Elan, I&#039;ve run into an issue with creating a second site on the CAS - forms-based authentication is set on the Exchange directory and is required for a 3rd party application and installing a second CAS is not an option at this stage. Going back to using the same web listener - the only way I can get it to work is setting users to All Users on the AS &amp; OA ISA publishing rule. Authenticated Users does not work. Is there a setting I&#039;m missing?  
Kind Regards 
Una </description>
		<content:encoded><![CDATA[<p>Hi Elan, I&#039;ve run into an issue with creating a second site on the CAS &#8211; forms-based authentication is set on the Exchange directory and is required for a 3rd party application and installing a second CAS is not an option at this stage. Going back to using the same web listener &#8211; the only way I can get it to work is setting users to All Users on the AS &amp; OA ISA publishing rule. Authenticated Users does not work. Is there a setting I&#039;m missing?<br />
Kind Regards<br />
Una</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Una</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8286</link>
		<dc:creator>Una</dc:creator>
		<pubDate>Fri, 02 Oct 2009 00:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8286</guid>
		<description>Thanks for your help Elan, OWA is authenticating to the RSA without the need to specify a domain. I&#039;ve decided to go the more secure option and purchase a new cert for OWA, hosting it on a new site and leave AS and OA as is using LDAPS for authentication. Kind Regards Una  </description>
		<content:encoded><![CDATA[<p>Thanks for your help Elan, OWA is authenticating to the RSA without the need to specify a domain. I&#039;ve decided to go the more secure option and purchase a new cert for OWA, hosting it on a new site and leave AS and OA as is using LDAPS for authentication. Kind Regards Una</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OWA 2007 Anmeldung - MCSEboard.de MCSE Forum</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8284</link>
		<dc:creator>OWA 2007 Anmeldung - MCSEboard.de MCSE Forum</dc:creator>
		<pubDate>Thu, 01 Oct 2009 13:03:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8284</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8281</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Wed, 30 Sep 2009 20:13:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8281</guid>
		<description>Yes </description>
		<content:encoded><![CDATA[<p>Yes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8280</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Wed, 30 Sep 2009 20:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8280</guid>
		<description>Yes. </description>
		<content:encoded><![CDATA[<p>Yes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Una</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8277</link>
		<dc:creator>Una</dc:creator>
		<pubDate>Wed, 30 Sep 2009 04:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8277</guid>
		<description>Thanks for the quick reply. Does this also work if ISA has been installed in a workgroup and not connected to the domain?  </description>
		<content:encoded><![CDATA[<p>Thanks for the quick reply. Does this also work if ISA has been installed in a workgroup and not connected to the domain?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8276</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 29 Sep 2009 23:46:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8276</guid>
		<description> 
You could use the same listener if you set your rule to not require ISA Pre-Authentication by setting its Authentication Delegation to Allow Clients to Authentication Directly. This will trump listener authentication. Otherwise, yes, you need a new listener with a new certificate. 
 </description>
		<content:encoded><![CDATA[<p>You could use the same listener if you set your rule to not require ISA Pre-Authentication by setting its Authentication Delegation to Allow Clients to Authentication Directly. This will trump listener authentication. Otherwise, yes, you need a new listener with a new certificate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Una</title>
		<link>http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/comment-page-1/#comment-8273</link>
		<dc:creator>Una</dc:creator>
		<pubDate>Tue, 29 Sep 2009 20:53:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1153#comment-8273</guid>
		<description>Hi Elan, Thank you for the RSA blog. I have a question re ActiveSync once I&#039;ve implemented OWA using RSA. 
 
Before I purchase another certificate, I would like to confirm my ActiveSync site will need to change? Because I need a new web listener for ActiveSync I will need a new certificate and site name for ActiveSync? In other words, ActiveSync can no longer use webmail.company.com but would have to be configured for mobile.company.com? 
 </description>
		<content:encoded><![CDATA[<p>Hi Elan, Thank you for the RSA blog. I have a question re ActiveSync once I&#039;ve implemented OWA using RSA. </p>
<p>Before I purchase another certificate, I would like to confirm my ActiveSync site will need to change? Because I need a new web listener for ActiveSync I will need a new certificate and site name for ActiveSync? In other words, ActiveSync can no longer use webmail.company.com but would have to be configured for mobile.company.com?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
