Exchange 2010 PKI Configuration Guide



Similar documents
Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

etoken Enterprise For: SSL SSL with etoken

Secure IIS Web Server with SSL

Creating the Certificate Request

ECA IIS Instructions. January 2005

Installation Guide. SafeNet Authentication Service

Junio SSL WebLogic Oracle. Guía de Instalación. Junio, SSL WebLogic Oracle Guía de Instalación CONFIDENCIAL Página 1 de 19

Wavecrest Certificate

Configuration Task 3: (Optional) As part of configuration, you can deploy rules. For more information, see "Deploy Inbox Rules" below.

Setting Up SSL on IIS6 for MEGA Advisor

Security Certificate Configuration for IM and Presence Service

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

WHITE PAPER Citrix Secure Gateway Startup Guide

Microsoft Exchange 2010 and 2007

NET UX Series with Microsoft Lync 2010 and CyberData VoIP Intercom

Browser-based Support Console

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

APNS Certificate generating and installation

Load Balancing Exchange 2007 Client Access Servers using Windows Network Load- Balancing Technology

Step-by-Step Guide for Setting Up VPN-based Remote Access in a

How to Request and Configure Exchange Server 2013 Certificate

Installing Samsung SDS CellWe EMM cloud connectors and administrator consoles

AVG Business SSO Connecting to Active Directory

Application Notes for Microsoft Office Communicator Clients with Avaya Communication Manager Phones - Issue 1.1

Microsoft IAS Configuration for RADIUS Authorization

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

Outlook Express POP Instructions - Bloomsburg University Students

App Orchestration 2.5

Exchange Reporter Plus SSL Configuration Guide

e-cert (Server) User Guide For Microsoft IIS 7.0

Using etoken for Securing s Using Outlook and Outlook Express

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

RoomWizard Synchronization Software Manual Installation Instructions

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

SSL Installing your new Certificate

Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication

AvePoint Meetings for SharePoint On-Premises. Installation and Configuration Guide

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

Getting Started with your Hosted Microsoft Exchange 2010 Administrators Quick Start Guide to Hosted Exchange 2010

NSi Mobile Installation Guide. Version 6.2

Using Exclaimer Signature Manager with Office 365

SETUP SSL IN SHAREPOINT 2013 (USING SELF-SIGNED CERTIFICATE)

Installation Procedure SSL Certificates in IIS 7

Basic Exchange Setup Guide

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

Certificate technology on Pulse Secure Access

USER GUIDE WWPass Security for (Outlook) For WWPass Security Pack 2.4

App Orchestration 2.0

Certificate technology on Junos Pulse Secure Access

S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

FTP, IIS, and Firewall Reference and Troubleshooting

Certificate Management for your ICE Server

How to Configure Certificate Based Authentication for WorxMail and XenMobile 10

ACTIVE DIRECTORY DEPLOYMENT

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

ADFS Integration Guidelines

Sophos UTM Web Application Firewall for Microsoft Exchange connectivity

Use 802.1x EAP-TLS or PEAP-MS-CHAP v2 with Microsoft Windows Server 2003 to Make a Secure Network

DMZ Server monitoring with

LAB 1: Installing Active Directory Federation Services

Using Microsoft s CA Server with SonicWALL Devices

Basic Exchange Setup Guide

Step-by-step Guide for Configuring Cisco ACS server as the Radius with an External Windows Database

Archiving with MS Exchange Server

Document Classification: Public Document Name: SAPO Trust Centre - Generating a SSL CSR for IIS with SAN Document Reference:

+27O.557+! RM Auditor Additions - Web Monitor. Contents

HOTPin Integration Guide: DirectAccess

Authenticating users of Cisco NCS or Cisco Prime Infrastructure against Microsoft NPS (RADIUS)

Update Instructions

Client configuration and migration Guide Setting up Thunderbird 3.1

SSL Intercept Mode. Certificate Installation Guide. Revision Warning and Disclaimer

DataCove. Installation Instructions for Search Plug-in for Microsoft Outlook 2007 & 2010 (All Users)

Specops Command. Installation Guide

Configuring Digital Certificates

Lab 05: Deploying Microsoft Office Web Apps Server

Step-by-Step Guide for Setting Up VPN-based Remote Access in a Test Lab

Managing the SSL Certificate for the ESRS HTTPS Listener Service Technical Notes P/N REV A01 January 14, 2011

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Verify LDAP over SSL/TLS (LDAPS) and CA Certificate Using Ldp.exe

Reference and Troubleshooting: FTP, IIS, and Firewall Information

IIS, FTP Server and Windows

Secure Web Service - Hybrid. Policy Server Setup. Release Manual Version 1.01

Certificate Request Generation and Certificate Installation Instructions for IIS 5 April 14, 2006

Blue Coat Security First Steps Solution for Controlling HTTPS

Erado Archiving & Setup Instruction Microsoft Exchange 2007 Push Journaling

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

CA NetQoS Performance Center

Setup Guide. network support pc repairs web design graphic design Internet services spam filtering hosting sales programming

BEA Weblogic Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Protecting Juniper SA using Certificate-Based Authentication. Quick Start Guide

Certificate Management

Windows Mail POP Instructions - Bloomsburg University Students

Step By Step Guide: Demonstrate DirectAccess in a Test Lab

HP Device Manager 4.7

Symantec Managed PKI. Integration Guide for ActiveSync

Update Instructions

Securing Microsoft Exchange 2010 WITH THAWTE SSL CERTIFICATES

Business mail 1 MS OUTLOOK CONFIGURATION... 2

Transcription:

Exchange 2010 PKI Configuration Guide Overview 1. Summary 2. Environment 3. Configuration a) Active Directory Configuration b) CA Configuration c) Exchange Server IIS Configuration d) Exchange Configuration 4. Testing on Exchange OWA PKI access 1. Summary This guide describes how to configure Exchange 2010 authentication using PKI 2. Environment This document was written with Single Domain environment. The CA server was located in the domain controller. Item Operating System IP Address Host Role 1 Windows Server 2008 R2 10.100.5.181 Win2k8dc.c6f1r1.cloud Domain Controller 2 Windows Server 2008 R2 10.100.5.181 Win2k8dc Enterprise Root CA 3 Windows Server 2008 R2 10.100.5.183 Exchange 2010 Exchange Server 4 Windows 7 Enterprise 10.100.5.180 Client computer OWA testing 3. Configuration: 3.1 Windows Server 2008 R2 Active Directory Configuration In Active Directory Group Policy Management snap-in, Expand Forests: c6f1r1.cloud Expand Domains Expand c6f1r1.cloud Right click Default Domain Policy Select Edit to open the Group Policy Management Editor In the Group Policy Management Editor snap-in, go to User Configuration container Expand Policies Expand Windows Settings Expand Security Settings Select Public Key Policy On the right pane, double click on Certificate Services Client Auto-Enrollment

Check Renew Expired Certificates, update pending certificates, and remove revoked certificates and Update certificates that use certificate templates. Keep others as default, click OK to save it. 3.2 Windows Server 2008 R2 CA Configuration In Certification Authority span-in, Expand c6f1r1-win2k8dc-ca Right click Certificate Templates Select Manage

In Certificate Templates Console snap-in, --> Right click on User template --> Select Duplicate Template --> Choose Windows Server 2003 Enterprise and click OK In Template display name --> In General tab, fill in the information as follow -->In Security tab, follow the screen below

Click OK to save and go back to Certificate Templates snap-in. In Certificate Templates snap-in, Right click on Certificate Templates Select New Select Certificate Template to Issue Select the template the newly created template AutoEnroll-User, click OK

Now you can find the template in the right pane in the Certificate Templates snap-in. 3.3 IIS Configuration Open Internet Information Services (IIS) Manager snap-in Expand EXCHANGE2010 (C6F1R1\administrator) Open Authentication in IIS section Set Active Directory Client Certificate Authentication as Enabled Expand Sites Select Default Web Site Open SSL Settings in IIS section Check Require SSL

Choose Require for Client certificates: To set OWA require SSL, go back to the Internet Information Services (IIS) Manager snap-in, Expand Sites Expand Default Web Site Select owa Open SSL Settings in IIS section Check Require SSL Choose Require for Client certificate: To edit the Exchange OWA Client Certificate Authentication Setting that to let user use certificate to login rather than password, go back to the Internet Information Services (IIS) Manager snap-in, Expand Sites

Expand Default Web Site Select owa Open Configuration Editor in Management section In the Section drop down list, Expand system.webserver Expand security Expand authentication Select ClientCertificateMappingAuthentication and set it as True To set the ActiveSync require SSL, go back to the Internet Information Services (IIS) Manager snap-in, Expand Sites Expand Default Web Site Select Microsoft-Server-ActiveSync Open SSL Settings in IIS section Check Require SSL Choose Require for Client certificate:

To edit the Exchange ActiveSync Client Certificate Authentication Setting that to let user use certificate to login rather than password, go back to the Internet Information Services (IIS) Manager snap-in, Expand Sites Expand Default Web Site Select Microsoft-Server-ActiveSync Open Configuration Editor in Management section In the Section drop down list, Expand system.webserver Expand security Expand authentication Select ClientCertificateMappingAuthentication and set it as True

3.4 Exchange 2010 Configuration We first generate a certificate request from Exchange Management Console, parse it to CA to issue a certificate and install the certificate back to the Exchange server. Open Exchange Management Console Expand Microsoft Exchange On-Premises Expand Server Configuration Select Client Access In the right pane, select the tab Outlook Web App Open owa (Default Web Site), in Authentication tab, choose use one or more standard authentication methods and select Integrated Windows authentication, then restart IIS

Open Exchange Management Console Expand Microsoft Exchange On-Premises Expand Server Configuration Select Client Access In the right pane, select tab Exchange ActiveSync Open Microsoft-Server-ActiveSync (Default Web Site) To enable client to use certificate to authenticate, select Require client certificates, uncheck Basic Authentication (password is sent in clear text)

Open Exchange Management Console Expand Microsoft Exchange On-Premises Expand Server Configuration In the right pane, under Exchange Certificates section, right click on white space and select New Exchange Certificate. Follow the screenshot to proceed.

You will see there is a pending certificated signing request (CSR) in Exchange Management Console

Open the certificate request file in E:\certrequest.req (the path stated above) with Notepad to review the certificate request Open Internet Explorer and connect htt://win2k8dc.c6f1r1.cloud/certsrv) to CA server to request the certificates for Exchange (e.g. In CA welcome front page Under Select a task, click Request a certificate Select Submit an advanced certificate request Select Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file. Copy the content of E:\certrequest.req to Base-64-encoded certificated request (CMC or PKCS #10 or PKCS #7) In Certificate Template, select Web Server Keep others as default and click Submit Select DER encoded and click Download Certificate save it to E:\

Open Exchange Management Console Expand Microsoft Exchange On-Premises Expand Server Configuration Select the pending certificate signing request (CSR) Right click on it and select Complete Pending Request Click Browse button to select the certificate that just download to E:\. Click Complete.

To verify the certificate has been imported successfully, you should see The certificate is valid for Exchange Server usage. To assign services to certificate, Right-click on the certificate Exchange2010PKI Select Assign Services to Certificate. Follow screenshot to proceed.

After the services were assigned successfully, you can delete other Exchange self-signed certificates by highlighting that, right-click and select Remove. 4. Testing on the Exchange OWA PKI access First we do not join the Windows 7 Enterprise client to the domain c6f1r1.cloud to verify it uses certificate to authenticate. You will need to edit the host file (C:\Windows\System32\drivers\etc\hosts) to add the mapping of the IP address against the hostname of the Exchange server, such that we can always use hostname instead of IP to access the OWA.

-->Open the Internet Explorer and type the URL of OWA to access the Exchange mailbox -->https://exchange2010.c6f1r1.cloud/owa, you will encounter the following error. Now let s join the Windows 7 Enterprise client to the domain c6f1r1.cloud and test it again. You will now found a dialogue box pop up asking you to select the certificate. Click on that and it will allow you go into the mailbox.

For the Exchange Server 2007 PKI configuration, the step is the same as Exchange Server 2010 except raising the certificate request. In Exchange Server 2007, you can only generate the certificate request with exchange management shell. Please refer to the URL below for details. http://technet.microsoft.com/en-us/library/aa995942.aspx ~END~