<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-559969103248710395.post1258937356579638284..comments</id><updated>2010-08-28T01:07:15.670+01:00</updated><title type='text'>Comments on Me, Myself and ISA Blog (MSFirewall.org.uk): Publishing Exchange 2007 Services with ISA Server ...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.msfirewall.org.uk/feeds/1258937356579638284/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default?start-index=26&amp;max-results=25'/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>jason.jones@silversands.co.uk</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-34236177166406619</id><published>2010-08-28T01:07:15.670+01:00</published><updated>2010-08-28T01:07:15.670+01:00</updated><title type='text'>Hi Eric,

Yep, http auth combined with basic auth ...</title><summary type='text'>Hi Eric,&lt;br /&gt;&lt;br /&gt;Yep, http auth combined with basic auth delegation should be fine for mobile devices.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;JJ</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/34236177166406619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/34236177166406619'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1282954035670#c34236177166406619' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-9116523779311934137</id><published>2010-08-25T04:59:42.369+01:00</published><updated>2010-08-25T04:59:42.369+01:00</updated><title type='text'>Can autodiscover for ActiveSync be accomplished wi...</title><summary type='text'>Can autodiscover for ActiveSync be accomplished without using KCD, for example, if the ISA servers are not in a domain?  All I care about is autodiscover for ActiveSync.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/9116523779311934137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/9116523779311934137'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1282708782369#c9116523779311934137' title=''/><author><name>Eric</name><uri>http://www.blogger.com/profile/07881982695475104835</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-7591895663650374175</id><published>2010-05-17T14:45:16.045+01:00</published><updated>2010-05-17T14:45:16.045+01:00</updated><title type='text'>Hi Aaron,

This looks resolved now ;)

http://foru...</title><summary type='text'>Hi Aaron,&lt;br /&gt;&lt;br /&gt;This looks resolved now ;)&lt;br /&gt;&lt;br /&gt;http://forums.isaserver.org/m_2002100926/mpage_1/key_/tm.htm#2002100926&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;JJ</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/7591895663650374175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/7591895663650374175'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1274103916045#c7591895663650374175' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-8893213565110758375</id><published>2010-05-14T19:18:10.146+01:00</published><updated>2010-05-14T19:18:10.146+01:00</updated><title type='text'>I did all of this; and I still get the login promp...</title><summary type='text'>I did all of this; and I still get the login prompt... what&amp;#39;s the first place I should check? &lt;br /&gt;&lt;br /&gt;&amp;#39;Set-OutlookProvider&amp;#39; do I need to do anything with that command? my EXPR is set to NULL currently... help.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8893213565110758375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8893213565110758375'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1273861090146#c8893213565110758375' title=''/><author><name>Aaron</name><uri>http://www.blogger.com/profile/15442582204004678766</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-2942370565835561385</id><published>2010-03-09T20:44:24.562Z</published><updated>2010-03-09T20:44:24.562Z</updated><title type='text'>Hi Mike,

Wow, how many questions! ;)

Please find...</title><summary type='text'>Hi Mike,&lt;br /&gt;&lt;br /&gt;Wow, how many questions! ;)&lt;br /&gt;&lt;br /&gt;Please find answers below:&lt;br /&gt;&lt;br /&gt;1. I have only used this approach for Exchange 2007, so not sure about Exchange 2003. I don&amp;#39;t think Exchange 2003 supported NTLM authentication for Outlook Anywhere, but I could be wrong here.&lt;br /&gt;&lt;br /&gt;2. I can confirm 100% that a non-domain member *can* connect to Exchange using Outlook </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2942370565835561385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2942370565835561385'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1268167464562#c2942370565835561385' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-4332381389451195109</id><published>2010-02-26T19:31:56.206Z</published><updated>2010-02-26T19:31:56.206Z</updated><title type='text'>Hi Jason,

I have multiple questions (all related ...</title><summary type='text'>Hi Jason,&lt;br /&gt;&lt;br /&gt;I have multiple questions (all related to the goal of securing the corporate data by ensuring we connect via trusted client machines, bear with me...)&lt;br /&gt;&lt;br /&gt;1. First of all does this work with Exchange 2003? I have not been able to get confirmation on KCD working with Exchange 2003 with Outlook 2007 RPC/HTTPS&lt;br /&gt;&lt;br /&gt;2. Secondly, I&amp;#39;m a little confused about the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/4332381389451195109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/4332381389451195109'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1267212716206#c4332381389451195109' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-8050886506866827561</id><published>2010-01-21T16:34:33.113Z</published><updated>2010-01-21T16:34:33.113Z</updated><title type='text'>&gt;&gt; Paul

Yep, that is workable, but I prefer to us...</title><summary type='text'>&amp;gt;&amp;gt; Paul&lt;br /&gt;&lt;br /&gt;Yep, that is workable, but I prefer to use internal PKI for internal certs and public PKI for ISA certs.&lt;br /&gt;&lt;br /&gt;This is more manageable, felxible and cost effective in the long term...&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;JJ</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8050886506866827561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8050886506866827561'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1264091673113#c8050886506866827561' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-3448579052875147400</id><published>2010-01-21T16:32:30.343Z</published><updated>2010-01-21T16:32:30.343Z</updated><title type='text'>Nope, you can listen on two different public names...</title><summary type='text'>Nope, you can listen on two different public names with different certs, but send them to the same destination server name; the differing paths will be used as appropriate...</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3448579052875147400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3448579052875147400'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1264091550343#c3448579052875147400' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-7673842885245131341</id><published>2010-01-21T16:29:19.417Z</published><updated>2010-01-21T16:29:19.417Z</updated><title type='text'>thank you for this information. quick question. if...</title><summary type='text'>thank you for this information. quick question. if i&amp;#39;m using a two certificates, one for owa and activesync and one for autodiscover and outlook anywhere. on the exchange server, don&amp;#39;t i have to set up a new website for autodiscover, rpc, ews, and oab? any help would be appreciated.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/7673842885245131341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/7673842885245131341'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1264091359417#c7673842885245131341' title=''/><author><name>allinbaby76</name><uri>http://www.blogger.com/profile/14419774533772619135</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-761803241830114359</id><published>2010-01-04T14:22:42.335Z</published><updated>2010-01-04T14:22:42.335Z</updated><title type='text'>Hi Jason,
Re certificates; any thoughts on using o...</title><summary type='text'>Hi Jason,&lt;br /&gt;Re certificates; any thoughts on using one public CA UC Certificate, for both Exchange and ISA.&lt;br /&gt;&lt;br /&gt;The UC certificate would be&lt;br /&gt;email.msfirewall.org.uk with a SAN of autodiscover.msfirewall.org.uk&lt;br /&gt;&lt;br /&gt;If I use this this certificate on the email ISA rule, its obviously valid. If I use it for the Autodiscover rule, I believe the only consequence is the SSL setting </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/761803241830114359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/761803241830114359'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1262614962335#c761803241830114359' title=''/><author><name>Paul</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-6453060226013522683</id><published>2009-12-04T23:33:37.610Z</published><updated>2009-12-04T23:33:37.610Z</updated><title type='text'>&gt;&gt;VileTasteOfDeath

That is true for user objects,...</title><summary type='text'>&amp;gt;&amp;gt;VileTasteOfDeath&lt;br /&gt;&lt;br /&gt;That is true for user objects, but for KCD to work the ISA Server computer object(s) and the published server computer object(s) MUST exist in the same domain.&lt;br /&gt;&lt;br /&gt;Check &amp;quot;The Limitations: Windows Requirements Item 2&amp;quot; in the article URL you provided...&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;JJ</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/6453060226013522683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/6453060226013522683'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1259969617610#c6453060226013522683' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-2193249467944465353</id><published>2009-12-04T14:26:14.724Z</published><updated>2009-12-04T14:26:14.724Z</updated><title type='text'>According to this article: http://technet.microsof...</title><summary type='text'>According to this article: http://technet.microsoft.com/en-us/library/cc752953.aspx &lt;br /&gt;You can now use KCD to authenticate users cross-forest/domain with the appropriate trusts in place.  You would need to be @ISA 2006 SP1 as it has a couple necessary hotfixes.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2193249467944465353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2193249467944465353'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1259936774724#c2193249467944465353' title=''/><author><name>VileTasteOfDeath</name><uri>http://www.blogger.com/profile/16100393841685321873</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-867467365113681585</id><published>2009-09-28T08:59:33.899+01:00</published><updated>2009-09-28T08:59:33.899+01:00</updated><title type='text'>&gt;&gt; Vladislav

You sure about that?

I have quite a...</title><summary type='text'>&amp;gt;&amp;gt; Vladislav&lt;br /&gt;&lt;br /&gt;You sure about that?&lt;br /&gt;&lt;br /&gt;I have quite a few deployments where I am publishing Exchange 2007 64bit with ISA Server 2006 SP1 and then have SAN certs...are you talking about a specific problem?</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/867467365113681585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/867467365113681585'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1254124773899#c867467365113681585' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-4618286204508716240</id><published>2009-09-27T15:04:15.562+01:00</published><updated>2009-09-27T15:04:15.562+01:00</updated><title type='text'>"This configuration will negate likely problems wi...</title><summary type='text'>&amp;quot;This configuration will negate likely problems with ISA Server 2006 pre-SP1 from reading multiple SAN entries as discussed here.&amp;quot;&lt;br /&gt;&lt;br /&gt;According to my research ISA Server 2006 SP1 doesn&amp;#39;t resolve the problem if you are using 64-bit Exchange 2007. &lt;br /&gt;&lt;br /&gt;Strange, there is no &amp;quot;multiple SAN&amp;quot; problem on non-production 32-bit Exchange 2007 SP1.&lt;br /&gt;&lt;br /&gt;Vladislav </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/4618286204508716240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/4618286204508716240'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1254060255562#c4618286204508716240' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-161681584212312967</id><published>2009-08-14T15:58:13.310+01:00</published><updated>2009-08-14T15:58:13.310+01:00</updated><title type='text'>Hi Jason,

Just re transparent authentication with...</title><summary type='text'>Hi Jason,&lt;br /&gt;&lt;br /&gt;Just re transparent authentication with non-domain joined clients.&lt;br /&gt;&lt;br /&gt;IE (and FF via config file) can send the credentials of the logged on user transparently if the site is in the Intranet security zone. There is no need for access to the KDC as NTLM is acceptable: http://support.microsoft.com/Default.aspx?id=258063&lt;br /&gt;&lt;br /&gt;Of course, for non-domain joined clients</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/161681584212312967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/161681584212312967'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1250261893310#c161681584212312967' title=''/><author><name>Ken Schaefer</name><uri>http://adopenstatic.com/blog</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-3493752811865205199</id><published>2009-05-05T09:23:00.000+01:00</published><updated>2009-05-05T09:23:00.000+01:00</updated><title type='text'>&gt;&gt; Chris

Thanks! I think this has been one of my ...</title><summary type='text'>&amp;gt;&amp;gt; Chris&lt;br /&gt;&lt;br /&gt;Thanks! I think this has been one of my more popular posts ;)&lt;br /&gt;&lt;br /&gt;Due to the way Exchange 2007 works, it is better to use ISA web server farm publishing (WSFP) than NLB fro CAS roles. You can still enable NLB for non-web service like POP3/IMAP, but WSFP is the best choice for web protocols needed for OWA, OA, EAS etc. You then use NLB VIPs for non-web services and</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3493752811865205199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3493752811865205199'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1241511780000#c3493752811865205199' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-1512708191601340893</id><published>2009-05-05T02:53:00.000+01:00</published><updated>2009-05-05T02:53:00.000+01:00</updated><title type='text'>This is an excellent article, Jason! I don't know ...</title><summary type='text'>This is an excellent article, Jason! I don't know how I would have implemented transparent authentication without your article.  I do have one question...  I would like to implement redundant servers, using Network Load Balancing (NLB), that host the CAS/HUB roles to provide service high availability to my users.  Is there any way to do Kerberos Constrained Delegation against multiple CAS servers</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/1512708191601340893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/1512708191601340893'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1241488380000#c1512708191601340893' title=''/><author><name>Chris Bushong</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-425995708616197648</id><published>2008-12-17T09:04:00.000Z</published><updated>2008-12-17T09:04:00.000Z</updated><title type='text'>&gt;&gt; AbdulHmmm...I'm not too sure, have you actually...</title><summary type='text'>&amp;gt;&amp;gt; Abdul&lt;BR/&gt;&lt;BR/&gt;Hmmm...I&amp;#39;m not too sure, have you actually tested this? Due to the use of KCD, I am pretty sure the machine would have to be a member of the domain in order to provide correct authentication. Not something I have tried though to be honest! ;)</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/425995708616197648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/425995708616197648'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1229504640000#c425995708616197648' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-8985571223959423892</id><published>2008-12-16T11:26:00.000Z</published><updated>2008-12-16T11:26:00.000Z</updated><title type='text'>I think even if you are connecting from a non-doma...</title><summary type='text'>I think even if you are connecting from a non-domain joined client, you should be able to achieve transparent authentication by adding the CAS and Mailbox server netbios and fqdn and saving the credentials for each of them in the local password store (start---&amp;gt;run--&amp;gt;control userpasswords2)&lt;BR/&gt;&lt;BR/&gt;A very good and informative article. Keep up the good work!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8985571223959423892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/8985571223959423892'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1229426760000#c8985571223959423892' title=''/><author><name>Abdul Aziz</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-3606828781814413146</id><published>2008-11-14T14:51:00.000Z</published><updated>2008-11-14T14:51:00.000Z</updated><title type='text'>&gt;&gt; TimHey, Tim - yep, non-domain joined machines w...</title><summary type='text'>&amp;gt;&amp;gt; Tim&lt;BR/&gt;&lt;BR/&gt;Hey, Tim - yep, non-domain joined machines will receive an authentication prompt as there will be no transparent authentication using cached credentials. I have tested this and all works fine if you enter valid credentials in the authentication pop-up for a non-domain joined machine.&lt;BR/&gt;&lt;BR/&gt;Cheers&lt;BR/&gt;&lt;BR/&gt;JJ</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3606828781814413146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3606828781814413146'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1226674260000#c3606828781814413146' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-2139970504044116041</id><published>2008-11-14T00:31:00.000Z</published><updated>2008-11-14T00:31:00.000Z</updated><title type='text'>What happens with Outlook clients on machines that...</title><summary type='text'>What happens with Outlook clients on machines that are not in the domain? Do they simply get prompted for authentication, or do they not work at all?</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2139970504044116041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2139970504044116041'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1226622660000#c2139970504044116041' title=''/><author><name>Tim</name><uri>http://www.blogger.com/profile/10940964836559789140</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-75819534345022182</id><published>2008-09-26T12:10:00.000+01:00</published><updated>2008-09-26T12:10:00.000+01:00</updated><title type='text'>Pingback: http://forums.isaserver.org/m_2002055762...</title><summary type='text'>Pingback: http://forums.isaserver.org/m_2002055762/mpage_2/key_/tm.htm#2002074426</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/75819534345022182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/75819534345022182'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1222427400000#c75819534345022182' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-3861258798138760315</id><published>2008-08-02T00:27:00.000+01:00</published><updated>2008-08-02T00:27:00.000+01:00</updated><title type='text'>&gt;&gt;HenningThanks for the detailed feedback!I tend t...</title><summary type='text'>&amp;gt;&amp;gt;Henning&lt;BR/&gt;&lt;BR/&gt;Thanks for the detailed feedback!&lt;BR/&gt;&lt;BR/&gt;I tend to enable HTTP to HTTPS redirection for most applications that require SSL. I would agree that in this particular case it is not strictly necessary as there is no real user interaction.&lt;BR/&gt;&lt;BR/&gt;I did consider including inforamtion on wildcard certificate, but wanted to keep things simple for the first entry. I may do a </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3861258798138760315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/3861258798138760315'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1217633220000#c3861258798138760315' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-2535609357370570310</id><published>2008-07-31T12:36:00.000+01:00</published><updated>2008-07-31T12:36:00.000+01:00</updated><title type='text'>Hello Jason,Thanks for a great article. I’ve spent...</title><summary type='text'>Hello Jason,&lt;BR/&gt;Thanks for a great article. I’ve spent weeks migrating from exchange 2003 to 2007 and at the same time also migrating from win 2003 to win 2008 including new forests and sanitizing name spaces for several customers. Reading your article summarizes the very elegant way of doing the NTLM to KCD authentication for Oulook anywhere users through ISA server. During my struggle for </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2535609357370570310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/2535609357370570310'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1217504160000#c2535609357370570310' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-559969103248710395.post-6329659123951387593</id><published>2008-07-31T10:39:00.000+01:00</published><updated>2008-07-31T10:39:00.000+01:00</updated><title type='text'>&gt;&gt;artyomThese additional steps are only necessary ...</title><summary type='text'>&amp;gt;&amp;gt;artyom&lt;BR/&gt;&lt;BR/&gt;These additional steps are only necessary if you plan to use certificate based authentication (as is required for ActiveSync).&lt;BR/&gt;&lt;BR/&gt;Some of these additional steps are required for OWA Document Access so keep tuned to see when similar additional delegation configuration is needed!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/6329659123951387593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/559969103248710395/1258937356579638284/comments/default/6329659123951387593'/><link rel='alternate' type='text/html' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html?showComment=1217497140000#c6329659123951387593' title=''/><author><name>Jason Jones</name><uri>http://www.blogger.com/profile/06409402559050650812</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04036566921868113365'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.msfirewall.org.uk/2008/07/publishing-exchange-2007-services-with.html' ref='tag:blogger.com,1999:blog-559969103248710395.post-1258937356579638284' source='http://www.blogger.com/feeds/559969103248710395/posts/default/1258937356579638284' type='text/html'/></entry></feed>