JuniperForum.com
September 07, 2010, 07:26:28 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: OWA and Single Sign-On?  (Read 1649 times)
oldo
Sr. Member
****
Posts: 497


View Profile
« on: August 14, 2006, 01:03:17 AM »

Hi! I've found some sort of info on how to get Exchange 2003 Outlook Web Access to work with Single Sign-On. I gave it a try, but never got it to work. Has anyone an OWA with SSO working. My OWA link looks this way:

https://server.domain.com/exchange/bin/auth/owaauth.dll?username=<USERNAME[1]>&password=<PASSWORD[1]>&SubmitCreds=Log+On&forcedownlevel=0&trusted=0&destination=https://server.domain.com/exchange

Should also mention that the Exchange server i worked with had a self signed certificate. The error I got was a 404, page cannot be found.

Any ideas?
Logged

JNCIA-FW, JNCIA-AC, JNCIS-SSL, Ironport ICSP, xSeries Specialist,
Joern
Newbie
*
Posts: 9


View Profile
« Reply #1 on: August 17, 2006, 08:57:06 AM »

If you have an adnvanced license use the sso form post method. You find an howto for this in the juniper knowledge base.
If you don't have an advanced license change your athentication method on your exchange server to basc auth and you can use the basc auth feature on your IVE.
Greetings
Joern
Logged
oldo
Sr. Member
****
Posts: 497


View Profile
« Reply #2 on: August 23, 2006, 06:19:35 AM »

Hi!

Thanks for your reply. Yes it has an "Advanced" license. I looked at KB ID: KB2668 when configuring this. I guess this is the article you mean I could search for? As I said, I never got it to work. Have you? Could it be it is because the OWA site has a self signed crtificate? Or have I missed something else?

regards,
oldO
Logged

JNCIA-FW, JNCIA-AC, JNCIS-SSL, Ironport ICSP, xSeries Specialist,
Frac
Hero Member
*****
Posts: 784


View Profile WWW
« Reply #3 on: August 23, 2006, 06:28:49 AM »

oldo,

why go to a the https page? use the http page (the SA will do the https, so np)

And yes the certificate could be the problem, who is is gona accept it? (popup self sign certf?)

change the https to the http page and try it again.

GreetZ,
Frac
Logged

JNCIS-FWV, JNCIS-ER, JNCIA-EX, JNCIA-IDP http://juniper-frac.blogspot.com
Joern
Newbie
*
Posts: 9


View Profile
« Reply #4 on: August 23, 2006, 06:53:26 AM »

Oldo,
https or http there is no problem with. In <Role><web><option> you have a check box where you can chose that the ive should accept certificates from untrusted webserver.

On you your first post it looks for me that you configured the sso as an URL in the bookmark page. This can't work.
The bookmark must be http(s)://<Exchange-Server>/exchange nothing else. The other things you must configure under <Ressource Policies><Web> <SSO Form Post>
Greetings
Joern
Logged
oldo
Sr. Member
****
Posts: 497


View Profile
« Reply #5 on: August 23, 2006, 07:42:20 AM »

Ahhh.. I finally get it. Thanks Joern! I did post it as a URL. Think I'll get it to work now! Thanks!!
Logged

JNCIA-FW, JNCIA-AC, JNCIS-SSL, Ironport ICSP, xSeries Specialist,
Frac
Hero Member
*****
Posts: 784


View Profile WWW
« Reply #6 on: August 23, 2006, 07:44:57 AM »

hi,

true joern, but no need for HTTPS! And i wouldn't enable "accept certf from untrusted webserver", because this means if people surf via SA to https servers, they can access wrong servers. (phising websites)

he doesn't need https anymore, because the SA will do that for him.

the other part is correct.

GreetZ,
Frac
Logged

JNCIS-FWV, JNCIS-ER, JNCIA-EX, JNCIA-IDP http://juniper-frac.blogspot.com
oldo
Sr. Member
****
Posts: 497


View Profile
« Reply #7 on: August 23, 2006, 07:57:27 AM »

Well, right now we are transfering users to the SA box, but not all of them have access yet. So in the furure you are right, we should scrap the self signed certificate on that site and close it from public access, (internet). But for a short period before all users are transferd we'll have to "accept cert from untrusted webserver". Thanks for your help and input!
Logged

JNCIA-FW, JNCIA-AC, JNCIS-SSL, Ironport ICSP, xSeries Specialist,
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
  • Total Members: 22514
  • Latest: Deepy
Stats
  • Total Posts: 40575
  • Total Topics: 11249
  • Online Today: 77
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 2
Guests: 58
Total: 60
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.219 seconds with 37 queries.