<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SharePoint George &#187; ISA</title>
	<atom:link href="http://sharepointgeorge.com/category/isa/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointgeorge.com</link>
	<description>Everyday experiences on SharePoint, Exchange and most things Microsoft</description>
	<lastBuildDate>Tue, 20 Dec 2011 23:01:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Outlook Web Access redirection via Microsoft ISA 2006</title>
		<link>http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/</link>
		<comments>http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 21:13:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[ISA]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/' addthis:title='Outlook Web Access redirection via Microsoft ISA 2006 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div>We all know from experience that advising end users to browse  to https://mail.yourdomain.com/OWA if you are running Exchange 2007 or /exchange if you are running Exchange 2003 is usually problematic .  Oh! and did I forget to mention that it’s HTTPS and not http!  We must admit that not all end users are likely going to remember this URL and at times even struggle to distinguish the difference between secure and non secure sites. <div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/' addthis:title='Outlook Web Access redirection via Microsoft ISA 2006 ' ><a href="//addthis.com/bookmark.php?v=250&#38;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">&#124;</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/' addthis:title='Outlook Web Access redirection via Microsoft ISA 2006 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div><p>We all know from experience that advising end users to browse  to https://mail.yourdomain.com/OWA if you are running Exchange 2007 or /exchange if you are running Exchange 2003 is usually problematic .  Oh! and did I forget to mention that it’s <strong>HTTPS </strong>and not http!  We must admit that not all end users are likely going to remember this URL and at times even struggle to distinguish the difference between secure and non secure sites.  Well if you are running ISA 2006 as an edge or secondary application layer firewall then we can easily simplify the URL that we will publish to our end users by creating a deny rule which will then automatically redirect them to the correct address.  By the end of this post,  your end users will only need to remember a simple URL in the form of  <em>mail.yourdomain.com (notice that http or https is not required). </em>This post is assuming that you already have an existing Exchange Publishing Rule in ISA 2006.  Note, that this technique can also be used for other websites that ISA may already be protecting such as SharePoint and Terminal Server Web Access.</p>
<p>Let’s begin by launching the ISA Management Console, and navigate to create a new web site publishing rule.  The New Access Rule Wizard will launch in which you will begin by specifying a name for your rule.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YBGQHrWI/AAAAAAAAAoM/O8SLrUMKbXA/s1600-h/Capture1%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Access Rule Wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YCNawM1I/AAAAAAAAAoQ/Vd8tp8a8bM4/Capture1_thumb%5B4%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="515" height="393" /></a></p>
<p>Select Deny as your Rule Action</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YCnQRKMI/AAAAAAAAAoU/X5meAitrPq0/s1600-h/Capture2%5B7%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Select Rule Action" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YDrxrfLI/AAAAAAAAAoY/mVxyfsSod0Q/Capture2_thumb%5B5%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="518" height="277" /></a></p>
<p>Select Publish a single web site or load balancer.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YEe72K7I/AAAAAAAAAoc/hmE162nNIuk/s1600-h/Capture3%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Publish a single web site or load balancer" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YFSUvqrI/AAAAAAAAAog/L1AOFDYmorM/Capture3_thumb%5B4%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="515" height="415" /></a></p>
<p>Select Use SSL to connect to the published Web server or server farm.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YGQ6eAlI/AAAAAAAAAok/8SqsM4uIGV0/s1600-h/Capture4%5B7%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Server Connection Security" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YHivX16I/AAAAAAAAAoo/rDGlIZdwYYI/Capture4_thumb%5B5%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="516" height="372" /></a></p>
<p>Enter your Internal Publishing Details which should be identical to the original Exchange Publishing rule.<a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SkDnB_W29HI/AAAAAAAAAp0/OQD3V6HzTII/s1600-h/Capture510.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Capture5" src="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YJSMpBvI/AAAAAAAAAp4/SbTbxJk7TIA/Capture5_thumb12.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="517" height="351" /></a></p>
<p>Click Next and then Next again skipping the Path details.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YKMP58JI/AAAAAAAAAo0/nAl6w6taqqA/s1600-h/Capture6%5B9%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Path ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YLMUsGTI/AAAAAAAAAo4/O2hL7AL8pBo/Capture6_thumb%5B5%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="519" height="291" /></a></p>
<p>Enter the Public Name details as per your original Exchange Publishing rule.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YLyMNDrI/AAAAAAAAAo8/m4PsmXLSZkE/s1600-h/Capture7%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Public Name Details" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YM3PFYlI/AAAAAAAAApA/zXDTwy8FiUI/Capture7_thumb%5B4%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="516" height="348" /></a></p>
<p>Select the existing Exchange Web listener that you already have created for your Exchange Publishing Rule.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YNtAnmYI/AAAAAAAAApE/dRj4R1beGfw/s1600-h/Capture8%5B8%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web listener" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YOQHfgtI/AAAAAAAAApI/Y0w4MZuax70/Capture8_thumb%5B6%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="515" height="243" /></a></p>
<p>Select, No delegation, and client cannot authenticate directly.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YPAlCmKI/AAAAAAAAApM/wZBy8YaJFlc/s1600-h/Capture9%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Authentication Delegation" src="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YP5m0sMI/AAAAAAAAApQ/WdWZZgL6R8M/Capture9_thumb%5B4%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="516" height="283" /></a></p>
<p>Remove Authenticated Users if present and select All Users instead.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YQ8Ms-KI/AAAAAAAAApU/CDsxRkJl1IE/s1600-h/Capture10%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA User Sets" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YRp42FaI/AAAAAAAAApY/_fP2NFYTb1Y/Capture10_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="517" height="247" /></a></p>
<p>You will then receive the below warning as we have selected All Users.  Ignore this warning and click on OK to continue.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YSQniFZI/AAAAAAAAApc/RSiN0kvWXtU/s1600-h/Capture11%5B8%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Warning" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YTFit-pI/AAAAAAAAApg/y08VzlMxbfY/Capture11_thumb%5B6%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="520" height="103" /></a></p>
<p>Now that the rule has been created, we need to specify the redirect page.  Right Click on the newly created rule and select properties.  Navigate to the Action tab and click on the check box beside “Redirect HTTP requests to this Web page:” and enter the full Outlook Web Access URL.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YUN9KTPI/AAAAAAAAApk/pp7njY7jkbQ/s1600-h/Capture12%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Outlook Web Access Redirection Properties" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YU3Fmn0I/AAAAAAAAApo/TvehkEDySxM/Capture12_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="410" height="360" /></a></p>
<p>We are now complete.  You will need to ensure that the deny rule is place immediately below the original Exchange Publishing Rule as per the below screen shot.  When a user now enters the url mail.yourdomain.com it will hit the redirection rule that we have just created which will then redirect to https://mail.yourdomain.com/owa and authenticate against your original Exchange OWA rule.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YVtFpbJI/AAAAAAAAAps/2ACL_bOH5G0/s1600-h/Capture13%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Rules" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YWEYgapI/AAAAAAAAApw/F7O--P6tK8k/Capture13_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="520" height="79" /></a></p>
<p>In summary we have removed the all so common confusion that end users may encounter when browsing to the Outlook Web Access site.  This methodology provided above with the deny rule can also be used against any other web site publishing rule including SharePoint Sites and Terminal Server Web Access.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/' addthis:title='Outlook Web Access redirection via Microsoft ISA 2006 ' ><a href="http://sharepointgeorge.com//addthis.com/bookmark.php?v=250&amp;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">|</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/outlook</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2</title>
		<link>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/</link>
		<comments>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 19:24:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[ISA]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SharePoint 2007]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div>In the second and last part of this series we will be focusing our efforts in securing our SharePoint Site through setting up a publishing rule in ISA 2006.  If you recall in the first article, we began our setup by extending the default SharePoint site into the Internet Zone, created a certificate request via IIS to be sent to a 3rd Party Certificate Authority and applied the certificate to our newly created extended site.<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2 ' ><a href="//addthis.com/bookmark.php?v=250&#38;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">&#124;</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div><p>In the second and last part of this series we will be focusing our efforts in securing our SharePoint Site through setting up a publishing rule in ISA 2006.  If you recall in the first article, we began our setup by extending the default SharePoint site into the Internet Zone, created a certificate request via IIS to be sent to a 3rd Party Certificate Authority and applied the certificate to our newly created extended site.  If you missed it, you can access part 1 <a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">here</a>.</p>
<p>So let’s begin the second part of our setup!  The first item we need to address is the newly created certificate that has been applied to our site in IIS.  ISA also needs to be aware of this certificate so we need to export it from IIS and then import it to the certificate store on the ISA server.  This certificate will be required when creating the web listener in the ISA rule later below.</p>
<p>To export the certificate, select it in IIS and select Export under Actions.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUB75SHAI/AAAAAAAAAmo/-mOJzsQJu-M/s1600-h/export6.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="export certificate isa sharepoint" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUChHy1EI/AAAAAAAAAms/hv01qQBd3UI/export_thumb4.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="212" height="301" /></a></p>
<p>Specify the export path and enter a password.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUDejlbXI/AAAAAAAAAmw/isc_sqJbVC8/s1600-h/export25.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="export certificate" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUEJM1SkI/AAAAAAAAAm0/QlnJ9yNb_54/export2_thumb3.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="343" height="275" /></a></p>
<p>After exporting the certificate, copy it to your ISA server and then launch the Certificate MMC snap-in from the ISA Server.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUFLuIldI/AAAAAAAAAm4/q1zBZUkQJ7E/s1600-h/export36.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate MMC Store " src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUGOvoUDI/AAAAAAAAAm8/JOnqpVnKxMc/export3_thumb4.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="470" height="283" /></a></p>
<p>Right click on the Personal Folder and select All Tasks /  Import.  This will invoke the Import Certificate Wizard.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUG_6vfSI/AAAAAAAAAnA/tYqR7YRYhdQ/s1600-h/wizard15.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="welcome to the certificate import wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUIEIVxNI/AAAAAAAAAnE/_XKovNoVAJ4/wizard1_thumb3.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="404" /></a></p>
<p>Click Next.  Browse for the certificate file that we exported and copied earlier.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjoUI8YUy1I/AAAAAAAAAnI/EPuzkCA4U_M/s1600-h/wizard25.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Certificate Import Qizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUJ9IR2eI/AAAAAAAAAnM/SmShK6kTz9E/wizard2_thumb3.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="405" /></a></p>
<p>Click Next.  Enter the password that we supplied to the exported certificate.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjoUK_xIxbI/AAAAAAAAAnQ/CsT26PWucAs/s1600-h/wizard46.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate import wizard ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUL0pKpbI/AAAAAAAAAnU/laE2naIJpLI/wizard4_thumb4.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="401" /></a></p>
<p>Click Next and ensure that the certificate is placed in the Personal Certificate Store.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUMgIjzKI/AAAAAAAAAnY/c9WGN67uuIM/s1600-h/wizard55.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Personal Certificate Import Wizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUNl0Oz4I/AAAAAAAAAnc/ZsQOPWH0GNo/wizard5_thumb3.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="403" /></a></p>
<p>Now that we have done the pre-work for ISA, it’s time to launch the ISA Server Management Console in order to create our SharePoint Publishing Rule.</p>
<ul>
<li>· Right click on Firewall Policy and select New / SharePoint Site Publishing Rule</li>
<li>· Specify a SharePoint publishing rule name</li>
<li>· Select your Publishing Type, in my case I selected <em>Publish a single Web site or load balancer.</em></li>
<li>· Click on <em>Use SSL to connect to the published Web server or server farm </em></li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcX9SFpCgI/AAAAAAAAAlo/Ukp3p35qI-Q/s1600-h/image%5B6%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint Publishing Rule ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcX-iFJP2I/AAAAAAAAAls/VpKVSrwrRHI/image_thumb%5B4%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="359" /></a></p>
<p>Type the Internal site name: The warning here states that the site name must match the common name or subject alternative name on the certificate. This should be the World Wide Web Address.</p>
<p>Then click on <em>Use a computer name or IP address to connect to the published server</em> and enter the correct details. This could potentially be a single server  IP or the IP address of your Network Load Balanced Cluster.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjtaVVAdINI/AAAAAAAAAn4/YFdlJMlxOQY/s1600-h/Capture1%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rule Wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjtaWVXv3xI/AAAAAAAAAn8/w50BPrfmgEk/Capture1_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="383" /></a></p>
<p>Specify the Public domain name.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjtaXLzp_wI/AAAAAAAAAoA/K2O72vifWQ8/s1600-h/Capture2%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Public Name Details FQDN" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjtaX9lgZcI/AAAAAAAAAoE/FVKiS9BgDrg/Capture2_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="517" height="245" /></a></p>
<p>We will now create a New Web Listener by clicking New. This will invoke the New Web Listener Wizard</p>
<ul>
<li>· Provide your web listener with a friendly name. e.g SharePoint FBA</li>
<li>· Select Require SSL secured connections with clients in the Client Connection Security Window</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcX_iZwobI/AAAAAAAAAlw/9_dpPZlE2h8/s1600-h/image%5B15%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Web Listener Definition Wizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYBH-fEEI/AAAAAAAAAl0/T8jT2EGASCU/image_thumb%5B11%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="357" /></a></p>
<ul>
<li>- Specify the Web Listener Internal IP address.  If you recall from <a href="http://www.gk.id.au/2009/06/securing-your-sharepoint-sites-with-isa.html">part 1</a>, this is a domain joined ISA server sitting in the internal network in between an existing edge firewall and your SharePoint Site.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcYCVeRo-I/AAAAAAAAAl4/3LsUHMBzCjM/s1600-h/image%5B24%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Web Listener Definiton Wizard ISA SharePoint" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYELDdajI/AAAAAAAAAl8/egACqlm0xLE/image_thumb%5B18%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="318" /></a></p>
<p>The next step requires you to select your SSL certificate. Depending on the number of certificates your ISA server is storing you will either select Single certificate (in the event you are using a SAN or wild card certificate) or assign a certificate for each IP address. In my case I am using singular certificates for my SharePoint Sites so I will assign a specific certificate against a unique IP address.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYE44oNPI/AAAAAAAAAmA/4oTcOicJmMY/s1600-h/image%5B30%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYF2XyQoI/AAAAAAAAAmE/_U2DdGoFRX8/image_thumb%5B22%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="352" /></a></p>
<p>You now need to select your Authentication Settings for the web listener. We are providing Forms based Authentication for our SharePoint Sites so I will select HTML Form Authentication and then select how ISA server will validate these. I am selecting Windows (Active Directory in my instance).</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYGu_LiyI/AAAAAAAAAmI/u1nUaBVe96I/s1600-h/image%5B36%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYH4pyZeI/AAAAAAAAAmM/fe1nkCb6OA4/image_thumb%5B26%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="355" /></a></p>
<ul>
<li>· Specify your Single Sign On Settings, Click Finish.</li>
<li>· Select your Authentication Delegation. In my case I am selecting NTLM</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYIy-4C0I/AAAAAAAAAmQ/Jiuwh6NPng0/s1600-h/image%5B42%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rile ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYJx_UIUI/AAAAAAAAAmU/oSAHjRs3ZaM/image_thumb%5B30%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="288" /></a></p>
<ul>
<li>· Select “SharePoint AAM is already configured on the SharePoint server. We completed this step after extending our site in Part 1 of this series.</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYK5cknJI/AAAAAAAAAmY/wQrnzs0yNCc/s1600-h/image%5B48%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ALternate Access Mapping AAM ISA SharePoint" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYMso905I/AAAAAAAAAmc/oDnQs2gRAiA/image_thumb%5B34%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="287" /></a></p>
<ul>
<li>· Select your User Sets</li>
</ul>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYNulv7lI/AAAAAAAAAmg/bzQaPRfzCcE/s1600-h/image%5B54%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rule ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYOkO7NqI/AAAAAAAAAmk/AKtarPvplw0/image_thumb%5B38%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="520" height="248" /></a></p>
<ul>
<li>· Then Click Finish to complete the Wizard.</li>
</ul>
<p>One of the great enhancements to ISA 2006 Service Pack 1, is the ability to test your rules automatically within the ISA Management console.  This will do the hard work for you and ensure that your rule is correctly setup and that your certificates are correctly in place.  All you need to do is right click on the rule that we have just created and select properties.</p>
<p>Under the General tab, click on the Test Rule button.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUOXV7IiI/AAAAAAAAAng/gFvI_ryW4Wo/s1600-h/test15.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web Publishing Rule" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUPe55ZVI/AAAAAAAAAnk/wWjdpkXhA9g/test1_thumb3.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="423" height="510" /></a></p>
<p>You should get green ticks as per below.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUQEnmvzI/AAAAAAAAAno/SWkhXFvvQ_I/s1600-h/test210.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Test Rule ISA Server" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUQ4WOmAI/AAAAAAAAAns/SIFXeJp19dU/test2_thumb8.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="247" height="260" /></a></p>
<p>We are done!  Our internal users can now navigate to the external published URL and get directed to ISA’s Forms Based Authentication screen as per below. After successfully authenticating with Active Directory via the ISA server the users will be automatically redirected to the SharePoint site.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoURriwj-I/AAAAAAAAAnw/BxoIXdyrT6I/s1600-h/image%5B19%5D%5B5%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Forms Based Authentication" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUSTCROFI/AAAAAAAAAn0/SKLTEyDoep8/image%5B19%5D_thumb%5B3%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2" width="501" height="361" /></a></p>
<p>Some important points to emphasise;</p>
<ul>
<li>Ensure your Alternate Access Mappings (AAM) are setup correctly for the correct zone.</li>
<li>Ensure your certificate common name matches the fully qualified external domain name which in turn matches the AAM in SharePoint.</li>
<li>Ensure that you have successfully exported the certificate from IIS Manager and Imported it to your Certificate store on the ISA Server.</li>
<li>Use the Test Rule Button in ISA 2006 SP1 to test your rule, so ensure you are running the latest Service Pack for your ISA server.</li>
</ul>
<p>___________________________________________</p>
<p>Articles in this series</p>
<ol>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2</a></li>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-22/" target="_blank">Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2</a></li>
</ol>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2 ' ><a href="http://sharepointgeorge.com//addthis.com/bookmark.php?v=250&amp;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">|</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/securing</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2</title>
		<link>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/</link>
		<comments>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 18:23:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[ISA]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SharePoint 2007]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div>Do you want to provide your information workers access to your SharePoint Site whilst out of the office easily from any internet connection without compromising security?  Do you want to accomplish this without complicated client-site VPN setups. <div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2 ' ><a href="//addthis.com/bookmark.php?v=250&#38;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">&#124;</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div><p>Do you want to provide your information workers access to your SharePoint Site whilst out of the office easily from any internet connection without compromising security?  Do you want to accomplish this without complicated client-site VPN setups.  In this 2 part series I will be providing you with step by step instructions explaining how you can leverage Microsoft’s Internet Security and Acceleration Server (ISA) 2006 and the out of the box SharePoint publishing rule to provide secure access for your corporate users using SSL.  YES! That’s right! Whether you like it or not, Microsoft ISA is a great reverse web proxy application firewall in which HTTP/HTTPS traffic from the internet is inspected first before it is forwarded onto the destination server, in our case our SharePoint web servers.  Microsoft ISA is also more than capable in providing you with a secure edge firewall as well.</p>
<p>Providing reverse web proxy is something that most major firewall vendors cannot accomplish out of the box including some of the big players like Checkpoint and Cisco.  ISA is an ideal choice of reverse proxy to place in between your existing edge firewall and your SharePoint server due to the application layer inspection filtering that is also provided.  Our ISA 2006 server should be domain joined in this instance as it will be acting as a dedicated reverse proxy and there are a lot of articles at <a href="http://www.isaserver.org">isaserver.org</a> supporting my case.</p>
<p>The below diagram is an example of how ISA can be strategically placed within your network.  In our example, all servers are running Windows Server 2008, SharePoint 2007 and ISA 2006 with the latest Service Packs applied at the time of this writing.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmvEmN3_I/AAAAAAAAAj4/ItXN_TXpuZQ/s1600-h/image%5B10%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmwE3qSnI/AAAAAAAAAj8/7fbL52fxt28/image_thumb%5B8%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="211" /></a></p>
<p>Our goal at the end of this 2 part series is to setup Forms-Based Authentication (FBA) (screen capture below) where users are forced to authenticate successfully with Active Directory first before being passed on to the SharePoint Server.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmwzx21lI/AAAAAAAAAkA/WDoSiHd0xMs/s1600-h/image%5B19%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA Server" src="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmxvRr5DI/AAAAAAAAAkE/yDzbGzB2FMI/image_thumb%5B15%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="501" height="361" /></a></p>
<p>So let’s begin. This post is assuming that you already have your current SharePoint Site setup correctly in IIS and Central Administration assigned to the Default Zone with Windows being our assigned Membership Provider. Our goal is to now be able to access the same SharePoint site outside of the corporate LAN via the World Wide Web using the same authentication method, i.e. via &lt;DOMAIN&gt;\&lt;Password&gt; . In order to do so, we need to extend the current site, ensure that the Alternate Access Mapping (AAM) is setup correctly and secure the extended site using  SSL via a 3<sup>rd</sup> party root certificate.</p>
<p><strong>Extend your existing SharePoint Site</strong></p>
<p>Browse to Central Administration / Application Management and under SharePoint Web Application Management, select</p>
<ul>
<li>· <em>Create or extend Web application<br />
</em>· Click on <em>Extend an existing Web application<br />
</em>· Select an existing Web application to Extend<br />
· Create a new IIS web site and type in your description<br />
· Port should be set to 443 (SSL)<br />
· Specify a Host Header : yousite.externalfullyqualifieddomain.com<br />
· Select <em>Yes</em> Use Secure Sockets Layer (SSL)<br />
· Select Internet for your Zone as requests are coming from world wide web<br />
· Click OK</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmyCFeG5I/AAAAAAAAAkI/B1UlUJc6G5c/s1600-h/clip_image002%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDmzAcnkPI/AAAAAAAAAkM/1U_oiD9j4qw/clip_image002_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="298" /></a></p>
<p><strong>Alternate Access Mappings (AAM)</strong></p>
<p>The Alternate access mappings for the zone should have been created for you and you can confirm this via Central Administration / Operations / Global Configuration / Alternate access mappings.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmz4fjg3I/AAAAAAAAAkQ/re8gM96qLG4/s1600-h/image%5B25%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint Alternative Access Mappings AAM" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm0oqyyyI/AAAAAAAAAkU/Gds0I2TriR4/image_thumb%5B19%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="95" /></a></p>
<p>More detailed information on Alternate Access Mappings (which I highly recommend) can be found at this TechNet Article <a href="http://technet.microsoft.com/en-us/library/cc288609.aspx">http://technet.microsoft.com/en-us/library/cc288609.aspx</a> (Plan alternate access mappings)</p>
<p>By default your Alternate access mappings for all 5 zones (Default, Intranet, Internet, Custom, Extranet) are set to use Windows as your Membership Provider Name which is what is required in this example. Recall that we want our users to authenticate using their Active Directory credentials. You can confirm the Membership provider for your zones via Central Administration / Application Management / Authentication Providers. Ensure the correct Web Application in question is selected first.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDm1VFux5I/AAAAAAAAAkY/GV3i-EMabXk/s1600-h/image%5B32%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm2kZWzoI/AAAAAAAAAkc/YUHpCuMe7vQ/image_thumb%5B24%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="250" /></a></p>
<p>Please also note that the extended Website will have been automatically created and listed in IIS Manager (Windows 2008)</p>
<p><strong>SSL and Certificate Creation</strong></p>
<p>We now need to create a certificate request that we will pass on to our preferred Certificate Authority (CA). Please note that it is best practice  to use an external CA to avoid SSL warnings and errors for your users when browsing to the site.  My preference is <a href="http://www.godaddy.com">Godaddy.com</a> who provide decently priced certificates, and no I am not a Godaddy reseller <img src='http://sharepointgeorge.com/wp-includes/images/smilies/icon_smile.gif' alt="icon smile Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" class='wp-smiley' title="Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" /> </p>
<p>In IIS 7 Windows 2008 this is done via Server Certificates located under the properties page of the IIS Server.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm3T0kgAI/AAAAAAAAAkg/96wHOe2oQdw/s1600-h/clip_image002%5B7%5D%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Server SharePoint" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm4Qh_-BI/AAAAAAAAAkk/HXa5esJYP08/clip_image002%5B7%5D_thumb%5B3%5D.jpg?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="341" /></a></p>
<ul>
<li>· Click on Server Certificates, under the IIS heading<br />
· Under Actions, Click on <em>Create Certificate Request<br />
</em>· Fill in the details; please note the Common name is important and should be the fully qualified domain name that is being accessed from the World Wide Web.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm5edsyDI/AAAAAAAAAko/y1fde6jOHBE/s1600-h/image%5B43%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA IIS Certificate Request" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDm6c_O7AI/AAAAAAAAAks/zHHQbotQvVU/image_thumb%5B33%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="389" /></a></p>
<ul>
<li>· Select your Cryptographic Service Provider Properties.<br />
· Specify the filename and location to output the certificate request (The contents of this file (MODIFIED EXAMPLE BELOW) is important as it will be required by your Certificate Authority. In my case I am using a 3<sup>rd</sup> Party Certificate Authority that will issue the certificate.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm7YZ0mPI/AAAAAAAAAkw/wLgwGlubqcM/s1600-h/image%5B49%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate Request IIS SSL" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm8gcaKbI/AAAAAAAAAk0/u8ssiF9WiL8/image_thumb%5B37%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="299" /></a></p>
<ul>
<li>· Once you have been issued with your certificate file from your Certificate Authority, go back into IIS Manager and re-launch Server Certificates and this time under Actions select <em>Complete Certificate Request<br />
</em>· Browse for the File Name and specify a Friendly name</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDm9lEMTcI/AAAAAAAAAk4/Ipakg-5C-tc/s1600-h/image%5B123%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Specify Certificate Authority Response" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm-kqOGLI/AAAAAAAAAk8/HpqS2nNhslA/image_thumb%5B107%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="270" /></a> <em></em></p>
<p>Upon completion of the wizard your certificate will appear beside the already self signed machine certificate in IIS7.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDm_sxc4hI/AAAAAAAAAlA/UHRA9TigvuE/s1600-h/image%5B122%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Server Certificates" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnAibU_tI/AAAAAAAAAlE/hKMtvh0AYUM/image_thumb%5B106%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="140" /></a></p>
<p>You will now need to apply the new certificate against the recently extended website.</p>
<ul>
<li>· Click on the Site you wish to apply the certificate and then click on SSL Settings.</li>
</ul>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDnBnzdLII/AAAAAAAAAlI/TGNNmYNbB1w/s1600-h/image%5B129%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Settings" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDnCXSrU7I/AAAAAAAAAlM/X0LIzSOr1D4/image_thumb%5B111%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="161" /></a></p>
<ul>
<li>· Select Require SSL and Require 128-bit SSL for your SSL settings and click on Apply</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnDJ7Cc2I/AAAAAAAAAlQ/IFszVmXb1jo/s1600-h/image%5B135%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Settings SharePoint IIS7" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnDw9fMjI/AAAAAAAAAlU/YnyONs2BX6k/image_thumb%5B115%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="498" height="243" /></a></p>
<p>We now need to apply our newly imported certificate to the extended site by clicking again on the extended site, and under Actions select Bindings and then click on Edit.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDnEUrHFZI/AAAAAAAAAlY/wvV_EiMRYGw/s1600-h/image%5B143%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Bindings" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnFHr6XTI/AAAAAAAAAlc/7rsFPcTCBhc/image_thumb%5B119%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="194" height="202" /></a></p>
<p>Select the newly added SSL certificate from the drop down and ensure the port and IP address settings are correct.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnFsMU0hI/AAAAAAAAAlg/x8I1bl_xjZM/s1600-h/image%5B145%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Edit Site Binding" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnGvjQM6I/AAAAAAAAAlk/f809qoN3uBc/image_thumb%5B121%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="260" height="147" /></a></p>
<p>Our site is now secure and ready to be accessed via the World Wide Web, well almost!  Stay tuned for next week for part 2 of this article, in which we will be focusing on the configuration of ISA 2006 and how we can leverage the inbuilt SharePoint Publishing Wizard to allow external access to our SharePoint site via SSL and Windows Forms Based Authentication.</p>
<p>___________________________________________</p>
<p>Articles in this series</p>
<ol>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">Securing your SharePoint Sites with ISA 2006 using  Forms Based Authentication – Part 1/2</a></li>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-22/" target="_blank">Securing your SharePoint Sites with ISA 2006 using  Forms Based Authentication – Part 2/2</a></li>
</ol>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/' addthis:title='Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2 ' ><a href="http://sharepointgeorge.com//addthis.com/bookmark.php?v=250&amp;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">|</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/securing</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

