<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SharePoint George &#187; ISA</title>
	<atom:link href="http://sharepointgeorge.com/category/isa/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointgeorge.com</link>
	<description>Everyday experiences on SharePoint, Exchange and most things Microsoft</description>
	<lastBuildDate>Mon, 26 Jul 2010 12:30:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Outlook Web Access redirection via Microsoft ISA 2006</title>
		<link>http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/</link>
		<comments>http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 21:13:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[ISA]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/outlook-web-access-redirection-via-microsoft-isa-2006/</guid>
		<description><![CDATA[We all know from experience that advising end users to browse  to https://mail.yourdomain.com/OWA if you are running Exchange 2007 or /exchange if you are running Exchange 2003 is usually problematic .  Oh! and did I forget to mention that it’s HTTPS and not http!  We must admit that not all end users are likely going to remember this URL and at times even struggle to distinguish the difference between secure and non secure sites. ]]></description>
			<content:encoded><![CDATA[<p>We all know from experience that advising end users to browse  to https://mail.yourdomain.com/OWA if you are running Exchange 2007 or /exchange if you are running Exchange 2003 is usually problematic .  Oh! and did I forget to mention that it’s <strong>HTTPS </strong>and not http!  We must admit that not all end users are likely going to remember this URL and at times even struggle to distinguish the difference between secure and non secure sites.  Well if you are running ISA 2006 as an edge or secondary application layer firewall then we can easily simplify the URL that we will publish to our end users by creating a deny rule which will then automatically redirect them to the correct address.  By the end of this post,  your end users will only need to remember a simple URL in the form of  <em>mail.yourdomain.com (notice that http or https is not required). </em>This post is assuming that you already have an existing Exchange Publishing Rule in ISA 2006.  Note, that this technique can also be used for other websites that ISA may already be protecting such as SharePoint and Terminal Server Web Access.</p>
<p>Let’s begin by launching the ISA Management Console, and navigate to create a new web site publishing rule.  The New Access Rule Wizard will launch in which you will begin by specifying a name for your rule.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YBGQHrWI/AAAAAAAAAoM/O8SLrUMKbXA/s1600-h/Capture1%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Access Rule Wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YCNawM1I/AAAAAAAAAoQ/Vd8tp8a8bM4/Capture1_thumb%5B4%5D.jpg?imgmax=800" border="0" alt="New Access Rule Wizard" width="515" height="393" /></a></p>
<p>Select Deny as your Rule Action</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YCnQRKMI/AAAAAAAAAoU/X5meAitrPq0/s1600-h/Capture2%5B7%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Select Rule Action" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YDrxrfLI/AAAAAAAAAoY/mVxyfsSod0Q/Capture2_thumb%5B5%5D.jpg?imgmax=800" border="0" alt="ISA Select Rule Action" width="518" height="277" /></a></p>
<p>Select Publish a single web site or load balancer.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YEe72K7I/AAAAAAAAAoc/hmE162nNIuk/s1600-h/Capture3%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Publish a single web site or load balancer" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YFSUvqrI/AAAAAAAAAog/L1AOFDYmorM/Capture3_thumb%5B4%5D.jpg?imgmax=800" border="0" alt="Publish a single web site or load balancer" width="515" height="415" /></a></p>
<p>Select Use SSL to connect to the published Web server or server farm.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YGQ6eAlI/AAAAAAAAAok/8SqsM4uIGV0/s1600-h/Capture4%5B7%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Server Connection Security" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YHivX16I/AAAAAAAAAoo/rDGlIZdwYYI/Capture4_thumb%5B5%5D.jpg?imgmax=800" border="0" alt="Server Connection Security" width="516" height="372" /></a></p>
<p>Enter your Internal Publishing Details which should be identical to the original Exchange Publishing rule.<a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SkDnB_W29HI/AAAAAAAAAp0/OQD3V6HzTII/s1600-h/Capture510.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Capture5" src="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YJSMpBvI/AAAAAAAAAp4/SbTbxJk7TIA/Capture5_thumb12.jpg?imgmax=800" border="0" alt=" Outlook Web Access redirection via Microsoft ISA 2006" width="517" height="351" /></a></p>
<p>Click Next and then Next again skipping the Path details.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YKMP58JI/AAAAAAAAAo0/nAl6w6taqqA/s1600-h/Capture6%5B9%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Path ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YLMUsGTI/AAAAAAAAAo4/O2hL7AL8pBo/Capture6_thumb%5B5%5D.jpg?imgmax=800" border="0" alt="Path ISA" width="519" height="291" /></a></p>
<p>Enter the Public Name details as per your original Exchange Publishing rule.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YLyMNDrI/AAAAAAAAAo8/m4PsmXLSZkE/s1600-h/Capture7%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Public Name Details" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YM3PFYlI/AAAAAAAAApA/zXDTwy8FiUI/Capture7_thumb%5B4%5D.jpg?imgmax=800" border="0" alt="Public Name Details" width="516" height="348" /></a></p>
<p>Select the existing Exchange Web listener that you already have created for your Exchange Publishing Rule.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YNtAnmYI/AAAAAAAAApE/dRj4R1beGfw/s1600-h/Capture8%5B8%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web listener" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YOQHfgtI/AAAAAAAAApI/Y0w4MZuax70/Capture8_thumb%5B6%5D.jpg?imgmax=800" border="0" alt="Web listener" width="515" height="243" /></a></p>
<p>Select, No delegation, and client cannot authenticate directly.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YPAlCmKI/AAAAAAAAApM/wZBy8YaJFlc/s1600-h/Capture9%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Authentication Delegation" src="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YP5m0sMI/AAAAAAAAApQ/WdWZZgL6R8M/Capture9_thumb%5B4%5D.jpg?imgmax=800" border="0" alt="Authentication Delegation" width="516" height="283" /></a></p>
<p>Remove Authenticated Users if present and select All Users instead.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YQ8Ms-KI/AAAAAAAAApU/CDsxRkJl1IE/s1600-h/Capture10%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA User Sets" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YRp42FaI/AAAAAAAAApY/_fP2NFYTb1Y/Capture10_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="ISA User Sets" width="517" height="247" /></a></p>
<p>You will then receive the below warning as we have selected All Users.  Ignore this warning and click on OK to continue.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YSQniFZI/AAAAAAAAApc/RSiN0kvWXtU/s1600-h/Capture11%5B8%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Warning" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YTFit-pI/AAAAAAAAApg/y08VzlMxbfY/Capture11_thumb%5B6%5D.jpg?imgmax=800" border="0" alt="Warning" width="520" height="103" /></a></p>
<p>Now that the rule has been created, we need to specify the redirect page.  Right Click on the newly created rule and select properties.  Navigate to the Action tab and click on the check box beside “Redirect HTTP requests to this Web page:” and enter the full Outlook Web Access URL.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/Sj9YUN9KTPI/AAAAAAAAApk/pp7njY7jkbQ/s1600-h/Capture12%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Outlook Web Access Redirection Properties" src="http://lh5.ggpht.com/_jC8JMIc-c-0/Sj9YU3Fmn0I/AAAAAAAAApo/TvehkEDySxM/Capture12_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="Outlook Web Access Redirection Properties" width="410" height="360" /></a></p>
<p>We are now complete.  You will need to ensure that the deny rule is place immediately below the original Exchange Publishing Rule as per the below screen shot.  When a user now enters the url mail.yourdomain.com it will hit the redirection rule that we have just created which will then redirect to https://mail.yourdomain.com/owa and authenticate against your original Exchange OWA rule.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/Sj9YVtFpbJI/AAAAAAAAAps/2ACL_bOH5G0/s1600-h/Capture13%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Rules" src="http://lh4.ggpht.com/_jC8JMIc-c-0/Sj9YWEYgapI/AAAAAAAAApw/F7O--P6tK8k/Capture13_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="ISA Rules" width="520" height="79" /></a></p>
<p>In summary we have removed the all so common confusion that end users may encounter when browsing to the Outlook Web Access site.  This methodology provided above with the deny rule can also be used against any other web site publishing rule including SharePoint Sites and Terminal Server Web Access.</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>If you enjoyed this article, consider sharing it with one of the below social networking sites:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;notes=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="del.icio.us"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;bodytext=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="Digg"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;annotation=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="Google Bookmarks"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;t=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="Facebook"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.friendfeed.com/share?title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F" title="FriendFeed"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;source=SharePoint+George+Everyday+experiences+on+SharePoint%2C+Exchange+and+most+things+Microsoft&amp;summary=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="LinkedIn"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;t=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="MySpace"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://sharepointgeorge.com/feed/" title="RSS"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="StumbleUpon"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F" title="Technorati"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="Reddit"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F" title="Fark"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="Live"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;h=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006" title="NewsVine"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;partner=sociable" title="PDF"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/pdf.png" title="PDF" alt="PDF" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;body=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="Ping.fm"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;title=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;selection=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20" title="Posterous"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/posterous.png" title="Posterous" alt="Posterous" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Foutlook-web-access-redirection-via-microsoft-isa-2006%2F&amp;submitHeadline=Outlook%20Web%20Access%20redirection%20via%20Microsoft%20ISA%202006&amp;submitSummary=We%20all%20know%20from%20experience%20that%20advising%20end%20users%20to%20browse%20%20to%20https%3A%2F%2Fmail.yourdomain.com%2FOWA%20if%20you%20are%20running%20Exchange%202007%20or%20%2Fexchange%20if%20you%20are%20running%20Exchange%202003%20is%20usually%20problematic%20.%20%20Oh%21%20and%20did%20I%20forget%20to%20mention%20that%20it%E2%80%99s%20HTTPS%20and%20not%20http%21%20%20We%20must%20admit%20that%20not%20all%20end%20users%20are%20likely%20going%20to%20remember%20this%20URL%20and%20at%20times%20even%20struggle%20to%20distinguish%20the%20difference%20between%20secure%20and%20non%20secure%20sites.%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/outlook</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2</title>
		<link>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/</link>
		<comments>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 19:24:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[ISA]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SharePoint 2007]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-22/</guid>
		<description><![CDATA[In the second and last part of this series we will be focusing our efforts in securing our SharePoint Site through setting up a publishing rule in ISA 2006.  If you recall in the first article, we began our setup by extending the default SharePoint site into the Internet Zone, created a certificate request via IIS to be sent to a 3rd Party Certificate Authority and applied the certificate to our newly created extended site.]]></description>
			<content:encoded><![CDATA[<p>In the second and last part of this series we will be focusing our efforts in securing our SharePoint Site through setting up a publishing rule in ISA 2006.  If you recall in the first article, we began our setup by extending the default SharePoint site into the Internet Zone, created a certificate request via IIS to be sent to a 3rd Party Certificate Authority and applied the certificate to our newly created extended site.  If you missed it, you can access part 1 <a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">here</a>.</p>
<p>So let’s begin the second part of our setup!  The first item we need to address is the newly created certificate that has been applied to our site in IIS.  ISA also needs to be aware of this certificate so we need to export it from IIS and then import it to the certificate store on the ISA server.  This certificate will be required when creating the web listener in the ISA rule later below.</p>
<p>To export the certificate, select it in IIS and select Export under Actions.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUB75SHAI/AAAAAAAAAmo/-mOJzsQJu-M/s1600-h/export6.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="export certificate isa sharepoint" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUChHy1EI/AAAAAAAAAms/hv01qQBd3UI/export_thumb4.jpg?imgmax=800" border="0" alt="export certificate isa sharepoint" width="212" height="301" /></a></p>
<p>Specify the export path and enter a password.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUDejlbXI/AAAAAAAAAmw/isc_sqJbVC8/s1600-h/export25.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="export certificate" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUEJM1SkI/AAAAAAAAAm0/QlnJ9yNb_54/export2_thumb3.jpg?imgmax=800" border="0" alt="export certificate" width="343" height="275" /></a></p>
<p>After exporting the certificate, copy it to your ISA server and then launch the Certificate MMC snap-in from the ISA Server.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUFLuIldI/AAAAAAAAAm4/q1zBZUkQJ7E/s1600-h/export36.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate MMC Store " src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUGOvoUDI/AAAAAAAAAm8/JOnqpVnKxMc/export3_thumb4.jpg?imgmax=800" border="0" alt="certificate MMC Store " width="470" height="283" /></a></p>
<p>Right click on the Personal Folder and select All Tasks /  Import.  This will invoke the Import Certificate Wizard.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUG_6vfSI/AAAAAAAAAnA/tYqR7YRYhdQ/s1600-h/wizard15.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="welcome to the certificate import wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUIEIVxNI/AAAAAAAAAnE/_XKovNoVAJ4/wizard1_thumb3.jpg?imgmax=800" border="0" alt="welcome to the certificate import wizard" width="520" height="404" /></a></p>
<p>Click Next.  Browse for the certificate file that we exported and copied earlier.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjoUI8YUy1I/AAAAAAAAAnI/EPuzkCA4U_M/s1600-h/wizard25.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Certificate Import Qizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUJ9IR2eI/AAAAAAAAAnM/SmShK6kTz9E/wizard2_thumb3.jpg?imgmax=800" border="0" alt="Certificate Import Qizard" width="520" height="405" /></a></p>
<p>Click Next.  Enter the password that we supplied to the exported certificate.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjoUK_xIxbI/AAAAAAAAAnQ/CsT26PWucAs/s1600-h/wizard46.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate import wizard ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUL0pKpbI/AAAAAAAAAnU/laE2naIJpLI/wizard4_thumb4.jpg?imgmax=800" border="0" alt="certificate import wizard ISA" width="520" height="401" /></a></p>
<p>Click Next and ensure that the certificate is placed in the Personal Certificate Store.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUMgIjzKI/AAAAAAAAAnY/c9WGN67uuIM/s1600-h/wizard55.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Personal Certificate Import Wizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUNl0Oz4I/AAAAAAAAAnc/ZsQOPWH0GNo/wizard5_thumb3.jpg?imgmax=800" border="0" alt="Personal Certificate Import Wizard" width="520" height="403" /></a></p>
<p>Now that we have done the pre-work for ISA, it’s time to launch the ISA Server Management Console in order to create our SharePoint Publishing Rule.</p>
<ul>
<li>· Right click on Firewall Policy and select New / SharePoint Site Publishing Rule</li>
<li>· Specify a SharePoint publishing rule name</li>
<li>· Select your Publishing Type, in my case I selected <em>Publish a single Web site or load balancer.</em></li>
<li>· Click on <em>Use SSL to connect to the published Web server or server farm </em></li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcX9SFpCgI/AAAAAAAAAlo/Ukp3p35qI-Q/s1600-h/image%5B6%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint Publishing Rule ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcX-iFJP2I/AAAAAAAAAls/VpKVSrwrRHI/image_thumb%5B4%5D.png?imgmax=800" border="0" alt="SharePoint Publishing Rule ISA" width="520" height="359" /></a></p>
<p>Type the Internal site name: The warning here states that the site name must match the common name or subject alternative name on the certificate. This should be the World Wide Web Address.</p>
<p>Then click on <em>Use a computer name or IP address to connect to the published server</em> and enter the correct details. This could potentially be a single server  IP or the IP address of your Network Load Balanced Cluster.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjtaVVAdINI/AAAAAAAAAn4/YFdlJMlxOQY/s1600-h/Capture1%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rule Wizard" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjtaWVXv3xI/AAAAAAAAAn8/w50BPrfmgEk/Capture1_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="New SharePoint Publishing Rule Wizard" width="520" height="383" /></a></p>
<p>Specify the Public domain name.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjtaXLzp_wI/AAAAAAAAAoA/K2O72vifWQ8/s1600-h/Capture2%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Public Name Details FQDN" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjtaX9lgZcI/AAAAAAAAAoE/FVKiS9BgDrg/Capture2_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="Public Name Details FQDN" width="517" height="245" /></a></p>
<p>We will now create a New Web Listener by clicking New. This will invoke the New Web Listener Wizard</p>
<ul>
<li>· Provide your web listener with a friendly name. e.g SharePoint FBA</li>
<li>· Select Require SSL secured connections with clients in the Client Connection Security Window</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcX_iZwobI/AAAAAAAAAlw/9_dpPZlE2h8/s1600-h/image%5B15%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Web Listener Definition Wizard" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYBH-fEEI/AAAAAAAAAl0/T8jT2EGASCU/image_thumb%5B11%5D.png?imgmax=800" border="0" alt="New Web Listener Definition Wizard" width="520" height="357" /></a></p>
<ul>
<li>- Specify the Web Listener Internal IP address.  If you recall from <a href="http://www.gk.id.au/2009/06/securing-your-sharepoint-sites-with-isa.html">part 1</a>, this is a domain joined ISA server sitting in the internal network in between an existing edge firewall and your SharePoint Site.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjcYCVeRo-I/AAAAAAAAAl4/3LsUHMBzCjM/s1600-h/image%5B24%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New Web Listener Definiton Wizard ISA SharePoint" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYELDdajI/AAAAAAAAAl8/egACqlm0xLE/image_thumb%5B18%5D.png?imgmax=800" border="0" alt="New Web Listener Definiton Wizard ISA SharePoint" width="520" height="318" /></a></p>
<p>The next step requires you to select your SSL certificate. Depending on the number of certificates your ISA server is storing you will either select Single certificate (in the event you are using a SAN or wild card certificate) or assign a certificate for each IP address. In my case I am using singular certificates for my SharePoint Sites so I will assign a specific certificate against a unique IP address.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYE44oNPI/AAAAAAAAAmA/4oTcOicJmMY/s1600-h/image%5B30%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYF2XyQoI/AAAAAAAAAmE/_U2DdGoFRX8/image_thumb%5B22%5D.png?imgmax=800" border="0" alt="SharePoint ISA" width="520" height="352" /></a></p>
<p>You now need to select your Authentication Settings for the web listener. We are providing Forms based Authentication for our SharePoint Sites so I will select HTML Form Authentication and then select how ISA server will validate these. I am selecting Windows (Active Directory in my instance).</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYGu_LiyI/AAAAAAAAAmI/u1nUaBVe96I/s1600-h/image%5B36%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYH4pyZeI/AAAAAAAAAmM/fe1nkCb6OA4/image_thumb%5B26%5D.png?imgmax=800" border="0" alt="SharePoint ISA" width="520" height="355" /></a></p>
<ul>
<li>· Specify your Single Sign On Settings, Click Finish.</li>
<li>· Select your Authentication Delegation. In my case I am selecting NTLM</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYIy-4C0I/AAAAAAAAAmQ/Jiuwh6NPng0/s1600-h/image%5B42%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rile ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYJx_UIUI/AAAAAAAAAmU/oSAHjRs3ZaM/image_thumb%5B30%5D.png?imgmax=800" border="0" alt="New SharePoint Publishing Rile ISA" width="520" height="288" /></a></p>
<ul>
<li>· Select “SharePoint AAM is already configured on the SharePoint server. We completed this step after extending our site in Part 1 of this series.</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYK5cknJI/AAAAAAAAAmY/wQrnzs0yNCc/s1600-h/image%5B48%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ALternate Access Mapping AAM ISA SharePoint" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjcYMso905I/AAAAAAAAAmc/oDnQs2gRAiA/image_thumb%5B34%5D.png?imgmax=800" border="0" alt="ALternate Access Mapping AAM ISA SharePoint" width="520" height="287" /></a></p>
<ul>
<li>· Select your User Sets</li>
</ul>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYNulv7lI/AAAAAAAAAmg/bzQaPRfzCcE/s1600-h/image%5B54%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="New SharePoint Publishing Rule ISA" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjcYOkO7NqI/AAAAAAAAAmk/AKtarPvplw0/image_thumb%5B38%5D.png?imgmax=800" border="0" alt="New SharePoint Publishing Rule ISA" width="520" height="248" /></a></p>
<ul>
<li>· Then Click Finish to complete the Wizard.</li>
</ul>
<p>One of the great enhancements to ISA 2006 Service Pack 1, is the ability to test your rules automatically within the ISA Management console.  This will do the hard work for you and ensure that your rule is correctly setup and that your certificates are correctly in place.  All you need to do is right click on the rule that we have just created and select properties.</p>
<p>Under the General tab, click on the Test Rule button.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjoUOXV7IiI/AAAAAAAAAng/gFvI_ryW4Wo/s1600-h/test15.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web Publishing Rule" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUPe55ZVI/AAAAAAAAAnk/wWjdpkXhA9g/test1_thumb3.jpg?imgmax=800" border="0" alt="Web Publishing Rule" width="423" height="510" /></a></p>
<p>You should get green ticks as per below.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUQEnmvzI/AAAAAAAAAno/SWkhXFvvQ_I/s1600-h/test210.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Test Rule ISA Server" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjoUQ4WOmAI/AAAAAAAAAns/SIFXeJp19dU/test2_thumb8.jpg?imgmax=800" border="0" alt="Test Rule ISA Server" width="247" height="260" /></a></p>
<p>We are done!  Our internal users can now navigate to the external published URL and get directed to ISA’s Forms Based Authentication screen as per below. After successfully authenticating with Active Directory via the ISA server the users will be automatically redirected to the SharePoint site.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoURriwj-I/AAAAAAAAAnw/BxoIXdyrT6I/s1600-h/image%5B19%5D%5B5%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Forms Based Authentication" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjoUSTCROFI/AAAAAAAAAn0/SKLTEyDoep8/image%5B19%5D_thumb%5B3%5D.png?imgmax=800" border="0" alt="ISA Forms Based Authentication" width="501" height="361" /></a></p>
<p>Some important points to emphasise;</p>
<ul>
<li>Ensure your Alternate Access Mappings (AAM) are setup correctly for the correct zone.</li>
<li>Ensure your certificate common name matches the fully qualified external domain name which in turn matches the AAM in SharePoint.</li>
<li>Ensure that you have successfully exported the certificate from IIS Manager and Imported it to your Certificate store on the ISA Server.</li>
<li>Use the Test Rule Button in ISA 2006 SP1 to test your rule, so ensure you are running the latest Service Pack for your ISA server.</li>
</ul>
<p>___________________________________________</p>
<p>Articles in this series</p>
<ol>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2</a></li>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-22/" target="_blank">Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 2/2</a></li>
</ol>

<div class="sociable">
<div class="sociable_tagline">
<strong>If you enjoyed this article, consider sharing it with one of the below social networking sites:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;notes=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="del.icio.us"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;bodytext=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="Digg"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;annotation=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="Google Bookmarks"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;t=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="Facebook"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.friendfeed.com/share?title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F" title="FriendFeed"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;source=SharePoint+George+Everyday+experiences+on+SharePoint%2C+Exchange+and+most+things+Microsoft&amp;summary=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="LinkedIn"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;t=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="MySpace"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://sharepointgeorge.com/feed/" title="RSS"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="StumbleUpon"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F" title="Technorati"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="Reddit"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F" title="Fark"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="Live"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;h=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2" title="NewsVine"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;partner=sociable" title="PDF"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/pdf.png" title="PDF" alt="PDF" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;body=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="Ping.fm"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;selection=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site." title="Posterous"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/posterous.png" title="Posterous" alt="Posterous" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-22%2F&amp;submitHeadline=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%202%2F2&amp;submitSummary=In%20the%20second%20and%20last%20part%20of%20this%20series%20we%20will%20be%20focusing%20our%20efforts%20in%20securing%20our%20SharePoint%20Site%20through%20setting%20up%20a%20publishing%20rule%20in%20ISA%202006.%20%20If%20you%20recall%20in%20the%20first%20article%2C%20we%20began%20our%20setup%20by%20extending%20the%20default%20SharePoint%20site%20into%20the%20Internet%20Zone%2C%20created%20a%20certificate%20request%20via%20IIS%20to%20be%20sent%20to%20a%203rd%20Party%20Certificate%20Authority%20and%20applied%20the%20certificate%20to%20our%20newly%20created%20extended%20site.&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/securing</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2</title>
		<link>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/</link>
		<comments>http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 18:23:00 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[ISA]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SharePoint 2007]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%e2%80%93-part-12/</guid>
		<description><![CDATA[Do you want to provide your information workers access to your SharePoint Site whilst out of the office easily from any internet connection without compromising security?  Do you want to accomplish this without complicated client-site VPN setups. ]]></description>
			<content:encoded><![CDATA[<p>Do you want to provide your information workers access to your SharePoint Site whilst out of the office easily from any internet connection without compromising security?  Do you want to accomplish this without complicated client-site VPN setups.  In this 2 part series I will be providing you with step by step instructions explaining how you can leverage Microsoft’s Internet Security and Acceleration Server (ISA) 2006 and the out of the box SharePoint publishing rule to provide secure access for your corporate users using SSL.  YES! That’s right! Whether you like it or not, Microsoft ISA is a great reverse web proxy application firewall in which HTTP/HTTPS traffic from the internet is inspected first before it is forwarded onto the destination server, in our case our SharePoint web servers.  Microsoft ISA is also more than capable in providing you with a secure edge firewall as well.</p>
<p>Providing reverse web proxy is something that most major firewall vendors cannot accomplish out of the box including some of the big players like Checkpoint and Cisco.  ISA is an ideal choice of reverse proxy to place in between your existing edge firewall and your SharePoint server due to the application layer inspection filtering that is also provided.  Our ISA 2006 server should be domain joined in this instance as it will be acting as a dedicated reverse proxy and there are a lot of articles at <a href="http://www.isaserver.org">isaserver.org</a> supporting my case.</p>
<p>The below diagram is an example of how ISA can be strategically placed within your network.  In our example, all servers are running Windows Server 2008, SharePoint 2007 and ISA 2006 with the latest Service Packs applied at the time of this writing.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmvEmN3_I/AAAAAAAAAj4/ItXN_TXpuZQ/s1600-h/image%5B10%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmwE3qSnI/AAAAAAAAAj8/7fbL52fxt28/image_thumb%5B8%5D.png?imgmax=800" border="0" alt="SharePoint ISA" width="520" height="211" /></a></p>
<p>Our goal at the end of this 2 part series is to setup Forms-Based Authentication (FBA) (screen capture below) where users are forced to authenticate successfully with Active Directory first before being passed on to the SharePoint Server.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmwzx21lI/AAAAAAAAAkA/WDoSiHd0xMs/s1600-h/image%5B19%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA Server" src="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDmxvRr5DI/AAAAAAAAAkE/yDzbGzB2FMI/image_thumb%5B15%5D.png?imgmax=800" border="0" alt="SharePoint ISA Server" width="501" height="361" /></a></p>
<p>So let’s begin. This post is assuming that you already have your current SharePoint Site setup correctly in IIS and Central Administration assigned to the Default Zone with Windows being our assigned Membership Provider. Our goal is to now be able to access the same SharePoint site outside of the corporate LAN via the World Wide Web using the same authentication method, i.e. via &lt;DOMAIN&gt;\&lt;Password&gt; . In order to do so, we need to extend the current site, ensure that the Alternate Access Mapping (AAM) is setup correctly and secure the extended site using  SSL via a 3<sup>rd</sup> party root certificate.</p>
<p><strong>Extend your existing SharePoint Site</strong></p>
<p>Browse to Central Administration / Application Management and under SharePoint Web Application Management, select</p>
<ul>
<li>· <em>Create or extend Web application<br />
</em>· Click on <em>Extend an existing Web application<br />
</em>· Select an existing Web application to Extend<br />
· Create a new IIS web site and type in your description<br />
· Port should be set to 443 (SSL)<br />
· Specify a Host Header : yousite.externalfullyqualifieddomain.com<br />
· Select <em>Yes</em> Use Secure Sockets Layer (SSL)<br />
· Select Internet for your Zone as requests are coming from world wide web<br />
· Click OK</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmyCFeG5I/AAAAAAAAAkI/B1UlUJc6G5c/s1600-h/clip_image002%5B6%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDmzAcnkPI/AAAAAAAAAkM/1U_oiD9j4qw/clip_image002_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="SharePoint ISA" width="520" height="298" /></a></p>
<p><strong>Alternate Access Mappings (AAM)</strong></p>
<p>The Alternate access mappings for the zone should have been created for you and you can confirm this via Central Administration / Operations / Global Configuration / Alternate access mappings.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDmz4fjg3I/AAAAAAAAAkQ/re8gM96qLG4/s1600-h/image%5B25%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint Alternative Access Mappings AAM" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm0oqyyyI/AAAAAAAAAkU/Gds0I2TriR4/image_thumb%5B19%5D.png?imgmax=800" border="0" alt="SharePoint Alternative Access Mappings AAM" width="520" height="95" /></a></p>
<p>More detailed information on Alternate Access Mappings (which I highly recommend) can be found at this TechNet Article <a href="http://technet.microsoft.com/en-us/library/cc288609.aspx">http://technet.microsoft.com/en-us/library/cc288609.aspx</a> (Plan alternate access mappings)</p>
<p>By default your Alternate access mappings for all 5 zones (Default, Intranet, Internet, Custom, Extranet) are set to use Windows as your Membership Provider Name which is what is required in this example. Recall that we want our users to authenticate using their Active Directory credentials. You can confirm the Membership provider for your zones via Central Administration / Application Management / Authentication Providers. Ensure the correct Web Application in question is selected first.</p>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDm1VFux5I/AAAAAAAAAkY/GV3i-EMabXk/s1600-h/image%5B32%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm2kZWzoI/AAAAAAAAAkc/YUHpCuMe7vQ/image_thumb%5B24%5D.png?imgmax=800" border="0" alt=" Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" width="520" height="250" /></a></p>
<p>Please also note that the extended Website will have been automatically created and listed in IIS Manager (Windows 2008)</p>
<p><strong>SSL and Certificate Creation</strong></p>
<p>We now need to create a certificate request that we will pass on to our preferred Certificate Authority (CA). Please note that it is best practice  to use an external CA to avoid SSL warnings and errors for your users when browsing to the site.  My preference is <a href="http://www.godaddy.com">Godaddy.com</a> who provide decently priced certificates, and no I am not a Godaddy reseller <img src='http://sharepointgeorge.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' title="Securing your SharePoint Sites with ISA 2006 using Forms Based Authentication – Part 1/2" /> </p>
<p>In IIS 7 Windows 2008 this is done via Server Certificates located under the properties page of the IIS Server.</p>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm3T0kgAI/AAAAAAAAAkg/96wHOe2oQdw/s1600-h/clip_image002%5B7%5D%5B5%5D.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ISA Server SharePoint" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm4Qh_-BI/AAAAAAAAAkk/HXa5esJYP08/clip_image002%5B7%5D_thumb%5B3%5D.jpg?imgmax=800" border="0" alt="ISA Server SharePoint" width="520" height="341" /></a></p>
<ul>
<li>· Click on Server Certificates, under the IIS heading<br />
· Under Actions, Click on <em>Create Certificate Request<br />
</em>· Fill in the details; please note the Common name is important and should be the fully qualified domain name that is being accessed from the World Wide Web.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm5edsyDI/AAAAAAAAAko/y1fde6jOHBE/s1600-h/image%5B43%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SharePoint ISA IIS Certificate Request" src="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDm6c_O7AI/AAAAAAAAAks/zHHQbotQvVU/image_thumb%5B33%5D.png?imgmax=800" border="0" alt="SharePoint ISA IIS Certificate Request" width="520" height="389" /></a></p>
<ul>
<li>· Select your Cryptographic Service Provider Properties.<br />
· Specify the filename and location to output the certificate request (The contents of this file (MODIFIED EXAMPLE BELOW) is important as it will be required by your Certificate Authority. In my case I am using a 3<sup>rd</sup> Party Certificate Authority that will issue the certificate.</li>
</ul>
<p><a href="http://lh6.ggpht.com/_jC8JMIc-c-0/SjDm7YZ0mPI/AAAAAAAAAkw/wLgwGlubqcM/s1600-h/image%5B49%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="certificate Request IIS SSL" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm8gcaKbI/AAAAAAAAAk0/u8ssiF9WiL8/image_thumb%5B37%5D.png?imgmax=800" border="0" alt="certificate Request IIS SSL" width="520" height="299" /></a></p>
<ul>
<li>· Once you have been issued with your certificate file from your Certificate Authority, go back into IIS Manager and re-launch Server Certificates and this time under Actions select <em>Complete Certificate Request<br />
</em>· Browse for the File Name and specify a Friendly name</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDm9lEMTcI/AAAAAAAAAk4/Ipakg-5C-tc/s1600-h/image%5B123%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Specify Certificate Authority Response" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDm-kqOGLI/AAAAAAAAAk8/HpqS2nNhslA/image_thumb%5B107%5D.png?imgmax=800" border="0" alt="Specify Certificate Authority Response" width="520" height="270" /></a> <em></em></p>
<p>Upon completion of the wizard your certificate will appear beside the already self signed machine certificate in IIS7.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDm_sxc4hI/AAAAAAAAAlA/UHRA9TigvuE/s1600-h/image%5B122%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Server Certificates" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnAibU_tI/AAAAAAAAAlE/hKMtvh0AYUM/image_thumb%5B106%5D.png?imgmax=800" border="0" alt="SSL Server Certificates" width="520" height="140" /></a></p>
<p>You will now need to apply the new certificate against the recently extended website.</p>
<ul>
<li>· Click on the Site you wish to apply the certificate and then click on SSL Settings.</li>
</ul>
<p><a href="http://lh4.ggpht.com/_jC8JMIc-c-0/SjDnBnzdLII/AAAAAAAAAlI/TGNNmYNbB1w/s1600-h/image%5B129%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Settings" src="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDnCXSrU7I/AAAAAAAAAlM/X0LIzSOr1D4/image_thumb%5B111%5D.png?imgmax=800" border="0" alt="SSL Settings" width="520" height="161" /></a></p>
<ul>
<li>· Select Require SSL and Require 128-bit SSL for your SSL settings and click on Apply</li>
</ul>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnDJ7Cc2I/AAAAAAAAAlQ/IFszVmXb1jo/s1600-h/image%5B135%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="SSL Settings SharePoint IIS7" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnDw9fMjI/AAAAAAAAAlU/YnyONs2BX6k/image_thumb%5B115%5D.png?imgmax=800" border="0" alt="SSL Settings SharePoint IIS7" width="498" height="243" /></a></p>
<p>We now need to apply our newly imported certificate to the extended site by clicking again on the extended site, and under Actions select Bindings and then click on Edit.</p>
<p><a href="http://lh5.ggpht.com/_jC8JMIc-c-0/SjDnEUrHFZI/AAAAAAAAAlY/wvV_EiMRYGw/s1600-h/image%5B143%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Bindings" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnFHr6XTI/AAAAAAAAAlc/7rsFPcTCBhc/image_thumb%5B119%5D.png?imgmax=800" border="0" alt="Bindings" width="194" height="202" /></a></p>
<p>Select the newly added SSL certificate from the drop down and ensure the port and IP address settings are correct.</p>
<p><a href="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnFsMU0hI/AAAAAAAAAlg/x8I1bl_xjZM/s1600-h/image%5B145%5D.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Edit Site Binding" src="http://lh3.ggpht.com/_jC8JMIc-c-0/SjDnGvjQM6I/AAAAAAAAAlk/f809qoN3uBc/image_thumb%5B121%5D.png?imgmax=800" border="0" alt="Edit Site Binding" width="260" height="147" /></a></p>
<p>Our site is now secure and ready to be accessed via the World Wide Web, well almost!  Stay tuned for next week for part 2 of this article, in which we will be focusing on the configuration of ISA 2006 and how we can leverage the inbuilt SharePoint Publishing Wizard to allow external access to our SharePoint site via SSL and Windows Forms Based Authentication.</p>
<p>___________________________________________</p>
<p>Articles in this series</p>
<ol>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-12/" target="_blank">Securing your SharePoint Sites with ISA 2006 using  Forms Based Authentication – Part 1/2</a></li>
<li><a href="http://sharepointgeorge.com/2009/securing-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%E2%80%93-part-22/" target="_blank">Securing your SharePoint Sites with ISA 2006 using  Forms Based Authentication – Part 2/2</a></li>
</ol>

<div class="sociable">
<div class="sociable_tagline">
<strong>If you enjoyed this article, consider sharing it with one of the below social networking sites:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;notes=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="del.icio.us"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;bodytext=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="Digg"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;annotation=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="Google Bookmarks"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;t=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="Facebook"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.friendfeed.com/share?title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F" title="FriendFeed"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;source=SharePoint+George+Everyday+experiences+on+SharePoint%2C+Exchange+and+most+things+Microsoft&amp;summary=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="LinkedIn"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;t=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="MySpace"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://sharepointgeorge.com/feed/" title="RSS"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="StumbleUpon"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F" title="Technorati"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="Reddit"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F" title="Fark"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="Live"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;h=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2" title="NewsVine"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;partner=sociable" title="PDF"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/pdf.png" title="PDF" alt="PDF" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;body=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="Ping.fm"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;title=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;selection=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20" title="Posterous"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/posterous.png" title="Posterous" alt="Posterous" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fsharepointgeorge.com%2F2009%2Fsecuring-your-sharepoint-sites-with-isa-2006-using-forms-based-authentication-%25e2%2580%2593-part-12%2F&amp;submitHeadline=Securing%20your%20SharePoint%20Sites%20with%20ISA%202006%20using%20Forms%20Based%20Authentication%20%E2%80%93%20Part%201%2F2&amp;submitSummary=Do%20you%20want%20to%20provide%20your%20information%20workers%20access%20to%20your%20SharePoint%20Site%20whilst%20out%20of%20the%20office%20easily%20from%20any%20internet%20connection%20without%20compromising%20security%3F%20%20Do%20you%20want%20to%20accomplish%20this%20without%20complicated%20client-site%20VPN%20setups.%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://sharepointgeorge.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/2009/securing</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
