SSL security

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi

I have an OWA 5.5 SP4 website behind an ISA server 2000 SP1. I have
installed a certificate on OWA website but I wasn't success exporting the
certificate + PK to import them into the ISA server.
My external OWA clients to access to the ISA by the HTTP protocol and ISA
redirects this request by the SSL protocol. My question is: if I leave ISA
without a SSL link between external OWA clients and ISA - are users still
passing their credentials in a basic text (I mean without encryption) to the
OWA website?
Is it secure only with SSL between ISA and OWA website? or I need to install
a certificate on ISA certificate store anyway

Thanks for the help

Sean
 
This is a dangerous setup because yes, all communications between clients
and ISA Server is in cleartext.

Obtain another certificate for your ISA Server and reconfigure your
publishing rules to use HTTPS between the clients and ISA Server.

Steve Riley
(e-mail address removed)
 
Back
Top