Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Securing a front-end certificate server
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Securing a front-end certificate server

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 14 July 2005
I have set up a front-end server to be the certificate server. How do I set up the back-end server to use this certificate, and make the requests on the main server go to the back-end server? The back-end server's Internet Information Server Exchange site has the red stop sign. What does that mean? It seems to work for HTTP traffic directly, just not from the front-end server, which is configured to require SSL.

>
EXPERT RESPONSE
You have fallen subject to a common misconception. That is that enabling SSL on a front-end server secures not only client to front-end server communications, but that it also secures front-end to back-end communication. As you have discovered, that is not how it works.

There are a few things that I want to share with you that I think will help you on your way.

  1. The front-end server is probably not the best place to install a certificate authority (CA). A better, more secure place would be a dedicated server; however, a more common location is a domain controller. There is a huge security risk placing the CA on a front-end server, especially if it will be located in a DMZ.

  2. The front-end server is the place to install the certificate, not the back-end server -- and you only need to install the certificate on the front-end server or servers. The only time you would need to install a certificate on the back-end server is if you are not deploying front-end servers.

    As far as getting the front-end server to communicate with the back-end server, you need to allow port 80 communications if there is a firewall in between them. They will not communicate with each other over port 443 as you might have expected.

    Note: There are additional ports I have not listed here that must be opened between if a firewall separates the front-end server from the internal network.

  3. Finally, to secure your front-end to back-end communications, you can implement IPsec policies on your front-end and back-end servers. If you use the default policies, I would enable the "Server (Request Security)" on both servers. This will encrypt all traffic between the two servers but will still allowed non-IPsec communications with other servers and clients.


Do you have comments on this Ask the Expert Q&A? Let us know.
Related information from SearchExchange.com:

  • Learning Guide: A primer on server roles and Exchange hardware
  • Reference Center: Permissions and passwords



  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Richard Luckett: Spam and Security
    Selectively set email permissions for Exchange groups
    What event log tracks user access to Exchange Server?
    Public folder permissions fail in Exchange mixed mode
    Locate 'missing' SPF record on an external DNS domain
    Enhance OWA logon security using Microsoft ISA Server
    Native Exchange Server 2003 antispam solutions
    Configure IMF's Gateway SCL to improve spam filtering
    POP3 server filters all email into Junk folder as spam
    Setting up an SSL certificate for OWA without a public IP address
    Creating one password for both local and Microsoft Outlook user accounts

    Exchange Server Security
    OWA 'Loading' problems with Internet Explorer security zones
    New Exchange Server tools named as Products of the Year
    Beware of bare linefeeds in Exchange Server email
    Top 10 Exchange Server administration tips of 2006
    Enabling protocol logging for Exchange Server
    Eliminate annoying Microsoft Outlook security warnings with ClickYes Pro
    Forefront beta secures SharePoint collaboration
    Dell, Symantec simplify Secure Exchange for SMBs
    Tutorial: How to determine which ports Exchange Server is using
    Unsecured devices worry IT professionals
    Exchange Server Security Research

    Microsoft Exchange Server Permissions
    Exchange public folder calendar can't be opened in Microsoft Outlook
    Grant or deny permissions to access a user's Exchange 2007 mailbox
    Set Outlook calendar permissions for group to view private meetings
    Exchange Admin 101: Exchange 2003 and Exchange 2007 admin privileges
    Selectively set email permissions for Exchange groups
    Public folder permissions fail in Exchange mixed mode
    Configure admin rights to access Exchange 2003 mailbox
    Share a user's calendar without giving access to the entire mailbox
    How to prevent a user from moving an Exchange Server shared calendar to personal mailbox
    Creating an ethical firewall in Exchange Server 2007

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    privilege  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts