Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Setting up an SSL certificate for OWA without a public IP address
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Setting up an SSL certificate for OWA without a public IP address

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 31 August 2006
We want to set up a Secure Sockets Layer (SSL) certificate for Outlook Web Access (OWA), and we do not have a public IP address assigned for our firewall. Can we use Dynamic Domain Name System (DDNS) to allow external access to our Exchange server? Or, will we need a fixed public address to get this to work? I have set up the certificate and OWA works internally, but not externally.

>
EXPERT RESPONSE
VIEW MEMBER FEEDBACK TO THIS ASK THE EXPERT Q&A.

It is possible to use DDNS. However, the certificate's common name must match the fully qualified domain name (FQDN) you use with DDNS. Using the IP address will not work unless the common name of the certificate is the IP address.

By the way, there are varying degrees of the word "works" when it comes to Web server certificates. The first level is to establish an SSL session. The next level is to get it to work without any certificate errors. The most common error is that you are not using a "Trusted CA." If this is the error you are getting, then you can simply publish the Root Certificate so that users can import it into their Web browser's trust list. If these are Active Directory (AD) members, I would recommend using a Group Policy Object (GPO) to perform this task.

MEMBER FEEDBACK TO THIS ASK THE EXPERT Q&A:

Depending on your purpose, there is a way to possibly accomplish this. I support Windows Small Business Server (SBS). Several clients have Windows Mobile phones that "require" a Root level certificate, but self-signed certificates created by SBS are not Root level.
—Kevin K.

Do you have comments on this Ask the Expert Q&A? Let us know.

Related information from SearchExchange.com:

  • Expert Advice: How enabling SSL for OWA affects bandwidth
  • Expert Advice: Securing a front-end certificate server
  • Tutorial: How to set up a front-end Exchange Server cluster
  • Tip: ActiveSync and front-end DNS aliases
  • Reference Center: Exchange Server authentication resources

  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Outlook Web Access
    Customizing an Outlook Web Access 2003 email signature
    Outlook Web Access limitations using Exchange Server public folders
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    Customizing Outlook Web Access (OWA) in Exchange Server 2007
    Fix OWA message size limit issue after Exchange 2007 SP1 upgrade
    How to customize OWA authentication logon in Exchange Server 2003
    Top 10 Microsoft Outlook and Outlook Web Access tips of 2007

    User Authentication for Microsoft Outlook and OWA
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    How to customize OWA authentication logon in Exchange Server 2003
    Automated redirects to OWA directories may fail when SSL is enforced
    Configure Windows Mobile devices to local wipe after failed logons
    How to set up an SSL certificate to encrypt OWA and ActiveSync traffic
    Error: 'The name of the security certificate is invalid or does not match the name of the site'
    Password authentication works for OWA but fails for Microsoft Outlook

    Richard Luckett: Spam and Security
    Selectively set email permissions for Exchange groups
    What event log tracks user access to Exchange Server?
    Public folder permissions fail in Exchange mixed mode
    Locate 'missing' SPF record on an external DNS domain
    Enhance OWA logon security using Microsoft ISA Server
    Native Exchange Server 2003 antispam solutions
    Configure IMF's Gateway SCL to improve spam filtering
    POP3 server filters all email into Junk folder as spam
    Creating one password for both local and Microsoft Outlook user accounts
    Should Exchange Server utilize the SMTP connector for internal email?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Vouch by Reference (VBR)  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts