Home > Microsoft Exchange Tips > Outlook and Outlook Web Access Tips > OWA authentication issues when using a proxy server
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

OUTLOOK AND OUTLOOK WEB ACCESS TIPS

OWA authentication issues when using a proxy server


Serdar Yegulalp
06.27.2006
Rating: --- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Outlook Web Access (OWA) can work on a server directly available from the Internet or a server concealed by a proxy. If you have the latter setup, you need to watch out for potential OWA authentication issues.

One 'gotcha' regarding OWA behind a proxy server -- whether it's the earlier Microsoft Proxy Server or the more recent Internet Security and Acceleration (ISA) Server -- is that NTLM authentication only works over one "hop" at a time.

VIEW MEMBER FEEDACK TO THIS OUTLOOK WEB ACCESS TIP
If you have NTLM authentication turned on at the proxy and try to access another NTLM-protected resource behind it, the authentication will fail.

The solution is to switch the proxy over to Basic authentication (over HTTPS when possible), and set any resources behind it that need to be protected to NTLM.

OWA is the most important element in this scenario, because it's the one that depends most heavily on the client's authenticated credentials.

Not all access to or through the proxy itself necessarily has to be secured, as long as what's behind it is secured properly. But you do need to make sure everything accessible through the proxy via Basic authentication is locked down.

This OWA authentication issue also appears if you're working with a multi-tiered application that uses a Web service, whether or not it's behind a proxy.

If you try to use NTLM authentication in a regular ASP/ASP.NET application, this isn't a problem, since there's only one "hop" for the credentials to traverse.

However, if you're using that in conjunction with a Web service, that's another "hop" that NTLM can't traverse. In such a case, the Web services should probably be run in a trusted-process model rather than using impersonation, which reduces the number of "hops" over which the client credentials need to be passed.

About the author: Serdar Yegulalp is editor of the Windows Power Users Newsletter.


MEMBER FEEDBACK TO THIS TIP

Does this problem apply to Outlook 2003 OWA form-based logon?
—Andy C.

******************************************

As far as I know this also applies to Outlook 2003 OWA form-based logon, since the problem is a server-based issue.
—Serdar Yegulalp, tip author


Do you have comments on this tip? Let us know.

Related information from SearchExchange.com:

  • FAQ: Outlook Web Access administration
  • Learning Center: Troubleshooting Outlook Web Access
  • Expert Advice: How enabling SSL for OWA affects bandwidth
  • Expert Advice: Configuring IIS to authenticate OWA users
  • Reference Center: Exchange Server authentication tips

    Please let others know how useful this tip was via the rating scale below. Do you have a useful Exchange Server or Microsoft Outlook tip, timesaver or workaround to share? Submit it to SearchExchange.com. If we publish it, we'll send you a nifty thank-you gift.

    Rate this Tip
    To rate tips, you must be a member of SearchExchange.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    User Authentication for Microsoft Outlook and OWA
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    How to customize OWA authentication logon in Exchange Server 2003
    Automated redirects to OWA directories may fail when SSL is enforced
    Configure Windows Mobile devices to local wipe after failed logons
    How to set up an SSL certificate to encrypt OWA and ActiveSync traffic
    Error: 'The name of the security certificate is invalid or does not match the name of the site'
    Password authentication works for OWA but fails for Microsoft Outlook

    ISA Server and Firewalls for Microsoft Exchange Server
    Why Exchange ActiveSync fails with NAT firewalls
    Deploying ISA Server as a firewall for Exchange Server mobile devices
    Adjust your firewall to avoid Exchange 2007 Direct Push failures
    OWA stops working from external network connection
    Enhance OWA logon security using Microsoft ISA Server
    Firewall problems with Exchange Server 2007 email attachments
    How and why to disable certain ESMTP verbs
    Creating an ethical firewall in Exchange Server 2007
    Beware of firewalls that block Exchange Server's SMTP/POP3 communications
    How HTTP verbs can 'hang' Outlook Web Access

    Outlook Web Access
    Repairing damaged OWA virtual directories in Exchange Server 2003
    Customizing an Outlook Web Access 2003 email signature
    Outlook Web Access limitations using Exchange Server public folders
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    Customizing Outlook Web Access (OWA) in Exchange Server 2007
    Fix OWA message size limit issue after Exchange 2007 SP1 upgrade
    How to customize OWA authentication logon in Exchange Server 2003

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Vouch by Reference (VBR)  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

  • HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts