Re: [Full-disclosure] Secure OWA



One possibility is to consider doing a two-stage authentication
scheme, where the user first authenticates with (say) an RSA SecurID
token, and then after authenticating there gets forwarded to the usual
OWA login page (all SSL encrypted of course!). I've seen this used
with good results.

-Brendan

On 8/25/06, Lohan Spies <lohan.spies@xxxxxxxxx> wrote:



Hi there,



Could someone please provide me with products or solutions that can secure
OWA authentication?



The client is already utilizing smartcards with certs for the internal
network authentication.



The problem is that the client needs another form of authentication against
the OWA instead of passwords or smartcards.



The end-users must also be able to use public computers to authenticate
against OWA. (i.e. no card readers etc)



Something like OTP? Maybe one of you had the same scenario and can point me
to the solutions / products you used!



Regards
_______________________________________________
Full-Disclosure - We believe in it.
Charter:
http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] Verizon Wireless DNS Tunneling
    ... the problem is the bad data doesn't flush after authentication. ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • RE: OWA Loading Issue
    ... First please let me know why you are trying to get the OWA interface to not ... credential to access the Exchange, this is more secure to your Exchange and ... Disable Forms-Based Authentication and enable Integrated ... please enable Integrated Windows Authentication in Exchange ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA Authentication Problem With SBS 2003
    ... you are able to log in OWA after disabling the form based ... authentication, and you would like to let the OWA work when you re-enable ... obtain access to your Exchange Server 2003 mailbox. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] Google Accounts Security Vulnerability
    ... users do not use 2-factor authentication and this is unlikely to ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • RE: OWA fails to close
    ... This posting is provided "AS IS" with no warranties, ... and cleared Integrated Windows Authentication. ... >closed in Exchange 2000 OWA. ... Users group ...
    (microsoft.public.exchange.misc)