SSL on OWA questions

From: leo (leo_space@hotmail.com)
Date: 01/23/03


From: "leo" <leo_space@hotmail.com>
Date: Wed, 22 Jan 2003 20:17:50 -0800

I have installed OWA on IIS4 server with SSL enabled on
default web site and exchange virtual directory. NTFS
permission are also added on exchange directory such that
whenever users hit "https://website" it prompts for the
user id and password. We are using basic authentication
and users have not installed the client authentication
certificate.

1.Can anyone tell me whether the ID and password sending
to OWA by client are encrypted by the SSL session? I just
wonder if the SSL session has not initialized yet for the
first prompt of user authentication.

2.Is the data only encrypted from server side to client
side for this setup? If encryption is already done on
both side then why we need to install client
authentication certificate?

thanks for your help



Relevant Pages

  • Re: a refresher
    ... pages available to whoever you want to by controlling the authentication ... methods and using ntfs permissions.If you are talking about web enrollment, ... public key unencrypted to start the SSL process. ... session keys agreed upon by the client computer to start the session. ...
    (microsoft.public.win2000.security)
  • Re: clients editing information w/o authentication--advice needed
    ... I completely concur that username/password authentication is the way to go. ... SSL, while the most secure, is not essential since there's no confidential ... I will "push back" with the client and tell them they'd be better off ...
    (comp.lang.php)
  • Re: always dual entries in IIS Log with first being HTTP 401.2 error
    ... If I disable client authentication, ... >> well as SSL connection. ...
    (microsoft.public.inetserver.iis.security)
  • Re: http://companyweb doesnt work but http://companyweb.domain.local or https://companyweb do
    ... I'm not forcing SSL on either web site. ... All the LAN clients are configured as Web Proxy client and the "Bypass ... Uncheck the "Bypass proxy server for local addresses" option in IE. ... Install the Firewall Client on all the workstations. ...
    (microsoft.public.windows.server.sbs)
  • SSL und client authentication
    ... Kann man mit outlook 6 / outlook express 6 per SSL mit client authentication ... Ich bin sehr dankbar fuer jede Hilfe bzw. ...
    (microsoft.public.de.outlook)