Re: IIS and client certificate



I don't think you can combine these two requirements in the way that you
wish.

You could create a second virtual directory (e.g. /internalOWA) and point it
to the same location that the existing virtual directory does (/exchange).
Your internal clients would use one virtual directory (with the IP address
restriction), and your external clients would use the other (with the client
certificate restriction).

To make it a bit easier for your users, you could create a single page which
redirects the user to the relevant folder depending on whether they are
internal or external.

Cheers
Ken

<spiazzi67@xxxxxxxxx> wrote in message
news:1150617847.359731.203490@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I have SBS2003.
I would expose exchange web in internert and intranet.
For intranet I would secure with IP filter.
For internet I would secure witch client certificate.
Now can I combine this methods? That is a person in my intranet that
haven't the certificate can access , because the IP is secure. A person
in internet with client trusted certificate can access also if he
hasn't an IP in the range.

It is possible and if yes what are the configuration?

Thanks



.



Relevant Pages

  • Re: SSL POP3 works only locally if cert name is used
    ... yes there is a way to export the certificate and install it on the client ... On the SERVER: ... 1- open Internet Explorer, ... On the client computer, ...
    (microsoft.public.windows.server.sbs)
  • Re: How do I make a local machine client certificate available to all users?
    ... It sounds like your client machines are Intranet machines which access ... your server machine to know the client machine is if the client ... specific machines to access this website over the internet. ... but the certificate is installed on a per user basis. ...
    (microsoft.public.inetserver.iis.security)
  • Re: No Companyweb via RWW
    ... Internet because outside of ISA. ... Client config on the ... >Did you run the CEICW wizard to create the certificate? ... >> The Firewall Client is installed on the laptops, ...
    (microsoft.public.windows.server.sbs)
  • Re: Client Certificate and Code Access Security
    ... Changing permissions on the client side is not an option for my customers. ... Why am I able to use client side certificates in the internet zone with my ... .NET app should not be allowed to access a users certificate store without ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: wscript shell run
    ... open file from Internet using parameter in command line, ... on client with a program on client. ... > What I really want is to open a file(through virtual directory) on server ...
    (microsoft.public.scripting.wsh)