Showing posts with label Exchange 2003. Show all posts
Showing posts with label Exchange 2003. Show all posts

Administer Exchange 2003 from Windows XP SP1

How can I manage my Exchange 2003 server from a Windows XP/2000/2003 workstation?

This article describes the steps to be taken in order to be able to administer an Exchange 2003 server from a Windows XP Pro computer that is installed with SP1 or SP1a or from a Windows Server 2003 Member Server.

Note: For an Exchange 2000 version of this page and for more background on this issue (with detailed screenshots) click on the following article: Administer Exchange 2000 from Windows XP SP1.

You can administer Exchange Server 2003 servers from a Windows computer by using Exchange Setup to install only Microsoft Exchange System Management Tools.

Note: If you have not installed an Exchange 2003 server in your organization, you must first run ForestPrep. ForestPrep extends the Active Directory schema to include Exchange-specific classes and attributes, and creates the container object for the Exchange organization in Active Directory.

To install Exchange System Management Tools ensure that the computer meets the following requirements:

*
The computer is running Windows XP, Windows Server 2003, Windows 2000 Professional, or Windows 2000 Server SP3.
*
The computer name does not contain unsupported characters.
*
The language version matches any previous installation of Exchange 2000 System Management Tools (except for upgrades from English to Korean, Traditional Chinese, or Simplified Chinese).
*
Log onto the domain with an account that has local machine administrator permissions.

Depending on the version of Windows that is running on the computer, install the required services.

Windows XP Service Pack 1

*
Internet Information Services Snap-In component
*
SMTP Service component
*
World Wide Web Service
*
Windows Server 2003 Administration Tools Pack, AdminPak.msi

Windows XP SP2

*
Internet Information Services Snap-In component
*
Windows Server 2003 Administration Tools Pack (AdminPak.msi)

Windows Server 2003

*
Internet Information Services Manager component

Windows 2000 Professional SP3

*
Internet Information Services Snap-In component
*
Windows Server 2000 Administration Tools Pack (AdminPak.msi)

Windows 2000 Server SP3

*
Internet Information Services Snap-In component
*
Windows Server 2000 Administration Tools Pack (AdminPak.msi)
*
SMTP Service component
*
NNTP Service component

Next, run Exchange Setup, located in the SETUP\I386 folder. On the Component Selection page, set the installation action to Custom, and then select Microsoft Exchange System Management Tools.



After the installation is complete go to the Start menu and see if the Microsoft Exchange folder and shortcuts have been successfully created.



Finally, you must install the latest Exchange 2003 Service Pack:

Exchange 2003 Service Pack 2 (SP2) was released on the 19th of October 2005. You can download SP2 for Exchange 2003 right here:

Download Exchange 2003 SP2 (109mb)

Publish Exchange 2007 OWA via ISA with RSA TOKEN

Few days ago, I perform the configuration for publishing OWA through ISA Server 2006 with a RADIUS authentication to use a RSA Token and use this post from Elan Shudnow to do it.

Procedure:

http://www.shudnow.net/2009/07/01/exchange-2007-owa-via-isa-rsa-authentication-delegation/

When utilizing ISA (in this case, ISA 2006) to publish Outlook Web Access (OWA), there are various options you can choose from in order to authenticate a user. One listener authentication mechanism that is often used is Forms Based Authentication. By default, your ISA form when publishing OWA will look like the following:

As you can see, by default, it asks you for Domain\User name. By going into the listener authentication options, you can specify the default domain that should be specified if the user does not specify a domain. Without specifying this, if the user were to only enter their user name, authentication would fail as it is not passing the domain back to Exchange. By going into the properties of your OWA listener, you will see an Authentication tab.

Because we will be utilizing RSA, we will choose RSA as the method of Authentication utilizing Forms Based. Because Exchange isn’t set to also authenticate to RSA (only ISA), we will need to collect additional information in the form. This allows a user to also enter their AD credentials so after ISA authenticates a user, ISA can still pass back the AD credentials back to Exchange as the Authentication Delegation mechanism using Basic. Selecting to Collect dditional delegation credentials in the form allows you to utilize either Basic, NTLM, or Negotiate as an Authentication Delegation mechanism.

By clicking on Advanced, we can see the section in which we can configure the domain to automatically pass back to Exchange during the Authentication Delegation. Again, a user authenticates from a browser to a web listener and from there, ISA then takes certain information about the user and passes that back to Exchange which is the Authentication Delegation piece.

But, as you can see, the Domain name piece is greyed out. But if you look at the authentication form for ISA when RSA is enabled, you can see it doesn’t ask for the Domain Name.

Now because of this, if a user doesn’t specify to use a different user name which does allow you to enter a domain\username, the authentication delegation piece will fail as the basic authentication mechanism that you will set on Exchange will want a domain\username passed back. So if we can’t set this in ISA, how do we set it? Well, we can actually configure IIS to automatically assume a specific domain to be used if no domain is specified. While IIS6 and IIS7 are very much different, you can actually utilize the Exchange Management Console to set this option which will stamp IIS appropriately (both IIS6 and IIS7.)

The default authentication option for OWA on a CAS is to use Forms Based Authentication and require a user to specify their domain.

If you specify the following option, choose your domain, and click Apply, it will stamp IIS to assume the specified domain name. A user can still specify their domain or not specify it and both will work when authenticating. This should hopefully make you realize that if ISA relays authentication back to IIS on the CAS, that it won’t matter anymore if the domain is specified or not.

But because our ISA Authentication Delegation for our OWA rule will utilize Basic Authentication, we now want to specify Basic Authentication within Exchange for OWA. But don’t worry, even if you change it from the previous setting of Forms Based Authentication with the assumed domain, IIS will still stay stamped properly. So go ahead and choose Basic. You will be prompted to do an IISReset -Noforce. Go ahead and do it after choosing Basic.

So back over to ISA, if we go into our Outlook Rule, we can see the Authentication Delegation set to Basic which it will need to be since that’s what the Authentication option is set to for OWA on our CAS.

So taking everything into account what we did above, what happens is the user authenticates to ISA utilizing a form and specifies their username without the domain, RSA key, and password for their username. When they click Log On to authenticate, ISA will authenticate the user with RSA, and when that passes, ISA will utilize basic authentication due to the authentication delegation being set to basic to pass the username and password they specified (with no domain) back to OWA. Because IIS is stamped to automatically utilize the domain even if it wasn’t specified, authentication will work and the user will be logged into OWA.

Resources:

Outlook Web Access Server Publishing in ISA Server 2004: RADIUS and Forms-based Client Authentication

http://technet.microsoft.com/en-us/library/cc302660.aspx

Enabling RADIUS authentication for the OWA Forms-Based Authentication in ISA Server 2004

http://support.microsoft.com/kb/884560

Webcast / Overcoming Exchange Failures - Insights from an Industry Expert

PRE-REGISTER FOR WEBCAST:
http://go.techtarget.com/r/8674620/8630994

Date and time:
Tuesday, July 21, 2009 8:00 am
Pacific Daylight Time (GMT -07:00, San Francisco)
Change time zone

Tuesday, July 21, 2009 10:00 am
Central Daylight Time (GMT -05:00, Chicago)

Tuesday, July 21, 2009 11:00 am
Eastern Daylight Time (GMT -04:00, New York)

Tuesday, July 21, 2009 4:00 pm
GMT Daylight Time (GMT +01:00, London)

Duration:
1 hour

Description:
Paul Robichaux, Exchange MVP and author of multiple books on Exchange management, integration, and security, will share his expert insight and provide guidelines for Exchange protection and recovery to address common challenges such as over-running Exchange backup windows and media failures as well as less common but potentially devastating failures such as database corruption and loss of an entire Exchange Server.