Forum Discussion
Exchange 2013 ActiveSync Client Certificate Authentication
Hi DevCentraler's,
I've setup an Exchange CAS Virtual Server using an iApp template which is working well. (OWA, Autodiscover, ActiveSync, Outlook Anywhere, EWS, OAB)
We would like to start using client certificates as an alternative form of authentication for ActiveSync, and have enabled this internally (works nicely).
Has anyone configured this sort of deployment before? Ideally we would like to use the same VIP and be able to offer username / password authentication OR client certificate authentication.
I have tried configuring a client SSL profile with the appropriate chain certificate and configuring client certificates to be 'requested' but this hasn't worked.
Exchange is configured as follows:
2 Replies
- mikeshimkus_111Historic F5 Account
If you want the client cert to be presented at the CAS, I think your options are:
-
Set up a separate VIP for ActiveSync that doesn't terminate SSL (aka passthrough).
-
Use ProxySSL: https://support.f5.com/kb/en-us/solutions/public/13000/300/sol13385.html.
If you have APM, you could:
- Use APM on-demand cert auth, collect the domain name from the user's UPN in the cert, stuff that into a Kerberos SSO request, and auth to the CAS using KCD (the iApp does something similar when deploying APM with smart card auth for OWA).
- Nath
Cirrostratus
This is my problem right now! I tried to configured chain cert and bundle cert but still no luck! Is there any way to use the ActiveSync that f5 will terminate and re-encrypt the traffic up to the CAS server?
-
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com