The potential problem with this is that when the user initially
authenticates to OWA, their logon/password is sent plain text as well. 
I'm not sure why you wouldn't want to enable SSL for the entire session.

Dave


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Salandra,
Justin A.
Sent: Tuesday, April 05, 2005 09:34 AM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] SSL on OWA to change password

Guys, I sent this to a different list but also wanted to bounce it off
of you.

Justin A. Salandra
MCSE Windows 2000 & 2003
Network and Technology Services Manager
Catholic Healthcare System
212.752.7300 - office
917.455.0110 - cell
[EMAIL PROTECTED]

-----Original Message-----
From: Salandra, Justin A. [mailto:[EMAIL PROTECTED]
Sent: Tuesday, April 05, 2005 11:10 AM
To: [EMAIL PROTECTED]
Subject: [Exchange2000] SSL on OWA to change password


Please check my logic here.  TO enable SSL on only the IISADMPWD virtual
Directory I do the following steps

Create the IISADMPWD Virtual Directory
Ensure proper rights and authenticated access are set on that directory
Apply the hotfixes described in the KB Articles for Windows 2003
Run asutil.vbs script to set the PasswordChangeFlag to 0
Generate the SSL Certificate
Apply the SSL Certificate
Set the IISADMPWD Virtual Directory to require SSL
Modify the Registry to show the Change Password button

http://support.microsoft.com/default.aspx?scid=kb;en-us;297121
http://support.microsoft.com/kb/833734/EN-US/
http://support.microsoft.com/kb/327134/

I only want to use HTTPS on the change password screen, not the entire
OWA Site.

Thanks

Justin A. Salandra
MCSE Windows 2000 & 2003
Network and Technology Services Manager
Catholic Healthcare System
212.752.7300 - office
917.455.0110 - cell
[EMAIL PROTECTED]




  Post message: [EMAIL PROTECTED]
  Unsubscribe:  [EMAIL PROTECTED]

  Exchange 2000 FAQ: 
  http://www.exchange-mail.org/faq.html
 
Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/Exchange2000/

<*> To unsubscribe from this group, send an email to:
    [EMAIL PROTECTED]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
 



List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to