<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outlook Web Access Security in BackOffice Products</title>
    <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932381#M1333</link>
    <description>The big decision and its more about money is if you want to run real SSL with a certificate from someone like Verisign or if you want to run a homebrew cert from Microsoft Certificate server and if you need 40 or 128 bit security.&lt;BR /&gt;&lt;BR /&gt;Good Luck&lt;BR /&gt;&lt;BR /&gt;Rob&lt;BR /&gt;</description>
    <pubDate>Fri, 21 Mar 2003 15:10:09 GMT</pubDate>
    <dc:creator>rob bergin</dc:creator>
    <dc:date>2003-03-21T15:10:09Z</dc:date>
    <item>
      <title>Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932377#M1329</link>
      <description>Can someone help me figure if its safe to put Outlook Web Access online?</description>
      <pubDate>Thu, 20 Mar 2003 21:23:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932377#M1329</guid>
      <dc:creator>twoguysandaserver</dc:creator>
      <dc:date>2003-03-20T21:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932378#M1330</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;its pretty safe, you can ensure further safety by using a firewall to protect the OWA box from the internet and you can use certificates to ensure the data sent back and forth is encrypted.&lt;BR /&gt;&lt;BR /&gt;good luck.&lt;BR /&gt;&lt;BR /&gt;rob&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Mar 2003 21:25:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932378#M1330</guid>
      <dc:creator>rob bergin</dc:creator>
      <dc:date>2003-03-20T21:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932379#M1331</link>
      <description>OWA is fine.&lt;BR /&gt;&lt;BR /&gt;As long as everyone uses IE to access it, the Regular NT style encrypted challenge/responce is built in.&lt;BR /&gt;&lt;BR /&gt;The data stream won't be encrypted, but the authentication will be.&lt;BR /&gt;&lt;BR /&gt;If you're worried about that, place the exchange server behind your firewall with an MTA on the other side.  Users should then VPN in to use OWA, and the entire stream will be protected.&lt;BR /&gt;&lt;BR /&gt;Jon&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2003 04:52:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932379#M1331</guid>
      <dc:creator>Jon Finley</dc:creator>
      <dc:date>2003-03-21T04:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932380#M1332</link>
      <description>Jon has the right answer, with your OWA server behind the firewall and an agent outside.  As an alternative to a VPN, you can use a reverse proxy server to query the agent.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Paul</description>
      <pubDate>Fri, 21 Mar 2003 12:53:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932380#M1332</guid>
      <dc:creator>Paul R. Dittrich</dc:creator>
      <dc:date>2003-03-21T12:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932381#M1333</link>
      <description>The big decision and its more about money is if you want to run real SSL with a certificate from someone like Verisign or if you want to run a homebrew cert from Microsoft Certificate server and if you need 40 or 128 bit security.&lt;BR /&gt;&lt;BR /&gt;Good Luck&lt;BR /&gt;&lt;BR /&gt;Rob&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2003 15:10:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932381#M1333</guid>
      <dc:creator>rob bergin</dc:creator>
      <dc:date>2003-03-21T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932382#M1334</link>
      <description>Jon&lt;BR /&gt;&lt;BR /&gt;What do you mean when you say:&lt;BR /&gt;&lt;BR /&gt;If you're worried about that, place the exchange server behind your firewall with an MTA on the other side. Users should then VPN in to use OWA, and the entire stream will be protected&lt;BR /&gt;&lt;BR /&gt;I am unfamiliar with how an MTA is going to permit HTTP access to email?  Aren't MTA's more for message transfer?&lt;BR /&gt;&lt;BR /&gt;Rob - we plan to use a 128 bit SSL certificate. Can you recommend a vendor?  Also what happens when a 40-bit version of the browser tries to access SSL done with a 128 bit certificate?  Does the browser software have to 128 bit?  We have 128 bit as our desktop standard but expect users to use Web Access from a variety of machines which may not be 128-bit.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2003 15:13:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932382#M1334</guid>
      <dc:creator>twoguysandaserver</dc:creator>
      <dc:date>2003-03-21T15:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932383#M1335</link>
      <description>Hey,&lt;BR /&gt;&lt;BR /&gt;We use Verisign and paid $900 for the Cert with 1 year support.  We started with a homebrew certificate and migrated off to a real SSL cert. I am not sure what an MTA for OWA is maybe its an appliance server that does the SSL and proxies the HTTP to the OWA box?&lt;BR /&gt;&lt;BR /&gt;Hope that helps.&lt;BR /&gt;&lt;BR /&gt;Rob&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2003 15:18:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932383#M1335</guid>
      <dc:creator>rob bergin</dc:creator>
      <dc:date>2003-03-21T15:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook Web Access Security</title>
      <link>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932384#M1336</link>
      <description>The MTA simply re-directs incoming mail (x.400 documents) to an IP address and port (your exchange server) to where ever it is behind your firewall.  It's a secure relay point.&lt;BR /&gt;&lt;BR /&gt;Your Employees/Users then connect to your network through VPN to access the OWA interface as it they were within your network.  Your Users will be the only ones accessing the HTML content from OWA.&lt;BR /&gt;&lt;BR /&gt;Using an MTA is simply a means of protecting the Exchange Server rather than having it stradle or sit outside of your firewall.&lt;BR /&gt;&lt;BR /&gt;An MTA can be a linux box using sendmail, or a FrontEnd Exchange Server that simply routes traffic to the internal exchange server (FE/BE servers).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Jon&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2003 19:53:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/backoffice-products/outlook-web-access-security/m-p/2932384#M1336</guid>
      <dc:creator>Jon Finley</dc:creator>
      <dc:date>2003-03-21T19:53:46Z</dc:date>
    </item>
  </channel>
</rss>

