Quantcast
Channel: Exchange Server 2013 - Outlook, OWA, POP, and IMAP Clients forum
Viewing all articles
Browse latest Browse all 10580

Publish Outlook Anywhere with Kerberos constrained delegation, authenticate with client certificate

$
0
0

Hi

I´m currently testing publishing of Outlook Anywhere with TMG/UAG, in my testenvironment I have Exchange 2010 in my environment at the moment.

My test accounts logon to our domain with smart card, I have no issues connecting with outlook to Exchange from internal network. When I try to logon from external network my clients shows disconnected after a few seconds and I can´t connect to Exchange. Is it possible to get SSO to outlook anywhere when connecting from Internet and using smart card?

I have configured TMG with Kerberos Constrained Delegation.

Our SPN is set to http/server.domain.com and our Exchange is trusted for delegation on computer object. In TMG I have tested with spn http/* and http/server.domain.com.

On our listener I have tested with authentication SSL client certificate and with HTTP Auth (Integrated).

When I configured the listener to use Basic auth I received logon prompt.

I have read several blogs and technet articles but I can´t find anything if outlook anywhere is going to work with SSO when using smart cards.

Br

Mikael


Viewing all articles
Browse latest Browse all 10580

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>