<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx</link><description>In previous posts, we have discussed certificate based authentication (CBA) for Outlook Web App, and Greg Taylor has covered publishing Outlook Web App and Exchange ActiveSync (EAS) with certificate based authentication using ForeFront TMG in this whitepaper</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3543383</link><pubDate>Mon, 31 Dec 2012 19:41:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3543383</guid><dc:creator>Johnathan</dc:creator><description>&lt;p&gt;It seems that in our testing the cert does not have to be published back to the user account, only the Subject / SAN name have to include the email address. &amp;nbsp;We have an MDM pushing the Cert with SCEP/NDES and it writes all the certs back to the MDM&amp;#39;s account. &amp;nbsp;So it looks like it doesn&amp;#39;t matter which account it is written back to. &amp;nbsp;Does that seem like a security flaw? or am I over thinking it? &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3543383" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3536087</link><pubDate>Mon, 03 Dec 2012 14:54:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3536087</guid><dc:creator>Fred</dc:creator><description>&lt;p&gt;In the article you mention that UAG also supports CBA for ActiveSync. Has something changed? UAG doesnt currently support CBA for EAS - Is this functionality being added in the Service Pack 3 for UAG release?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3536087" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535759</link><pubDate>Fri, 30 Nov 2012 19:08:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535759</guid><dc:creator>ahwc</dc:creator><description>&lt;p&gt;thanks for the article, will this work if the Forefront TMG gateway has TLS renegotiation disabled?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535759" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535534</link><pubDate>Thu, 29 Nov 2012 18:58:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535534</guid><dc:creator>Bharat Suneja [MSFT]</dc:creator><description>&lt;p&gt;@Ronald den Os:&lt;/p&gt;
&lt;ul class="nobullet"&gt;
&lt;li&gt;- The TMG whitepaper linked in this post is from 2010.&lt;/li&gt;
&lt;li&gt;- TMG will continue to be supported for years. See the &lt;a class="bold" href="http://support.microsoft.com/lifecycle/?p1=14873"&gt;TMG support lifecycle&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;- As stated in the beginning of this particular post: &amp;quot;In this post, we will discuss how to configure CBA for EAS for Exchange 2010 in deployments without TMG or UAG.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535534" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535532</link><pubDate>Thu, 29 Nov 2012 18:53:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535532</guid><dc:creator>Bharat Suneja [MSFT]</dc:creator><description>&lt;p&gt;@Anonymous: We&amp;#39;ve pinged the Windows 8 Mail team, will update the previous post (&lt;a class="bold" href="http://blogs.technet.com/b/exchange/archive/2012/11/26/supporting-windows-8-mail-in-your-organization.aspx" rel="nofollow" target="_new"&gt;Supporting Windows 8 Mail in your organization&lt;/a&gt;) with the info.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535532" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535531</link><pubDate>Thu, 29 Nov 2012 18:51:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535531</guid><dc:creator>Bharat Suneja [MSFT]</dc:creator><description>&lt;p&gt;@Benoit Boudeville: Thanks for catching that - fixed.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535531" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535443</link><pubDate>Thu, 29 Nov 2012 13:00:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535443</guid><dc:creator>Q</dc:creator><description>&lt;p&gt;What if you dont use Active Directory Integrated CA. That is, if you use Standalone CA or Public CA? check out this solution: &lt;a rel="nofollow" target="_new" href="http://refikunver.wordpress.com/2012/11/28/problem-exchange-active-sync-with-certificate-authentication-does-not-work-with-standalone-ca/"&gt;refikunver.wordpress.com/.../problem-exchange-active-sync-with-certificate-authentication-does-not-work-with-standalone-ca&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535443" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535411</link><pubDate>Thu, 29 Nov 2012 09:21:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535411</guid><dc:creator>Andreas Helland</dc:creator><description>&lt;p&gt;J,&lt;/p&gt;
&lt;p&gt;You&amp;#39;re right - it is problematic in deed.&lt;/p&gt;
&lt;p&gt;Android, iOS and Windows Phone all support client certs for EAS by now. But how you get the certificate onto the device varies:&lt;/p&gt;
&lt;p&gt;Android can use /certsrv.&lt;/p&gt;
&lt;p&gt;iOS can use iPhone Configuration Utility to enroll.&lt;/p&gt;
&lt;p&gt;Windows Phone 7.x can install a pfx file. (I have not tested whether WP 8 works with /certsrv yet, but it should support pfx as well.)&lt;/p&gt;
&lt;p&gt;There&amp;#39;s more details on this over at my blog:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://mobilitydojo.net/2012/01/31/certsrv-vs-mobile-devices/"&gt;mobilitydojo.net/.../certsrv-vs-mobile-devices&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://mobilitydojo.net/2011/12/31/client-certificates-in-android-ice-cream-sandwich/"&gt;mobilitydojo.net/.../client-certificates-in-android-ice-cream-sandwich&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Using MDM there are different approaches depending on how the vendor has chosen to implement it, but in general it will be easier for the end-user with MDM.&lt;/p&gt;
&lt;p&gt;There&amp;#39;s also a test utility on my blog if you like to test client certs auth and troubleshoot:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://mobilitydojo.net/downloads/"&gt;mobilitydojo.net/downloads&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535411" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535409</link><pubDate>Thu, 29 Nov 2012 09:13:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535409</guid><dc:creator>Benoit Boudeville</dc:creator><description>&lt;p&gt;Good article, however the SPN to add for the Exchange 2003 server is &amp;quot;HTTP/serverFQDN&amp;quot;, not &amp;quot;HTTP://serverFQDN&amp;quot;. You may also consider adding the shortname as it&amp;#39;s a common practice even though probably not required.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535409" width="1" height="1"&gt;</description></item><item><title>re: Configure certificate-based authentication for Exchange ActiveSync</title><link>http://blogs.technet.com/b/exchange/archive/2012/11/28/configure-certificate-based-authentication-for-exchange-activesync.aspx#3535400</link><pubDate>Thu, 29 Nov 2012 08:16:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535400</guid><dc:creator>Ronald den Os</dc:creator><description>&lt;p&gt;Why publish all those TMG whitepapers when Microsoft discontinues the product this week? Doesn&amp;#39;t make any sense...&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535400" width="1" height="1"&gt;</description></item></channel></rss>