This post is an update to the original architectural guidance I published previously at http://blogs.technet.com/b/speschka/archive/2013/10/11/architecture-design-recommendation-for-sharepoint-2013-hybrid-search-features.aspx. If you read that post then you’ll recall that we had a “scenario problem” with hybrid search when SharePoint 2013 released. The problem, which I explain more fully in that post, is that there wasn’t a good way to publish both an endpoint for hybrid search as well as users outside of your firewall to access a SharePoint farm.
IMPORTANT: The features described in this post require that you install the April 2014 CU or later for SharePoint 2013. That introduced one breaking change that you will also need to fix for everything to work. Please see this post for details and the fix: http://blogs.technet.com/b/speschka/archive/2014/08/28/you-start-getting-a-401-unauthorized-error-when-using-the-sharepoint-hybrid-features-after-applying-april-2014-cu-or-later.aspx.
The good news is that the team has been able to add some new functionality to the hybrid features such that we can now support this scenario. In short what needs to be done is:
Here’s a few more details on these steps. To help illustrate, let’s assume you have a SharePoint zone with a Url of https://portal.contoso.com and it is reachable on your corporate network at IP address 10.1.1.1. You have a reverse proxy in your DMZ and it is configured to listen for incoming requests on IP address 175.10.10.10. Now let’s see how this scenario would be implemented.
When https://portal.contoso.com was created it was added to the default zone. We’re going to add another incoming Url for the zone that will be used for hybrid search, so I’ll call it https://hybrid.contoso.com. Now in terms of how you add the incoming Url I’ll just say that there are a few ways of doing it, and a lot of documentation out there for how to do it. For my purposes I created my web application with this in mind, so I used hybrid.contoso.com as the Host Header value and https://portal.contoso.com as the Public Url. After the web app was created I had to a) go add an incoming Url for the zone of https://hybrid.contoso.com and b) add another HTTPS binding in IIS on my web application so that it listens for portal.contoso.com. Since I used hybrid.contoso.com as the Host Header value when I created the web application, that HTTPS binding was already created in IIS. I used the SNI feature in IIS so I could set both host header values and still use SSL.
Configuring DNS for users to access the Public Url of the zone can be done in one of two ways:
Configuring DNS for the incoming Url for the SharePoint zone is much easier; you’re just going to create one A record in your external DNS for “hybrid.contoso.com” and it will use the IP address of the reverse proxy server, which is 175.10.10.10.
The exact details of how you publish endpoints in a reverse proxy are going to vary by the proxy product being used. For an example of how to use WAP in Windows Server 2012 R2 you can see one of my prior posts here: https://blogs.technet.com/b/speschka/archive/2013/12/23/configuring-windows-server-2012-r2-web-application-proxy-for-sharepoint-2013-hybrid-features.aspx. At a high level though there’s really just a couple of concepts you need to know when you publish the endpoints:
The goal here is to have two unique hostnames for the same SharePoint content. By using the AAM feature, when the request comes in for hybrid.contoso.com, any search results that it returns will be rendered using the Public URL for the zone, which is portal.contoso.com. When a user clicks on a search result then they will be sent to whatever IP address resolves for portal.contoso.com and they will be able to access the SharePoint content using their credentials, without having to provide a client certificate like hybrid search does. In your Office 365 tenant that also means that when you create the Result Source for the on premises farm, you need to configure the Url to be https://hybrid.contoso.com so that it gets routed to the correct published application on the reverse proxy server.
This is the last and most important step, which was provided by the April 2014 CU. A new property was added to both the SPSecurityTokenServiceConfig as well as SPWebApplication. The property is called UseIncomingUriToValidateAudience and is set to False by default. In order to get the hybrid features to use the AAM lookup as we’ve configured above you need to set it to true. To make this change farm wide, use the SPSecurityTokenServiceConfig object; to set it on just one web application use the SPWebApplication. Here’s an example of the PowerShell needed to set it at the farm level:
$cfg = Get-SPSecurityTokenServiceConfig
$cfg.UseIncomingUriToValidateAudience = $true
$cfg.Update()
Once you’ve completed all of these steps you should be able to have Office 365 issue inbound queries to your on premises farms and get search results back that are rendered using the Public Url of your SharePoint zone. This request will be securely authenticated using the client certificate you configure the Office 365 Result Source to use. You will also be able to have users outside your corporate network access the SharePoint zone using their corporate credentials, and they will not be required to present a client certificate to get to the SharePoint farm. This is a really nice improvement in the hybrid features so I hope you find it useful. For more details on the new property that was added please see this article on TechNet: http://technet.microsoft.com/en-us/library/dn751515(v=office.15).aspx.
Luis Enrique no stranger to the "super classic" (El Clasico) but over as a manager, this is the first time he experienced. M88 is anticipated difficulties are enormous when the military rulers faced a veteran Ancelotti, who has built a powerful empire at Real Madrid. Enrique debt union, with Real After Luis Aragones at the 1987/88 season, coach Luis Enrique will be the 2nd in the history of Barca attend "super classic" as a former player http://www.m88no.com/Main/Home.aspx?affiliateId=99156 jacket arch rivals Real Madrid. Yet another point is that, if the old Aragones only "polish" the bench at the Bernabeu next Enrique played 157 games, scoring 15 goals in the season for Los Blancos 5. Jump to a summer move to Barcelona in 1996, Enrique was the Madridista stigmatized for calling a traitor. The Bernabeu was back then, Enrique always receive encouragements from the crowd boos M88 and strident. But personally Enrique, he proved that his departure was justified to achieve the same success Barca.
Tao http://dichvuketoanlongbien.com/ Rủa http://dichvuketoanlongbien.com/a2-96-dich-vu-ke-toan-tron-goi.html Thằng http://dichvuketoanlongbien.com/a2-98-dich-vu-ke-toan-thue.html Cờ http://dichvuketoanlongbien.com/a2-103-dich-vu-bao-cao-tai-chinh.html Hó http://dichvuketoanlongbien.com/a2-97-dich-vu-quyet-toan-thue.html Nào http://dichvuketoanlongbien.com/a2-114-dich-vu-ke-toan-tai-29-quan-huyen.html Soi http://dichvuketoanlongbien.com/i780-dich-vu-ke-toan-thue-tron-goi-tai-bac-ninh.html Tài http://dichvuketoanlongbien.com/i779-dich-vu-ke-toan-thue-tron-goi-tai-bac-giang.html Khoản http://dichvuketoanlongbien.com/i778-dich-vu-ke-toan-thue-tron-goi-tai-phu-tho.html Và http://dichvuketoanlongbien.com/i781-dich-vu-ke-toan-thue-tron-goi-tai-hung-yen.html Link http://dichvuketoanlongbien.com/i782-dich-vu-ke-toan-thue-tron-goi-tai-vinh-phuc.html Của http://dichvuketoanlongbien.com/i783-dich-vu-ke-toan-thue-tron-goi-tai-hai-phong.html Tao. http://www.trungtamketoan.com.vn/ Chúng http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-ha-noi.html Mày http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-tp-hcm.html Đủ http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-quang-ninh.html Trình http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-hai-duong.html Thì http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-bac-giang.html Tự http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-bac-ninh.html Đi http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-hai-phong.html Mà http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-nam-dinh.html Làm. http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-thai-binh.html Việc http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-thanh-hoa.html Gì http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-vinh-phuc.html Phải http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-hung-yen.html Rẻ http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-phu-tho.html Rách http://www.trungtamketoan.com.vn/p/trung-tam-dao-tao-ke-toan-tai-binh-duong.html Như http://www.tosvn.com Thế. http://iketoan247.blogspot.com Loại http://tailieuveketoan.blogspot.com Chó http://mauhinhnendep.blogspot.com Má. http://www.tosvn.com/search/label/Hack%20CF Tao http://www.tosvn.com/search/label/Hack%20AvatarStar Rủa http://www.tosvn.com/search/label/Hack%20Warcraft-Dota2 Những http://hocketoan360.com/category/tai-lieu-ke-toan/ Thằng http://iketoan247.blogspot.com/search/label/thong-tin-kinh-te Soi http://iketoan247.blogspot.com/search/label/tin-bai-ve-thue Tao http://hoclamketoan.edu.vn/ Sẽ http://hoclamketoan.edu.vn/category/khoa-hoc-ke-toan Tan http://hoclamketoan.edu.vn/category/dich-vu-ke-toan Cửa http://hoclamketoan.edu.vn/category/hoc-lam-ke-toan Nát http://hoclamketoan.edu.vn/category/tai-lieu-ke-toan Nhà http://hocketoan360.com/ Haha http://hocketoan360.com/category/khoa-hoc-ke-toan/ http://hocketoan360.com/category/dich-vu-ke-toan/
http://www.burberryfactorys.com/ http://www.shophandbagsonline.com/ http://www.official-coachoutlet.com/ http://www.barbour-factory.com/ http://www.burberry-outlet2014.com/ http://www.gucci-factory.com/ http://www.marcjacobsonsale.com/ http://www.mcmworldwide.ca/ http://www.guccishoes-uk.com/ http://www.kate-spades.com/ http://www.louisvuittonas.com/ http://www.lv-guccishoesfactory.com/ http://www.official-mkoutlets.com/ http://www.official-pradaoutlet.com/ http://www.michael-korsusa.net/ http://www.north-facesoutlet.com/ http://www.moncler-clearance.com/ http://www.north-faceclearance.com/ http://www.clothes-mall.com/ http://www.polo-outlets.com/ http://www.ralphlauren.so/ http://www.ralphlaurentshirts.com/ http://www.ferragamos.in.net/ http://www.longchampsoutlet.com/ http://www.abercrombiee.com/ http://www.barbour-jacketsoutlet.com/ http://www.michael--korsonline.com/ http://www.thenorthface.so/ http://www.cheapuggsbootso.com/ http://www.beatsbydreoutlet.net/ http://www.tommyhilfiger.in.net/ http://www.ralphslauren.co.uk/ http://www.michaelkors.so/ http://www.oakleyssunglassoutlet.com/ http://www.warm-boots.com/ http://www.tory-burches.com/ http://www.woolrich-clearance.com/ http://www.tommy-hilfigeroutlet.com/ http://www.uggboots-factory.com/ http://www.official-northfaceoutlet.com/ http://www.nike-jordanshoes.com/ http://www.monsterbeatsbydres.net/ http://www.canada-gooser.com/ http://www.bestcustomsonline.com/ http://coach.mischristmas.com/ http://www.coach-blackfriday2014.com/ http://www.coachccoachoutlet.com/ http://www.coach-clearance.com/ http://www.coach-factories.net/ http://www.louisvuittonsas.com/ http://www.coach-factorysoutlet.com/ http://www.coachlosangeles.com/ http://www.coachoutletstates.com/ http://www.coach-pursesoutlets.com/ http://www.hermes-outletonline.com/ http://www.misblackfriday.com/ http://www.mischristmas.com/ http://www.mmoncler-outlet.com/ http://www.newoutletonlinemall.com/ http://www.ralphlaurenepolo.com/ http://www.zxcoachoutlet.com/ http://www.embereso.com/ http://www.varmoweuts.com/ http://www.bootiexew.com/ http://www.mistuesday.com/ http://www.towednesday.com/