<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx</link><description>What is a “SAN”? “SAN” in this context refers to the certificate attribute “Subject Alternative Name”. Among other uses, this attribute allows the site administrator to save money and administrative overhead by building a single certificate that lists</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Henrik Walther Blog  &amp;raquo; Blog Archive   &amp;raquo; Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1855202</link><pubDate>Wed, 29 Aug 2007 20:11:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1855202</guid><dc:creator>Henrik Walther Blog  » Blog Archive   » Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blogs.msexchange.org/walther/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing/"&gt;http://blogs.msexchange.org/walther/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1855762</link><pubDate>Wed, 29 Aug 2007 22:33:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1855762</guid><dc:creator>Marc Grote aka Jens Baier</dc:creator><description>&lt;p&gt;Hi Jim,&lt;/p&gt;
&lt;p&gt;great information about SAN certificates on ISA. Do you know when the solution from the ISA team will be available?&lt;/p&gt;
&lt;p&gt;regards Marc Grote&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1855827</link><pubDate>Wed, 29 Aug 2007 22:46:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1855827</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Marc,&lt;/p&gt;
&lt;p&gt;We're examining our options. &amp;nbsp;We can't discuss an ETA until we're satisified with the scope of the problem and the solution options we have.&lt;/p&gt;
&lt;p&gt;I'll comment here when we reach a decision.&lt;/p&gt;
</description></item><item><title>ISA Server 2006 a certifkáty s SAN jmény</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1860058</link><pubDate>Thu, 30 Aug 2007 13:32:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1860058</guid><dc:creator>TechNet Blog CZ/SK</dc:creator><description>&lt;p&gt;Pokud jste se někdy snažili o publikaci služeb Exchange Server 2007 skrze ISA Server 2006, dost pravděpodobně&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1864699</link><pubDate>Fri, 31 Aug 2007 04:31:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1864699</guid><dc:creator>Elan Shudnow</dc:creator><description>&lt;p&gt;If you want your other SAN names to work, just keep your TO: tab to be either the CN or 1st SAN name as the article suggests, and just change the Public Name tab to be the name of another SAN name and it'll work just fine.&lt;/p&gt;
&lt;p&gt;An example is included in my blog entry below where I explain how to get this to work with both Exchange web services as well as autodiscover using a SAN cert. &amp;nbsp;So for those wanting to get Autodiscover, Web Services, EAS, OA, OWA, etc. using a SAN cert all published on ISA 2006, check out the following article:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/"&gt;http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1869137</link><pubDate>Fri, 31 Aug 2007 18:26:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1869137</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Elan,&lt;/p&gt;
&lt;p&gt;Actually, what you do at the web listener itself has no bearing on how ISA acts as a &amp;quot;certificate consumer&amp;quot;. &amp;nbsp;Based on recent threads in the isapros list and some other offline comments, this seems to be a common point of confusion.&lt;/p&gt;
&lt;p&gt;While it's true that OL operates similarly to ISA regarding SAN enteirs, this only means that you make &amp;quot;autodiscover&amp;quot; the Subject or first SAN entry in the cert associated with the web listener.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1896776</link><pubDate>Tue, 04 Sep 2007 22:36:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1896776</guid><dc:creator>tshinder</dc:creator><description>&lt;p&gt;Jim,&lt;/p&gt;
&lt;p&gt;This is interesting in that seems to contrast with what Steven Hope has found in his investigations of how ISA acts as a &amp;quot;consumer&amp;quot; of server certificates of a published Web site. Over at:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://isaserver.org/tutorials/Generating-SSL-Certificates-Exchange-2007-ISA-Server-2006.html#"&gt;http://isaserver.org/tutorials/Generating-SSL-Certificates-Exchange-2007-ISA-Server-2006.html#&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;He says:&lt;/p&gt;
&lt;p&gt;&amp;quot;To top all this, ISA 2006 has a bug regarding Common Names (CNs) and Subject Alternative Names (SANs). When ISA Server bridges a SSL Connection to a web server with a certificate containing SANs, it ignores the CN and only does a name match with the FIRST SAN entry! To work around this make sure the FIRST SAN listed is the same as the CN which in this scenario is MAIL.VIRCOM.CO.UK&amp;quot;&lt;/p&gt;
&lt;p&gt;So, if I read it correctly, you say that ISA will use *either* the common/subject name or the first SAN. Steven says that the common/subject name is ignored and only the first SAN is used.&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1897202</link><pubDate>Tue, 04 Sep 2007 23:46:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1897202</guid><dc:creator>Jim Harrison</dc:creator><description>&lt;p&gt;Hi Tom,&lt;/p&gt;
&lt;p&gt;That's interesting. &amp;nbsp;My testing (yes, I really did test this &amp;lt;g&amp;gt;) was quite different; ISA 2006 recognized the Subject name just fine. &amp;nbsp;Could be there's someting in his environment that caused his observaations..?&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1928080</link><pubDate>Sun, 09 Sep 2007 12:15:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1928080</guid><dc:creator>Mohit Saxena</dc:creator><description>&lt;p&gt;In the test I did I only saw ISA using the CN only if there was no SAN present. If multiple SAN were present it would only use the SAN and not the CN.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#1995068</link><pubDate>Wed, 19 Sep 2007 19:01:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1995068</guid><dc:creator>Steven Hope</dc:creator><description>&lt;p&gt;Hi Jim and Tom&lt;/p&gt;
&lt;p&gt;ISA 2006 behaved in the following way during my testing:&lt;/p&gt;
&lt;p&gt;If there was a cert on the exchange server 2007 that had NO SAN entry then the CN was used - as expected. However, if there was a cert on the exchange server that had at least one SAN entry then ISA ONLY looked at the first SAN entry and ignored the CN completely. In conclusion it seemed that ISA 2006 would ONLY look at the CN if there were NO SAN entries at all.&lt;/p&gt;
&lt;p&gt;My recommendation is thus to always make the first SAN entry the same as the CN so ISA behaves the way you would expect it to, i.e. appears to use the CN even though its actually using the first SAN. It would be nice if ISA would FIRST look at the CN and if a match isn’t found, SECOND run through the list of SAN’s, but that isn’t the case. &lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Steven Hope&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2148009</link><pubDate>Wed, 10 Oct 2007 19:34:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2148009</guid><dc:creator>Rick Engle</dc:creator><description>&lt;p&gt;How would this configuration be enhanced to support an environment where on the front-end server there are two URLs and certificates, one for OWA and one for Exchange ActiveSync. &amp;nbsp;There were some significant challenges when coming up with an ISA SSL configuration that could support a web farm of two FE servers hosting OWA, that certificate has a SAN and adding to that configuration support for EAS, leveraging that same web farm but using a different certificate and URL.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2179033</link><pubDate>Tue, 16 Oct 2007 00:01:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2179033</guid><dc:creator>Jim Harrison (ISA SE)</dc:creator><description>&lt;p&gt;You'd have to create separate rules for each VRoot that operates under a different certificate.&lt;/p&gt;
&lt;p&gt;ISA redirects based on the published hostname, and if these differ between VRoots (whether they're separate servers or simply separate IIS listeners), then you need sepoarate rules.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2186054</link><pubDate>Wed, 17 Oct 2007 01:50:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2186054</guid><dc:creator>ilantz</dc:creator><description>&lt;p&gt;Jim ! where was this wonderful guide when i needed it :)??&lt;/p&gt;
&lt;p&gt;I had a terrible time to figure this out on ISA 2004 , now that i noticed both this article &amp;amp; the update to autodiscovery service i'll might just re-do this all over again...properly this time.&lt;/p&gt;
&lt;p&gt;Thanks !&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2435794</link><pubDate>Tue, 13 Nov 2007 22:23:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2435794</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;What a nightmare. &amp;nbsp;Is it too much to expect the “recommended” firewall for Exchange 2007 to “just work” correctly the first time? &amp;nbsp;Did anyone bother piloting this before Exchange 2007 shipped?&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2447986</link><pubDate>Wed, 14 Nov 2007 19:28:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2447986</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;There's a temporal disconnect you're overlooking.&lt;/p&gt;
&lt;p&gt;ISA 2006 shipped before Exchange 2007.&lt;/p&gt;
&lt;p&gt;SAN certificates didn't become part of the Exchange recommended deployment until after Exch 2007 shipped.&lt;/p&gt;
&lt;p&gt;It's rather difficult for any product team to test &amp;quot;future scenarios&amp;quot;, but we're working on it.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2456225</link><pubDate>Thu, 15 Nov 2007 07:18:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2456225</guid><dc:creator>Marty</dc:creator><description>&lt;p&gt;The temporal disconnect is funny, but the sad reality is that the ISA team has had almost a year to release a hotfix or service pack that addresses this problem. And if we include the beta/RC period then you've had well over a year. &amp;nbsp;How much time do you think is reasonable?&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2576081</link><pubDate>Wed, 28 Nov 2007 01:09:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2576081</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;The reality (sad or not) is that SAN certificates were not in common use by ISA administrators until just before this blog was motivated (days; not years).&lt;/p&gt;
&lt;p&gt;Had they been as commonly deployed in ISA web publishing scenarios as you seem to believe, you can certainly bet that ISA customers would have made plenty of noise before now (they haven't).&lt;/p&gt;
&lt;p&gt;Because the problem and resolution are much more complex than they appear, we're planning on shipping the fix with ISA 2006 SP1 to ensure proper regression testing. &amp;nbsp;The schedule for this SP will be released ASAP.&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2812317</link><pubDate>Sat, 02 Feb 2008 09:47:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2812317</guid><dc:creator>royal</dc:creator><description>&lt;p&gt;Any update on this? &amp;nbsp;When is ISA going to be patched so it can use all the SAN entries on a SAN cert?&lt;/p&gt;
</description></item><item><title>Firewalls and Internet Based Client Management: Part 2: ISA Bridging with ConfigMgr 2007</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2892290</link><pubDate>Fri, 15 Feb 2008 03:37:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2892290</guid><dc:creator>Adam Meltzer's Configuration Manager Blog</dc:creator><description>&lt;p&gt;I was going to save this for last, but there's been a lot of questions lately about this that I've been fielding, including a hot interest at TechReady 6 about ISA bridging. This is not a meant to be a step-by-step guide, and will require a bit of familiarity&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#2940611</link><pubDate>Thu, 28 Feb 2008 20:02:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2940611</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Adam and I are working on a slightly different scenario for publishing SCCM through ISA. &amp;nbsp;It's not specifically related to SAN certificates.&lt;/p&gt;
&lt;p&gt;Jim&lt;/p&gt;
</description></item><item><title>ISA Server 2006 Service Pack 1 Features</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#3060221</link><pubDate>Sat, 24 May 2008 02:06:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3060221</guid><dc:creator>ISA Server Product Team Blog</dc:creator><description>&lt;p&gt;ISA Server 2006 Service Pack 1 Features Introduction Microsoft &amp;#174; Internet Security and Acceleration (ISA)&lt;/p&gt;
</description></item><item><title>Firewalls and Internet Based Client Management: Part 2: ISA Bridging with ConfigMgr 2007 (Take Two)</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#3082549</link><pubDate>Wed, 02 Jul 2008 23:11:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3082549</guid><dc:creator>Adam Meltzer's Configuration Manager Blog</dc:creator><description>&lt;p&gt;IMPORTANT: This post is being kept for archival purposes, but please reference &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/cc707697"&gt;http://technet.microsoft.com/en-us/library/cc707697&lt;/a&gt;(TechNet.10).aspx&lt;/p&gt;
</description></item><item><title>Point sur l'utilisation des certificats SAN avec ISA Server</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#3085812</link><pubDate>Wed, 09 Jul 2008 00:36:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3085812</guid><dc:creator>David Pekmez's Blog</dc:creator><description>&lt;p&gt;Article tr&amp;#232;s complet sur l'utilisation des certificats SAN avec ISA, &lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx"&gt;http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Certificates with Multiple SAN Entries May Break ISA Server Web Publishing</title><link>http://blogs.technet.com/isablog/archive/2007/08/29/certificates-with-multiple-san-entries-may-break-isa-server-web-publishing.aspx#3245596</link><pubDate>Tue, 26 May 2009 10:56:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3245596</guid><dc:creator>HD Video Converter</dc:creator><description>&lt;p&gt;Open Interoperability Lab &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/presspass/press/2007/sep07/09-11MSNovellLabsPR.mspx"&gt;http://www.microsoft.com/presspass/press/2007/sep07/09-11MSNovellLabsPR.mspx&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>