ADS-Training Home
All Libraries and Lists
Site Management
Create (reserved)
Site Help
ADS-Training InfoCenter
Knowledge Base and Tips
: Microsoft security issue affecting Exchange...
New Item
|
Edit Item
|
Delete Item
|
Alert Me
|
Go Back to List
Title:
Microsoft security issue affecting Exchange Server 2003 and OWA
Body:
Microsoft has received reports of a security issue affecting Exchange Server 2003 and Outlook Web Access (OWA).
The problem occurs when a user installs Windows SharePoint Services 2.0 on top of Exchange Server 2003 and Windows Server 2003. The deployment causes Kerberos authentication to be disabled in Internet Information Services (IIS) and can result in the incorrect handling of Outlook Web Access requests to an Exchange Server.
At worst, this issue could result in access to mailboxes at random and only to an authenticated Exchange user in the same organization on the same network.
Microsoft is working with customers to ensure their information is protected. Microsoft has published two Knowledge Base articles that detail the problem and instruct customers how to correct and avoid this issue.
Microsoft Product Support has also successfully helped and is
continuing to help customers who have problems.
This information is available at
http://support.microsoft.com/?id=832769
and
http://support.microsoft.com/?id=832749
As a general rule, Microsoft recommends customers run Exchange 2003 with Kerberos enabled in Internet Information Services to achieve the most secure environment and that is why Windows Server 2003 ships with Kerberos enabled by default.
KB Article by ID Number:
Directory Services Keywords:
Kerberos W2000KERB
General Services Keywords:
AD GENERAL
Technologies Keywords:
LDAP
Networking Keywords:
WINDOWS LOGON
Expires:
Attachments:
Created at 7/6/2003 5:12 PM by
Jean-François APREA
Last modified at 1/6/2004 5:24 PM by
Jean-François APREA