Outlook Anywhere not working through proxy with HTTPS inspectionProper syntax for generating an SSL certificate CSR to protect an Exchange 2007 serverExchange 2003 Outlook Anywhere - Changed certificate, not workingOutlook Anywhere asking for passwordOWA, Outlook Anywhere, RPCPing InconsistenciesClarifying terminology: MAPI vs RPC/HTTPS vs Outlook AnywhereLocal CA for remote web serverOutlook Anywhere remote https connection issueExchange 2010 Outlook Anywhere not working - RPC Proxy, Address Book?Linux HTTPS Header inspectionApache2.4: Forward proxy for client certificate authentication to IIS7

Is there a risk to write an invitation letter for a stranger to obtain a Czech (Schengen) visa?

How can I maintain game balance while allowing my player to craft genuinely useful items?

Why can't I craft scaffolding in Minecraft 1.14?

Right indicator flash-frequency has increased and rear-right bulb is out

Operator currying: how to convert f[a,b][c,d] to a+c,b+d?

Print the new site header

How did Frodo know where the Bree village was?

How can caller ID be faked?

First occurrence in the Sixers sequence

How can I prevent a user from copying files on another hard drive?

How to recover a single blank shot from a film camera

Would a 7805 5v regulator drain a 9v battery?

How useful is the GRE Exam?

What is this airplane that sits in front of Barringer High School in Newark, NJ?

You may find me... puzzling

I have found ports on my Samsung smart tv running a display service. What can I do with it?

In the US, can a former president run again?

Got a new frameset, don't know why I need this split ring collar?

Is swap gate equivalent to just exchanging the wire of the two qubits?

Using roof rails to set up hammock

Can a character with the Polearm Master feat make an opportunity attack against an invisible creature that enters their reach?

What is the context for Napoleon's quote "[the Austrians] did not know the value of five minutes"?

How could I create a situation in which a PC has to make a saving throw or be forced to pet a dog?

Time at 1G acceleration to travel 100 000 light years



Outlook Anywhere not working through proxy with HTTPS inspection


Proper syntax for generating an SSL certificate CSR to protect an Exchange 2007 serverExchange 2003 Outlook Anywhere - Changed certificate, not workingOutlook Anywhere asking for passwordOWA, Outlook Anywhere, RPCPing InconsistenciesClarifying terminology: MAPI vs RPC/HTTPS vs Outlook AnywhereLocal CA for remote web serverOutlook Anywhere remote https connection issueExchange 2010 Outlook Anywhere not working - RPC Proxy, Address Book?Linux HTTPS Header inspectionApache2.4: Forward proxy for client certificate authentication to IIS7






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








2















I'm currently working at a customer's site where they use a web proxy with HTTPS inspection: for each HTTPS connection, the proxy acts as a man-in-the-middle by terminating the HTTPS channel, generating a new certificate using its own internal CA and presenting it to the client; of course, the client complains about the certificate being invalid: in order to avoid this, I've imported the proxy root certificate in my computer's local certificate store. I can succesfully browse HTTPS web sites and I receive no warnings; this includes OWA on my company's Exchange server.



However, Outlook Anywhere (which uses the exact same public name and certificate as OWA) doesn't work. Outlook gives no error messages, it simply doesn't connect at all.



Why? And How can I fix this?










share|improve this question






















  • In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

    – 1.618
    Apr 17 '13 at 13:12











  • That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

    – Massimo
    Apr 17 '13 at 13:48











  • Is it being set by Group Policy?

    – 1.618
    Apr 17 '13 at 14:35











  • No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

    – Massimo
    Apr 17 '13 at 14:44











  • Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

    – Jeremy Lyons
    Apr 18 '13 at 3:24

















2















I'm currently working at a customer's site where they use a web proxy with HTTPS inspection: for each HTTPS connection, the proxy acts as a man-in-the-middle by terminating the HTTPS channel, generating a new certificate using its own internal CA and presenting it to the client; of course, the client complains about the certificate being invalid: in order to avoid this, I've imported the proxy root certificate in my computer's local certificate store. I can succesfully browse HTTPS web sites and I receive no warnings; this includes OWA on my company's Exchange server.



However, Outlook Anywhere (which uses the exact same public name and certificate as OWA) doesn't work. Outlook gives no error messages, it simply doesn't connect at all.



Why? And How can I fix this?










share|improve this question






















  • In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

    – 1.618
    Apr 17 '13 at 13:12











  • That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

    – Massimo
    Apr 17 '13 at 13:48











  • Is it being set by Group Policy?

    – 1.618
    Apr 17 '13 at 14:35











  • No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

    – Massimo
    Apr 17 '13 at 14:44











  • Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

    – Jeremy Lyons
    Apr 18 '13 at 3:24













2












2








2








I'm currently working at a customer's site where they use a web proxy with HTTPS inspection: for each HTTPS connection, the proxy acts as a man-in-the-middle by terminating the HTTPS channel, generating a new certificate using its own internal CA and presenting it to the client; of course, the client complains about the certificate being invalid: in order to avoid this, I've imported the proxy root certificate in my computer's local certificate store. I can succesfully browse HTTPS web sites and I receive no warnings; this includes OWA on my company's Exchange server.



However, Outlook Anywhere (which uses the exact same public name and certificate as OWA) doesn't work. Outlook gives no error messages, it simply doesn't connect at all.



Why? And How can I fix this?










share|improve this question














I'm currently working at a customer's site where they use a web proxy with HTTPS inspection: for each HTTPS connection, the proxy acts as a man-in-the-middle by terminating the HTTPS channel, generating a new certificate using its own internal CA and presenting it to the client; of course, the client complains about the certificate being invalid: in order to avoid this, I've imported the proxy root certificate in my computer's local certificate store. I can succesfully browse HTTPS web sites and I receive no warnings; this includes OWA on my company's Exchange server.



However, Outlook Anywhere (which uses the exact same public name and certificate as OWA) doesn't work. Outlook gives no error messages, it simply doesn't connect at all.



Why? And How can I fix this?







proxy exchange-2010 ssl-certificate https outlook-anywhere






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Apr 17 '13 at 9:36









MassimoMassimo

53.6k45172288




53.6k45172288












  • In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

    – 1.618
    Apr 17 '13 at 13:12











  • That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

    – Massimo
    Apr 17 '13 at 13:48











  • Is it being set by Group Policy?

    – 1.618
    Apr 17 '13 at 14:35











  • No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

    – Massimo
    Apr 17 '13 at 14:44











  • Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

    – Jeremy Lyons
    Apr 18 '13 at 3:24

















  • In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

    – 1.618
    Apr 17 '13 at 13:12











  • That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

    – Massimo
    Apr 17 '13 at 13:48











  • Is it being set by Group Policy?

    – 1.618
    Apr 17 '13 at 14:35











  • No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

    – Massimo
    Apr 17 '13 at 14:44











  • Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

    – Jeremy Lyons
    Apr 18 '13 at 3:24
















In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

– 1.618
Apr 17 '13 at 13:12





In the Microsoft Exchange Proxy Settings (Outlook Anywhere) in Outlook, have you tried unchecking "Only connect to proxy servers that have this principal name in their certificate"?

– 1.618
Apr 17 '13 at 13:12













That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

– Massimo
Apr 17 '13 at 13:48





That was my first guess. But it gets automatically checked again as soon as I launch Outlook.

– Massimo
Apr 17 '13 at 13:48













Is it being set by Group Policy?

– 1.618
Apr 17 '13 at 14:35





Is it being set by Group Policy?

– 1.618
Apr 17 '13 at 14:35













No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

– Massimo
Apr 17 '13 at 14:44





No, there's no GPO configuring that; and anyway, my laptop is not even joined to the domain.

– Massimo
Apr 17 '13 at 14:44













Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

– Jeremy Lyons
Apr 18 '13 at 3:24





Do you get any useful feedback using the downloadable client from www.testexchangeconnectivity.com ? I haven't used it in a while, but I think it supports Outlook Anywhere tests.

– Jeremy Lyons
Apr 18 '13 at 3:24










2 Answers
2






active

oldest

votes


















0














What is the proxy server they are using? I know with WinGate you can configure some pretty funky policies based on a number of things which may help you?



I would suggest you have a look through the proxy servers log files, it should give you a clue as to why it is failing.






share|improve this answer






























    0














    The Outlook client is behaving exactly as designed--it is effectively protecting your Outlook Anywhere traffic from a 'man-in-the-middle' attack.



    The 'Only connect to proxy servers that have this principal name in their certificate' option is likely being re-asserted by the client autodiscover process--again, as designed.



    I believe your only options are to (1) work with the deep-packet-inspection-firewall administrator to modify policies within the proxy server to handle your Outlook Anywhere traffic as an exception and eliminate the 'man-in-the-middle' inspection (e.g. convince the admin to 'trust' traffic from your Exchange Client Access Server), (2) see if the client can provide you with access to a 'guest' network which bypasses the deep-packet-inspection MITM proxy server, or (3) resign yourself to using OWA to access your mailbox while on that client's network.






    share|improve this answer























      Your Answer








      StackExchange.ready(function()
      var channelOptions =
      tags: "".split(" "),
      id: "2"
      ;
      initTagRenderer("".split(" "), "".split(" "), channelOptions);

      StackExchange.using("externalEditor", function()
      // Have to fire editor after snippets, if snippets enabled
      if (StackExchange.settings.snippets.snippetsEnabled)
      StackExchange.using("snippets", function()
      createEditor();
      );

      else
      createEditor();

      );

      function createEditor()
      StackExchange.prepareEditor(
      heartbeatType: 'answer',
      autoActivateHeartbeat: false,
      convertImagesToLinks: true,
      noModals: true,
      showLowRepImageUploadWarning: true,
      reputationToPostImages: 10,
      bindNavPrevention: true,
      postfix: "",
      imageUploader:
      brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
      contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
      allowUrls: true
      ,
      onDemand: true,
      discardSelector: ".discard-answer"
      ,immediatelyShowMarkdownHelp:true
      );



      );













      draft saved

      draft discarded


















      StackExchange.ready(
      function ()
      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f500119%2foutlook-anywhere-not-working-through-proxy-with-https-inspection%23new-answer', 'question_page');

      );

      Post as a guest















      Required, but never shown

























      2 Answers
      2






      active

      oldest

      votes








      2 Answers
      2






      active

      oldest

      votes









      active

      oldest

      votes






      active

      oldest

      votes









      0














      What is the proxy server they are using? I know with WinGate you can configure some pretty funky policies based on a number of things which may help you?



      I would suggest you have a look through the proxy servers log files, it should give you a clue as to why it is failing.






      share|improve this answer



























        0














        What is the proxy server they are using? I know with WinGate you can configure some pretty funky policies based on a number of things which may help you?



        I would suggest you have a look through the proxy servers log files, it should give you a clue as to why it is failing.






        share|improve this answer

























          0












          0








          0







          What is the proxy server they are using? I know with WinGate you can configure some pretty funky policies based on a number of things which may help you?



          I would suggest you have a look through the proxy servers log files, it should give you a clue as to why it is failing.






          share|improve this answer













          What is the proxy server they are using? I know with WinGate you can configure some pretty funky policies based on a number of things which may help you?



          I would suggest you have a look through the proxy servers log files, it should give you a clue as to why it is failing.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Jul 12 '13 at 0:28









          JaseJase

          1116




          1116























              0














              The Outlook client is behaving exactly as designed--it is effectively protecting your Outlook Anywhere traffic from a 'man-in-the-middle' attack.



              The 'Only connect to proxy servers that have this principal name in their certificate' option is likely being re-asserted by the client autodiscover process--again, as designed.



              I believe your only options are to (1) work with the deep-packet-inspection-firewall administrator to modify policies within the proxy server to handle your Outlook Anywhere traffic as an exception and eliminate the 'man-in-the-middle' inspection (e.g. convince the admin to 'trust' traffic from your Exchange Client Access Server), (2) see if the client can provide you with access to a 'guest' network which bypasses the deep-packet-inspection MITM proxy server, or (3) resign yourself to using OWA to access your mailbox while on that client's network.






              share|improve this answer



























                0














                The Outlook client is behaving exactly as designed--it is effectively protecting your Outlook Anywhere traffic from a 'man-in-the-middle' attack.



                The 'Only connect to proxy servers that have this principal name in their certificate' option is likely being re-asserted by the client autodiscover process--again, as designed.



                I believe your only options are to (1) work with the deep-packet-inspection-firewall administrator to modify policies within the proxy server to handle your Outlook Anywhere traffic as an exception and eliminate the 'man-in-the-middle' inspection (e.g. convince the admin to 'trust' traffic from your Exchange Client Access Server), (2) see if the client can provide you with access to a 'guest' network which bypasses the deep-packet-inspection MITM proxy server, or (3) resign yourself to using OWA to access your mailbox while on that client's network.






                share|improve this answer

























                  0












                  0








                  0







                  The Outlook client is behaving exactly as designed--it is effectively protecting your Outlook Anywhere traffic from a 'man-in-the-middle' attack.



                  The 'Only connect to proxy servers that have this principal name in their certificate' option is likely being re-asserted by the client autodiscover process--again, as designed.



                  I believe your only options are to (1) work with the deep-packet-inspection-firewall administrator to modify policies within the proxy server to handle your Outlook Anywhere traffic as an exception and eliminate the 'man-in-the-middle' inspection (e.g. convince the admin to 'trust' traffic from your Exchange Client Access Server), (2) see if the client can provide you with access to a 'guest' network which bypasses the deep-packet-inspection MITM proxy server, or (3) resign yourself to using OWA to access your mailbox while on that client's network.






                  share|improve this answer













                  The Outlook client is behaving exactly as designed--it is effectively protecting your Outlook Anywhere traffic from a 'man-in-the-middle' attack.



                  The 'Only connect to proxy servers that have this principal name in their certificate' option is likely being re-asserted by the client autodiscover process--again, as designed.



                  I believe your only options are to (1) work with the deep-packet-inspection-firewall administrator to modify policies within the proxy server to handle your Outlook Anywhere traffic as an exception and eliminate the 'man-in-the-middle' inspection (e.g. convince the admin to 'trust' traffic from your Exchange Client Access Server), (2) see if the client can provide you with access to a 'guest' network which bypasses the deep-packet-inspection MITM proxy server, or (3) resign yourself to using OWA to access your mailbox while on that client's network.







                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Oct 8 '13 at 4:30









                  jnaabjnaab

                  900611




                  900611



























                      draft saved

                      draft discarded
















































                      Thanks for contributing an answer to Server Fault!


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid


                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.

                      To learn more, see our tips on writing great answers.




                      draft saved


                      draft discarded














                      StackExchange.ready(
                      function ()
                      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f500119%2foutlook-anywhere-not-working-through-proxy-with-https-inspection%23new-answer', 'question_page');

                      );

                      Post as a guest















                      Required, but never shown





















































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown

































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown







                      Popular posts from this blog

                      Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                      Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                      Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020