<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Automatic Certificate Enrollment Fails on the ISA Firewall</title>
	<link>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Fri, 29 Aug 2008 17:58:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Thomas Godsk Joergensen</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-114194</link>
		<pubDate>Mon, 20 Aug 2007 13:00:33 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-114194</guid>
					<description>I've encountered the same problem on ISA 2006. As mentioned by Tom, if using Windows XP and Windows Server 2003 DCOM is used (Windows 2000 uses RPC). In that case, the problem can be resolved by disabling the RPC interface and fixing the TCP port used by DCOM on the issuing CA and then create a custom rule for this fixed port in addition to allowing RPC (all interfaces). It is all described in detail in the following Microsoft article on web enrollment: http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx. Search for &quot;Disabling the RPC Interface at the Issuing CA&quot; (without quotes) and read on.

HTH

Thomas</description>
		<content:encoded><![CDATA[<p>I&#8217;ve encountered the same problem on ISA 2006. As mentioned by Tom, if using Windows XP and Windows Server 2003 DCOM is used (Windows 2000 uses RPC). In that case, the problem can be resolved by disabling the RPC interface and fixing the TCP port used by DCOM on the issuing CA and then create a custom rule for this fixed port in addition to allowing RPC (all interfaces). It is all described in detail in the following Microsoft article on web enrollment: <a href='http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx' rel='nofollow'>http://www.microsoft.com/technet/prodtechnol/windo...l.mspx</a>. Search for &#8220;Disabling the RPC Interface at the Issuing CA&#8221; (without quotes) and read on.</p>
<p>HTH</p>
<p>Thomas
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-985</link>
		<pubDate>Sun, 28 May 2006 11:32:46 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-985</guid>
					<description>Hi Stefaan,
I've found that you need to disable the RPC filter *before* creating that access rule or else it won't work. Are you working with ISA 2006? Maybe that's the difference?
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Stefaan,<br />
I&#8217;ve found that you need to disable the RPC filter *before* creating that access rule or else it won&#8217;t work. Are you working with ISA 2006? Maybe that&#8217;s the difference?<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stefaan Pouseele</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-984</link>
		<pubDate>Sun, 28 May 2006 10:42:33 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/27/automatic-certificate-enrollment-fails-on-the-isa-firewall/#comment-984</guid>
					<description>Hi Tom, 

creating a temporary access rule from Localhost to the Internal Network allowing All Outbound Traffic seems to cure the problem too. 

HTH, 
Stefaan</description>
		<content:encoded><![CDATA[<p>Hi Tom, </p>
<p>creating a temporary access rule from Localhost to the Internal Network allowing All Outbound Traffic seems to cure the problem too. </p>
<p>HTH,<br />
Stefaan
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
