Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  News  »  Blog article: Solving the "All Open" Rule Problem for Acquiring a Machine Certificate from an Enterprise CA

Solving the "All Open" Rule Problem for Acquiring a Machine Certificate from an Enterprise CA

Stefaan Pouseele posted a great blog entry this week on how to configure the Enterprise CA to use a specific port that can be used to make a request to an online Enterprise CA without having to create an “All Open” rule between the ISA Firewall and the CA. Stefaan points out that there are basically four steps:

  • On the CA, configure the RPC application or DCOM endpoint to use a custom TCP protocol port as a static port.
  • On the ISA, turn off the “Enable strict RPC compliance” setting on the RPC access rule.
  • On the ISA, create the custom protocol for outbound use.
  • On the ISA, create an access rule to allow the custom protocol between the required source and destination.

For the details on how to carry out the config, check out Stefaan’s blog at:

http://blogs.isaserver.org/pouseele/2007/10/12/cer...tocol/

HTH,

Tom

Thomas W Shinder, M.D.
Site: http://www.isaserver.org/

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center