• RSS
  • Twitter
  • FaceBook

Deb Shinder Blog RSS

All Blogs  »  Deb Shinder Blog  »  News  »  Blog article: Solving the "All Open" Rule Problem for Acquiring a Machine Certificate from an Enterprise CA

Solving the "All Open" Rule Problem for Acquiring a Machine Certificate from an Enterprise CA

Stefaan Pouseele posted a great blog entry this week on how to configure the Enterprise CA to use a specific port that can be used to make a request to an online Enterprise CA without having to create an “All Open” rule between the ISA Firewall and the CA. Stefaan points out that there are basically four steps:

  • On the CA, configure the RPC application or DCOM endpoint to use a custom TCP protocol port as a static port.
  • On the ISA, turn off the “Enable strict RPC compliance” setting on the RPC access rule.
  • On the ISA, create the custom protocol for outbound use.
  • On the ISA, create an access rule to allow the custom protocol between the required source and destination.

For the details on how to carry out the config, check out Stefaan’s blog at:

http://blogs.isaserver.org/pouseele/2007/10/12/cer...tocol/

HTH,

Tom

Thomas W Shinder, M.D.
Site: http://www.isaserver.org/

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

One Response to “Solving the "All Open" Rule Problem for Acquiring a Machine Certificate from an Enterprise CA”

  1. Audrea Calnimptewa Says:

    April 16th, 2011 at 10:50 am

    thanx! useful post, great blog!

Leave a Reply


Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!