Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Update on ISA 2006 SP1 Support for User Certificate Authentication

Update on ISA 2006 SP1 Support for User Certificate Authentication

A couple days ago I wrote to you about how ISA 2006 SP1 will allow you to perform User Certificate authentication at the ISA firewall without requiring that you map the certificate to a user account in the Active Directory and that the ISA firewall doesn’t need to be a member of the user domain. At the time I thought to myself “this is too good to be true” but I’ve seen the magic the ISA firewall team can perform, so I suppressed my incredulity and just gave thanks for such a great feature.

Well when something seems to be too good to be true, it usually is. I was informed yesterday that there was a slight error in the SP1 document at https://blogs.technet.com/isablog/archive/2008/05/...s.aspx

It turns out that while you can use User Certificate authentication when the machine isn’t a domain member and when the certificates aren’t mapped to the user accounts in the Active Directory, User Certificate authentication must be used together with Forms-based authentication. I’ve written about this in the past, where you can require both FBA and User Certificate Authentication. But in order for the new ISA 2006 SP1 User Certificate feature to work, you have to also use FBA.

If you want to use only User Certificate authentication, then the ISA Firewall will still need to be a domain member and the certificates will need to be mapped to the user accounts in the Active Directory.

HTH,

Tom

Thomas W Shinder, M.D.
Site: http://www.isaserver.org/

Blog: http://blogs.isaserver.org/shinder/
GET THE NEW BOOK! Go to 
http://tinyurl.com/2gpoo8
Email: tshinder@isaserver.org
MVP — Microsoft Firewalls (ISA)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center