7. Wat is Autodiscover Automatische client configuratie Goedvooreindgebruikers Goedvoor de IT afdeling Onafhankelijk van lokatie Ontsluiting Exchange functionaliteiten Exchange Web Services
8. Hoe werkt het Informatiebron (CAS) via AD of DNS(.. alshet moetlokale XML file, kb956955) Levert op: Displayname Mailbox Server External + Internal Connection Settings External + Internal URLs Free/Busy, OAB, OOF & UM Outlook Anywhere
10. Intern vs. Extern Interne client (domain joined) Discovery via Service Connection Point (SCP) in AD CN=Autodiscover,CN=Protocols,CN=<CAS Server>,CN=Servers,CN=<AG>,CN=Administrative Groups,CN=<ORG>,CN=Microsoft Exchange,CN=Services Autoconfiguratie via POX1 Externe client Discovery via DNS Autoconfiguratievia POX1 Meerdere scenarios Single/Multi SMTP domain 1) POX= Plain Old XML
11. Service Connection Point Publicatie in Active Directory door CAS servers: CN=Autodiscover,CN=Protocols,CN=<CAS Server>,CN=Servers,CN=<AG>,CN=Administrative Groups,CN=<ORG>,CN=Microsoft Exchange,CN=Services Attributes: serviceBindingInformation = CAS FQDN keywords = Site (Site Affinity) Reconfig via Set-ClientAccessServer, parameters: AutodiscoverServiceInternalURI = URL Site = Authoritative Site(s)
12. Intern 2. Query SCP objects 3. Autodiscover URL(s) 1. Register SCP (AutodiscoverInternalURI) 4. Connect Outlook 5. Available Services URLs
13.
14. DNS, Single Domain 1. Contact AD 2. Resolve contoso.com 3. Resolve autodiscover.contoso.com 4. Post autodiscover.contoso.com/autodiscover/autodiscover.xml Outlook michel.de.rooij@contoso.com 5. Available Services URLs
15. DNS, Redirect, Multi Domain 1. Contact AD 2. Resolve fabrikam.com 3. Resolve autodiscover.fabrikam.com 4. https://autodiscover.fabrikam.com/autodiscover/autodiscover.xml 5. Post http://autodiscover.fabrikam.com/autodiscover/autodiscover.xml Outlook michel.de.rooij@fabrikam.com 6. Redirect (302) to autodiscover.contoso.com 7. Contact autodiscover.contoso.com 8. Available Services URLs
16. Redirect, How-To IIS Nieuwe Virtual Website (+ 2e IP adres) Redirect /autodiscover/autodiscover.xml naar https://autodiscover.<domain>/autodiscover/autodiscover.xml ISA Web Publishing rule Bind 2nd public IP to ISA New website, deny non-SSL rule op autodiscover.<altdomain>/autodiscover/autodiscover.xml en redirect naarhttps://autodiscover.<maildomain>/autodiscover Plus: ISA array => danook redirect load balanced
17. Multidomain: Redirect of SRV DNS / HTTP Redirect SRV Record Pro: Werkt in alle scenarios Werktvooralle Outlook 2007 versies Con: Implementatie Onderhoud 2 x public IP adres (multidomain) Popup Pro: Implementatie 1 public IP adres Con: DNS provider SRV support Client env. SRV support (proxy) Werktniet in alle scenarios Outlook2007SP1/RTM+ kb940881 Popup Noot: Redirect Popup onderdrukbaar (kb956528)
19. Autodiscover & Certificates Wanneer is eencertificaatgeldig(Outlook 2007) Certificaat chain t/m trusted root Naam op certificaat matched URL Certificaatgeldig en niet expired Noot: Outlook op domain joined clients slaan regel 1 over (ivm self-signed certificates)
20.
21. Names to Register Interne namen Server hostname(s) Server interne FQDN(s) ..of Array FQDN Externenamen Domeinnamenvoor OWA/POP/IMAP Autodiscoverdomeinnamen Voorbeeld mbx1, mbx1.contoso.local,mail.contoso.com, autodiscover.contoso.com Let op: ISA 2006 RTM -> 1e SAN = CN Private Key exporteerbaarivm Export/Import ISA
22. Certificate Authorities “De Autodiscover Microsoft lijst” Entrust ($449, 10 names, 1yr, single srv) Comodo($285, 3 names, 1yr, single srv) DigiCert($328, 4 names, 1yr, unlimited srv) http://support.microsoft.com/kb/929395 Overigeaanbieders b.v. via sslshopper.com Let op: Federated Sharing gewenst? Comodo, Digicert, Entrust, Go Daddyhttp://technet.microsoft.com/en-us/library/ee332350.aspx
24. Certificaat Export/Import Voorb.v. publikatie Exchange in ISA ISA 2006 SP1 support SAN certs Vergeet export private key niet Fileformat Chain(PKCS#7/P7B, .p7b) Chain+private key (PKCS#12/PFX, .pfx, p12)
25. Autodiscover in Exchange 2010 AutodiscoverPOX of SOAP1 Meer Web Services ECP (voor UM), Archive, MailTips Let op wijzigingen in cmdlet syntax o.a. New-ExchangeCertificate ECM functies o.a. Certificate Request Wizard 1) SOAP= Simple Object Access Protocol = XML Web Services
29. Autodiscover Support Microsoft Outlook 2007 (SP1)+ Windows Mobile 6.1+ Entourage 2008 SP1+ Apple iPhone, Snow Leopard Nokia N-series, E-series Diverse Sony Ericsson & Palm modellen Bijtwijfel: Raadpleegproduktinformatie & test Let op:Support voorsynchronisatie met Exchange 2007/2010 betekentnietdat client/device Autodiscoverondersteunt
30. Links Exchange 2007 Autodiscover Whitepaper http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx Autodiscover en Exchange 2007 (LANvision 8/2006) http://www.ngn.nl/ngndirs/up/ZstwnvyHcD_LanVision32.pdf Understanding the Autodiscover Service (Exchange 2010) http://technet.microsoft.com/en-us/library/bb124251.aspx
Local XML zieo.a. blogs.technet.com/ilvancri/archive/2010/02/03/some-autodiscover-fun.aspx
Let op: Keywords can contain Site=<Sitename> or GUIDs, e.g. 77378F46-2C66-4aa9-A6A6-3E7A48B19596 or 67661D7F-8FC4-4fa7-BFAC-E1D7794C1F6. Zie [MS-OXDISCO]
SCPs are selected at “random”, unless Site set
Uiteraardook in beidegevallenook DNS regelenMeerdere e-mail domeinen (multi-tenant)Preciezeimplementatie redirect in IIS hangtaf van IIS (6 of 7)
Voor SRV, CN in certificate moetmatchen met SCP (AutodiscoverInternalURI) en InternalURLs (defaults to NetBIOS names of servers) => Outlook certificate warningProxy = proxy + ISA fw client
External + Internal is afhankelijk split DNSGeen Server Gated Cryptography (SGC) (SGC is to create 128-bit SSL support for pre-2000 browsers (~1% population))Wildcard certs compatibility issues subdomains, cert *.contoso can issue warnings for mail1.emea.contoso.com. Probable with WinMobileWildcard certs for single domain domain onlySingle/multi server licentieivm import op ISA of NLB/array
Don’t forget to include outer Edge/Hub (w/Antispam agents) transports etc. when you want to use the UCC certificate for SMTP TLSYou can use FQDNs instead of NetBIOS (default registered for URIs) but they influence load balancing scheme (reverts to netmask ordering instead, which goes before RoundRobin)Note: Ex2007SP1: New-ExchangeCertificate, leave autodiscover out and use –IncludeAutoDiscover and –IncludeAcceptedDomains switches (but check)ISA 2006 SP1 kanoverweg met SAN cert, vandaar pre-ISA 2006 SP1: 1e SAN = CN
Pkcs#12=.p12, pkcs#7=.p7b/.p7c
Cert. Request Wizard : request & import, geenPowershell / generators nodig (kanwel)External Client Access ipvExternalURLsdefinierenvoorelke Web Service (ActiveSync, OWA, UM, ..) voorelke CAS
Outlook, CTRL-click SysTray Icon
MSDNAutodiscover HTTP Service Protocol Specification http://msdn.microsoft.com/en-us/library/cc433481(EXCHG.80).aspxAutodiscover Publishing and Lookup Protocol Specificationhttp://msdn.microsoft.com/en-us/library/cc463896(EXCHG.80).aspx