Home All Groups Group Topic Archive Search About

Exchange 2003 with OWA and Verisign Digital ID's

Author
24 Sep 2008 9:02 PM
Lance
I am having problems trying to send an email that is digitally signed with a
Verisign digital id. I have this working fine through Outlook but want the
option to do it through OWA too. I get the following error message "You are
attempting to sign the message with an invalid digital ID. The certificate
chain that contains the digital ID was not created properly. Try sending
without a digital signature." If I send with out it works fine. I tried
following the instructions in http://support.microsoft.com/kb/927463 but am
having a hell of a time find the id I need to use. I talked with Verisign and
they told me this

"Ok, so what you can do on the Exchange end is actually install your Digital
ID Certificate on the server. The certificate we send already has the
complete chain. However if you only have the certificate installed on your
browser and your machine locally, the Exchange server cannot read the
certificate. Therefore to properly encrypt an email using OWA, your Digital
Certificate must be installed on the server."

But according to the KB Article I shouldn't need to do that. I couldn't
imagine having to do that in an enterprise with a couple of hundred let alone
thousand users. Any assistance would greatly be appreciated.

Thanks
Lance

Author
24 Sep 2008 10:51 PM
Ed Crowley [MVP]
The KB article you're referring to covers the requirement to install the
trusted root certificate, i.e., Verisign's certificate on the Exchange
server used for OWA.  You are correct that you do not install the sender's
individual certificate on the Exchange server.
--
Ed Crowley MVP
"There are seldom good technological solutions to behavioral problems."
..

Show quoteHide quote
"Lance" <La***@discussions.microsoft.com> wrote in message
news:B8B7BB16-4CFF-411A-9E9F-AE8B9AEE8FBC@microsoft.com...
>I am having problems trying to send an email that is digitally signed with
>a
> Verisign digital id. I have this working fine through Outlook but want the
> option to do it through OWA too. I get the following error message "You
> are
> attempting to sign the message with an invalid digital ID. The certificate
> chain that contains the digital ID was not created properly. Try sending
> without a digital signature." If I send with out it works fine. I tried
> following the instructions in http://support.microsoft.com/kb/927463 but
> am
> having a hell of a time find the id I need to use. I talked with Verisign
> and
> they told me this
>
> "Ok, so what you can do on the Exchange end is actually install your
> Digital
> ID Certificate on the server. The certificate we send already has the
> complete chain. However if you only have the certificate installed on your
> browser and your machine locally, the Exchange server cannot read the
> certificate. Therefore to properly encrypt an email using OWA, your
> Digital
> Certificate must be installed on the server."
>
> But according to the KB Article I shouldn't need to do that. I couldn't
> imagine having to do that in an enterprise with a couple of hundred let
> alone
> thousand users. Any assistance would greatly be appreciated.
>
> Thanks
> Lance
Are all your drivers up to date? click for free checkup

Author
1 Oct 2008 9:37 PM
Lance
When I figure out Verisigns certificate that I need to install on the server
I should be able to send an email message with my digital id correct?

Show quoteHide quote
"Ed Crowley [MVP]" wrote:

> The KB article you're referring to covers the requirement to install the
> trusted root certificate, i.e., Verisign's certificate on the Exchange
> server used for OWA.  You are correct that you do not install the sender's
> individual certificate on the Exchange server.
> --
> Ed Crowley MVP
> "There are seldom good technological solutions to behavioral problems."
> ..
>
> "Lance" <La***@discussions.microsoft.com> wrote in message
> news:B8B7BB16-4CFF-411A-9E9F-AE8B9AEE8FBC@microsoft.com...
> >I am having problems trying to send an email that is digitally signed with
> >a
> > Verisign digital id. I have this working fine through Outlook but want the
> > option to do it through OWA too. I get the following error message "You
> > are
> > attempting to sign the message with an invalid digital ID. The certificate
> > chain that contains the digital ID was not created properly. Try sending
> > without a digital signature." If I send with out it works fine. I tried
> > following the instructions in http://support.microsoft.com/kb/927463 but
> > am
> > having a hell of a time find the id I need to use. I talked with Verisign
> > and
> > they told me this
> >
> > "Ok, so what you can do on the Exchange end is actually install your
> > Digital
> > ID Certificate on the server. The certificate we send already has the
> > complete chain. However if you only have the certificate installed on your
> > browser and your machine locally, the Exchange server cannot read the
> > certificate. Therefore to properly encrypt an email using OWA, your
> > Digital
> > Certificate must be installed on the server."
> >
> > But according to the KB Article I shouldn't need to do that. I couldn't
> > imagine having to do that in an enterprise with a couple of hundred let
> > alone
> > thousand users. Any assistance would greatly be appreciated.
> >
> > Thanks
> > Lance
>
>
>
Author
2 Oct 2008 12:58 AM
Ed Crowley [MVP]
I don't know if that's all you need.
--
Ed Crowley MVP
"There are seldom good technological solutions to behavioral problems."
..

Show quoteHide quote
"Lance" <La***@discussions.microsoft.com> wrote in message
news:4F4254CF-5551-4E42-8C22-00F198F056B5@microsoft.com...
> When I figure out Verisigns certificate that I need to install on the
> server
> I should be able to send an email message with my digital id correct?
>
> "Ed Crowley [MVP]" wrote:
>
>> The KB article you're referring to covers the requirement to install the
>> trusted root certificate, i.e., Verisign's certificate on the Exchange
>> server used for OWA.  You are correct that you do not install the
>> sender's
>> individual certificate on the Exchange server.
>> --
>> Ed Crowley MVP
>> "There are seldom good technological solutions to behavioral problems."
>> ..
>>
>> "Lance" <La***@discussions.microsoft.com> wrote in message
>> news:B8B7BB16-4CFF-411A-9E9F-AE8B9AEE8FBC@microsoft.com...
>> >I am having problems trying to send an email that is digitally signed
>> >with
>> >a
>> > Verisign digital id. I have this working fine through Outlook but want
>> > the
>> > option to do it through OWA too. I get the following error message "You
>> > are
>> > attempting to sign the message with an invalid digital ID. The
>> > certificate
>> > chain that contains the digital ID was not created properly. Try
>> > sending
>> > without a digital signature." If I send with out it works fine. I tried
>> > following the instructions in http://support.microsoft.com/kb/927463
>> > but
>> > am
>> > having a hell of a time find the id I need to use. I talked with
>> > Verisign
>> > and
>> > they told me this
>> >
>> > "Ok, so what you can do on the Exchange end is actually install your
>> > Digital
>> > ID Certificate on the server. The certificate we send already has the
>> > complete chain. However if you only have the certificate installed on
>> > your
>> > browser and your machine locally, the Exchange server cannot read the
>> > certificate. Therefore to properly encrypt an email using OWA, your
>> > Digital
>> > Certificate must be installed on the server."
>> >
>> > But according to the KB Article I shouldn't need to do that. I couldn't
>> > imagine having to do that in an enterprise with a couple of hundred let
>> > alone
>> > thousand users. Any assistance would greatly be appreciated.
>> >
>> > Thanks
>> > Lance
>>
>>
>>
Author
7 Oct 2008 8:21 PM
Lance
Is there a good how to on how people secure their email communications with
digital ids that use OWA?

Show quoteHide quote
"Ed Crowley [MVP]" wrote:

> I don't know if that's all you need.
> --
> Ed Crowley MVP
> "There are seldom good technological solutions to behavioral problems."
> ..
>
> "Lance" <La***@discussions.microsoft.com> wrote in message
> news:4F4254CF-5551-4E42-8C22-00F198F056B5@microsoft.com...
> > When I figure out Verisigns certificate that I need to install on the
> > server
> > I should be able to send an email message with my digital id correct?
> >
> > "Ed Crowley [MVP]" wrote:
> >
> >> The KB article you're referring to covers the requirement to install the
> >> trusted root certificate, i.e., Verisign's certificate on the Exchange
> >> server used for OWA.  You are correct that you do not install the
> >> sender's
> >> individual certificate on the Exchange server.
> >> --
> >> Ed Crowley MVP
> >> "There are seldom good technological solutions to behavioral problems."
> >> ..
> >>
> >> "Lance" <La***@discussions.microsoft.com> wrote in message
> >> news:B8B7BB16-4CFF-411A-9E9F-AE8B9AEE8FBC@microsoft.com...
> >> >I am having problems trying to send an email that is digitally signed
> >> >with
> >> >a
> >> > Verisign digital id. I have this working fine through Outlook but want
> >> > the
> >> > option to do it through OWA too. I get the following error message "You
> >> > are
> >> > attempting to sign the message with an invalid digital ID. The
> >> > certificate
> >> > chain that contains the digital ID was not created properly. Try
> >> > sending
> >> > without a digital signature." If I send with out it works fine. I tried
> >> > following the instructions in http://support.microsoft.com/kb/927463
> >> > but
> >> > am
> >> > having a hell of a time find the id I need to use. I talked with
> >> > Verisign
> >> > and
> >> > they told me this
> >> >
> >> > "Ok, so what you can do on the Exchange end is actually install your
> >> > Digital
> >> > ID Certificate on the server. The certificate we send already has the
> >> > complete chain. However if you only have the certificate installed on
> >> > your
> >> > browser and your machine locally, the Exchange server cannot read the
> >> > certificate. Therefore to properly encrypt an email using OWA, your
> >> > Digital
> >> > Certificate must be installed on the server."
> >> >
> >> > But according to the KB Article I shouldn't need to do that. I couldn't
> >> > imagine having to do that in an enterprise with a couple of hundred let
> >> > alone
> >> > thousand users. Any assistance would greatly be appreciated.
> >> >
> >> > Thanks
> >> > Lance
> >>
> >>
> >>
>
>
>
Author
7 Oct 2008 10:07 PM
Ed Crowley [MVP]
What do you mean by secure?  If you require HTTPS, then all transmissions
between IE and Exchange are encrypted.  Beyond that, there are probably all
sorts of things you can do, none of which are native to Exchange.
--
Ed Crowley MVP
"There are seldom good technological solutions to behavioral problems."
..

Show quoteHide quote
"Lance" <La***@discussions.microsoft.com> wrote in message
news:EA27D578-1CD3-4277-9DED-7DA24255540C@microsoft.com...
> Is there a good how to on how people secure their email communications
> with
> digital ids that use OWA?
>
> "Ed Crowley [MVP]" wrote:
>
>> I don't know if that's all you need.
>> --
>> Ed Crowley MVP
>> "There are seldom good technological solutions to behavioral problems."
>> ..
>>
>> "Lance" <La***@discussions.microsoft.com> wrote in message
>> news:4F4254CF-5551-4E42-8C22-00F198F056B5@microsoft.com...
>> > When I figure out Verisigns certificate that I need to install on the
>> > server
>> > I should be able to send an email message with my digital id correct?
>> >
>> > "Ed Crowley [MVP]" wrote:
>> >
>> >> The KB article you're referring to covers the requirement to install
>> >> the
>> >> trusted root certificate, i.e., Verisign's certificate on the Exchange
>> >> server used for OWA.  You are correct that you do not install the
>> >> sender's
>> >> individual certificate on the Exchange server.
>> >> --
>> >> Ed Crowley MVP
>> >> "There are seldom good technological solutions to behavioral
>> >> problems."
>> >> ..
>> >>
>> >> "Lance" <La***@discussions.microsoft.com> wrote in message
>> >> news:B8B7BB16-4CFF-411A-9E9F-AE8B9AEE8FBC@microsoft.com...
>> >> >I am having problems trying to send an email that is digitally signed
>> >> >with
>> >> >a
>> >> > Verisign digital id. I have this working fine through Outlook but
>> >> > want
>> >> > the
>> >> > option to do it through OWA too. I get the following error message
>> >> > "You
>> >> > are
>> >> > attempting to sign the message with an invalid digital ID. The
>> >> > certificate
>> >> > chain that contains the digital ID was not created properly. Try
>> >> > sending
>> >> > without a digital signature." If I send with out it works fine. I
>> >> > tried
>> >> > following the instructions in http://support.microsoft.com/kb/927463
>> >> > but
>> >> > am
>> >> > having a hell of a time find the id I need to use. I talked with
>> >> > Verisign
>> >> > and
>> >> > they told me this
>> >> >
>> >> > "Ok, so what you can do on the Exchange end is actually install your
>> >> > Digital
>> >> > ID Certificate on the server. The certificate we send already has
>> >> > the
>> >> > complete chain. However if you only have the certificate installed
>> >> > on
>> >> > your
>> >> > browser and your machine locally, the Exchange server cannot read
>> >> > the
>> >> > certificate. Therefore to properly encrypt an email using OWA, your
>> >> > Digital
>> >> > Certificate must be installed on the server."
>> >> >
>> >> > But according to the KB Article I shouldn't need to do that. I
>> >> > couldn't
>> >> > imagine having to do that in an enterprise with a couple of hundred
>> >> > let
>> >> > alone
>> >> > thousand users. Any assistance would greatly be appreciated.
>> >> >
>> >> > Thanks
>> >> > Lance
>> >>
>> >>
>> >>
>>
>>
>>

Bookmark and Share

Post Thread options