¸ÅÀÀ: | |
| |
ÒÆ¶¯Ô±¹¤ÊÇ IT ×éÖ¯ÃæÁÙµÄ×îΪ¶ÀÌØµÄ°²È«ÌôÕ½¡£Ô¶³ÌÓû§ÐèÒª¶ÔÊý¾ÝºÍ·þÎñ£¨Èçµç×ÓÓʼþ£©½øÐа²È«·ÃÎÊ¡£È»¶øÒź¶µÄÊÇ£¬ÏÖʵÖÐ
°²È«Á´×îΪ±¡ÈõµÄ»·½ÚÍùÍùÓë´àÈõµÄÃÜÂë¡¢¶ñÒâÈí¼þ£¨Èç»÷¼ü¼Ç¼Æ÷£©£¬ÒÔ¼°·ÃÎÊÄúËùÔÚ×éÖ¯ÄÚ²¿×ÊÔ´µÄÔ¶³Ì¼ÆËã»úÉϵIJ¡¶¾Óйء£
Ìá¸ßÕâÖÖÒÆ¶¯»·¾³°²È«ÐÔµÄÆäÖÐÒ»ÖÖ·½·¨ÊÇÈ¥µôÕâÆäÖеÄijһ¸ö±¡Èõ»·½Ú£ºÃÜÂ루ËäÈ»ÔÊÐíÔÚ·ÃÎÊij¸öÕÊ»§Ê±²»Ê¹ÓÃÃÜÂë½øÐÐÉí·ÝÑéÖ¤¿ÉÄÜ»á´øÀ´Âé·³£©¡£ÓÃÓÚ½â¾öÃÜÂëÏà¹ØÎÊÌâµÄÖ÷Òª¼¼Êõ±ãÊÇË«ÖØÉí·ÝÑéÖ¤£¨»òÓÐʱΪ¶àÖØÉí·ÝÑéÖ¤£©¡£Ë«ÖØÉí·ÝÑéÖ¤ÔÚÆôÓ÷ÃÎÊʱ²»ÊÇÒÀÀµÒ»ÖÖµ¥Ò»µÄ·½·¨£¨ÃÜÂ룩£¬¶ø»áʹÓöîÍâµÄÉí·ÝÑéÖ¤·½·¨£¬°üÀ¨Óû§Ãû/ÃÜÂëµÄ×éºÏ¡¢ÎïÀíÉ豸£¨ÈçÖÇÄÜ¿¨£©£¬»òÉúÎïÌØÕ÷ʶ±ðÂ루ÈçÖ¸ÎÆ£©¡£
Èç¹ûÄúÓÐÔ¶³ÌÓû§£¬Í¨³£»áÉÔÉÔ¿ªÆôÄúµÄ·À»ðǽÒÔ±ãÔÊÐíÔ¶³ÌÓû§·ÃÎʹ«Ë¾ÍøÂç¡£±ê×¼µÄ·À»ðǽͨ¹ýÌṩÄÚ²¿ÍøÂçºÍÍâ²¿ÍøÂç¼äÍøÂç¼¶µÄ¸ôÀëÀ´Ìṩ»ù±¾µÄ·çÏÕ»º½â£¨²Î¼ûͼ 1£©¡£ÎªÔöÇ¿°²È«ÐÔ£¬Ö»Äܹرն˿ڣ¬ÈçÈôÐèÒªÓëÄÚ²¿ÍøÂçÖеÄÉ豸½øÐÐͨÐÅ£¬¾Í½«¶Ë¿ÚÓ³Éäµ½ÕýÈ·µÄλÖá£ÕâЩ¼¼ÊõȷʵÌṩÁË×ã¹»µÄÍøÂç¼¶±£»¤£¬µ«ÓÉÓÚ¹¥»÷¼¼Êõ²»¶Ï·¢Õ¹³ÉÊ죬¶à²ãÍøÂ簲ȫÐԾͱäµÃ·Ç³£±ØÒªÁË¡£
¼ÈÈ»ÒÆ¶¯Ô±¹¤×ʹÓõĹ«Ë¾·þÎñÊǵç×ÓÓʼþºÍÏûÏ¢´«ËÍ£¬Òò´Ë½«ÄúµÄ Exchange »ù´¡½á¹¹½øÐа²È«ÅäÖþͱäµÃ±ÈÈκÎʱºò¶¼ÖØÒªÁË¡£ÈÃÄúµÄÓû§Í¨¹ý Outlook® Web Access (OWA) ·ÃÎʵç×ÓÓʼþÊÇÎªÒÆ¶¯Ô±¹¤Ìṩ°²È«·þÎñµÄÒ»ÖÖ·½·¨¡£Í¨¹ýÖÇÄÜ¿¨Îª OWA Ìṩ¸üΪ°²È«µÄË«ÖØÉí·ÝÑéÖ¤ÊÇÁíÒ»¸ö¹Ø¼ü²½Öè¡£ÔÚ±¾ÎÄÖУ¬ÎÒÃǽ«½øÒ»²½ËµÃ÷ÄúÔÚÆôÓÃ×Ô¼ºµÄʹÓÃÖÇÄÜ¿¨µÄ OWA ²¿ÊðÖÐÓ¦µ±×¢ÒâµÄÎÊÌâ¡£
ÔÚÄúµÄÍøÂçÖÐʹÓà Microsoft® Internet Security and Acceleration (ISA) Server 2006 ¿ÉÒÔ¼ò»¯ÏòÔ¶³ÌÓû§¿ª·ÅÍøÂçÕâÒ»ÈÎÎñ£¬¶øÇÒ¸üΪ°²È«¡£ISA Server 2006 °üº¬Ò»Ð©°²È«ÔöÇ¿¹¦ÄÜ£¬ÈçÆôÓÃÖÇÄÜ¿¨µÄÐéÄâרÓÃÍøÂç (VPN)¡¢µ½ Active Directory® µÄÇáÐÍĿ¼·ÃÎÊÐÒé (LDAP) Éí·ÝÑéÖ¤£¬ÒÔ¼° Kerberos Ô¼ÊøÎ¯ÅÉ¡£ISA Server ÓëÄúÏëÏóµÄ´«Í³·À»ðǽÉÔÓв»Í¬¡£Ëü²»½öͨ¹ýÔÚÍøÂç²ãÌṩ¶à²ã°²È«ÐÔ¡ª¡ªÕâ¿ÉÒÔ´úÌæ»òÓë±ê×¼µÄ·À»ðǽӲ¼þ½áºÏʹÓ᪡ª¶øÇÒ»¹Ìṩ´«Í³·À»ðǽͨ³£²»Ö§³ÖµÄһЩÆäËû°²È«¹¦ÄÜ£¬ÈçÓ¦ÓóÌÐòɸѡÆ÷¡£²»ÏëÈÃij¸öÈËÔÚÌØ¶¨ÍйÜÍøÕ¾ÉÏʹÓà HTTP POST ·½·¨£¿ÏëÒªÔÚ SMTP ÏûÏ¢½Ó´¥ÄúµÄ Exchange ·þÎñÆ÷֮ǰÔÚÆäÉÏÇ¿ÖÆÊµÐÐ RFC ×ñ´ÓÐÔ£¿ÏëÒªÔÚ¼ÓÃܵݲȫÌ×½Ó×Ö²ã (SSL) HTTP Êý¾Ý°ü½øÈëÍøÂçǰ¶ÔÆä½øÐмì²é£¿ISA Server ¿ÉÒÔ¹ÜÀíËùÓÐÕâЩÒÔ¼°¸ü¶àµÄÈÎÎñ£¬´Ó¶øÈ·±£Ö»Óиɾ»µÄ¡¢¾É¸Ñ¡µÄͨÐÅ¿ÉÒÔ±»×ª·¢µ½ÄúµÄ DMZ »òÄÚ²¿ÍøÂçÖС£
¶ÔÓÚ±ê×¼·À»ðǽÀ´Ëµ£¬SSL »á»°ÊÇÒ»¸ö´óÎÊÌâ¡£µ±Êý¾Ý°üͨ¹ý·À»ðǽʱ£¬ËüÃǻᱣ³Ö¼ÓÃÜ״̬£¨ÕâÒâζ×Å SSL Õý³£¹¤×÷£©¡£Òò´Ë£¬Èç¹ûÒ»¸öÓ¦ÓóÌÐò£¨Èç OWA£©Í¨¹ýʹÓà SSL µÄÓ²¼þ»òÈí¼þ·À»ðǽ½øÐз¢²¼£¬ÄÇô³ýÁË״̬Êý¾Ý°ü¼ì²éÍ⣬±ê×¼·À»ðǽ±ã²»ÄÜÖ´ÐÐÆäËûÕæÕýÓÐЧµÄ¼ì²éÁË¡£ÕâÖÖ½ö½öÊÇ´ò¿ªºÍÓ³Éä¶Ë¿Ú»á¼«´óµØÔö¼ÓÊܹ¥»÷µÄ»ú»á¡£ÓÉÓÚÔÚ±ßÔµ´¦Ã»ÓнøÐÐÕæÕýµÄ¼ì²é£¬Î´¾¼ì²éºÍÉí·ÝÑéÖ¤µÄÊý¾Ý°ü±ã¿É´«Ë͵½ÄúµÄÄÚ²¿ÍøÂçÖС£
ISA Server 2006 ¿ÉÒÔ×÷Ϊ HTTP ¿Í»§¶ËµÄ SSL ÖÕ½áµã£¬È·±£Ö»Óо¹ýÉí·ÝÑéÖ¤µÄͨÐÅ¿ÉÒÔµ½´ïÒÑ·¢²¼µÄ Exchange ·þÎñÆ÷¡£ISA Server Ö§³ÖÒ»¸öÃûΪ SSL ÇŽӵÄÓÐÓù¦ÄÜ¡£Í¨³£Êý¾Ý°üÊÇÓÉͨ¹ýÒ»¸ö±ê×¼µÄ SSL »á»°Óë ISA Server ½øÐÐͨÐŵĿͻ§¶Ë½øÐмÓÃܵġ£ÓÐÁË SSL ÇŽӹ¦ÄÜ£¬ISA Server ¾Í¿ÉÒÔ±¾µØÖÕÖ¹ SSL ¼ÓÃÜ£¬¼ì²éµ±Ç°Î´¼ÓÃܵÄÊý¾Ý°ü£¬¶Ô Active Directory µÄÓû§½øÐÐÉí·ÝÑéÖ¤£¨Èç¹ûÐèÒª£©£¬Ê¹Óà SSL ¶ÔÊý¾Ý°üÖØÐ½øÐмÓÃÜ£¬È»ºó½«¼ÓÃܺóµÄÊý¾Ý°ü´«Ë͵½ÏàÓ¦µÄ Exchange ·þÎñÆ÷ÉÏ£¨²Î¼ûͼ 2£©¡£Ê¹ÓÃÕâÖÖ¼¼Êõ£¬SSL ÇŽӿÉÒÔ»º½â SSL »á»°ÖÐÒþ²ØµÄ¹¥»÷£¬¶øÕâЩ¹¥»÷¶ÔÓÚÄÇЩӦÓóÌÐò²»Ãô¸ÐµÄ·À»ðǽÀ´ËµÖ»²»¹ýÊÇһЩ¼ÓÃܵÄÊý¾Ý Blob¡£
Ìáµ½ Kerberos Ô¼ÊøÎ¯ÅÉ£¬µ½´ï·þÎñÆ÷µÄ¾¹ýÔ¤ÏÈÉí·ÝÑéÖ¤µÄͨÐÅÊÇÊ®·ÖÖµµÃ×¢ÒâµÄÒ»µã¡£ÔÚ±ê×¼µÄ·À»ðǽÖУ¬¶Ë¿ÚÖ»ÊǼòµ¥µØÓ³Éäµ½ Exchange ·þÎñÆ÷£¬²¢ÇÒÓÉǰ¶Ë·þÎñÆ÷×ÔÉíÀ´Ö´ÐÐÉí·ÝÑéÖ¤ÈÎÎñÒÔ·ÀÖ¹¶ñÒâÓû§¡£µ±ÐèÒª½øÐÐÉí·ÝÑé֤ʱ£¬ISA Server ¿ÉÒÔÖ±½ÓÁªÏµ Active Directory£¬²¢´ú±íÓû§ÇëÇó»ñµÃƾ¾Ý¡£Èç¹ûÓû§³É¹¦Í¨¹ýÉí·ÝÑéÖ¤£¬ISA Server »á½«ÏûϢת·¢ÖÁ Exchange ǰ¶Ë·þÎñÆ÷¡£Ç°¶Ë·þÎñÆ÷Ôò²»ÔÙÐèÒª¶ÔËæ»úµÄδ֪Óû§ÇëÇó½øÐÐÉí·ÝÑéÖ¤£¬²¢¿Éµ¥¶ÀÓÃÓÚ´úÀíµ½ºó¶Ë·þÎñÆ÷µÄÇëÇó¡£ISA Server 2006 »¹¿ÉÒÔʹÓà Kerberos Ô¼ÊøÎ¯ÅÉÀ´ÆôÓõ½ Windows SharePoint Services ºÍ Exchange ActiveSync µÈ¼¼ÊõµÄ»ùÓÚÖ¤ÊéµÄ·ÃÎÊ¡£
Exchange Server 2003 °üº¬¶Ô OWA µÇ¼µÄǰºó¶Ë·þÎñÆ÷Ö®¼ä»ùÓÚ Kerberos µÄÉí·ÝÑéÖ¤Ö§³Ö¡££¨ÄúÊÇ·ñʹÓà IPsec À´±£»¤¸Ã¿Í»§¶ËͨÐÅ£¿£©Exchange Server »¹Ö§³Öµ½Èº¼¯ÓÊÏä·þÎñÆ÷µÄ Kerberos Éí·ÝÑéÖ¤¡£
Ϊ OWA ʵʩ»ùÓÚÖÇÄÜ¿¨µÄÉí·ÝÑéÖ¤Ò»Ö±ÒÔÀ´¶¼ÊÇÒ»ÏîÌôÕ½¡£²»¹ýÏÖÔÚ ISA Server 2006 ÖÐÒÑÓÐÁËÒ»¸ö¸ù¾Ý Kerberos Ô¼ÊøÎ¯Åɹ¦ÄÜ¿ª·¢µÄ½â¾ö·½°¸¡£¸Ã½â¾ö·½°¸ÔÊÐíÓû§Í¨¹ýÖ¤ÊéÀ´Ìύƾ¾Ý£¬ÒÔ±ã³É¹¦Í¨¹ý OWA µÄÉí·ÝÑéÖ¤¡£Kerberos Ô¼ÊøÎ¯ÅÉÉîÊܹã´óÓû§µÄ»¶Ó£¬ËüÊǶÔʹÓÃÎÞÔ¼ÊøÎ¯ÅÉ¡¢ÊÜ Windows® 2000 Ö§³ÖµÄ Kerberos ίÅɵÄÒ»´Î¸Ä½ø¡£Kerberos µÄÔ¼Êø¹¦ÄÜ¿ÉÒÔÌá¸ß°²È«ÐÔ£¬²¢ÇÒÏÞÖÆÁËʹÓüÙðÉí·ÝÕâÖÖ¸üΪ¸´ÔӵĹ¥»÷µÄDZÔÚ·çÏÕ¡£
ÔÚÆôÓÃÖÇÄÜ¿¨µÄÇé¿öÏ£¬ÓÉÓÚÓû§ÎÞ·¨´ÓÍâ²¿ÍøÂç¶ÔÃÜÔ¿·¢ÐÐÖÐÐÄ (KDC) ½øÐпÉ·ÓɵķÃÎÊ£¬Òò´Ë ISA Server 2006 »áÁªÏµ Active Directory À´¶ÔÓû§½øÐÐÉí·ÝÑéÖ¤¡£ISA Server »á¸ù¾Ý Active Directory Ö¤Êé-Óû§Ó³ÉäÀ´¶ÔÓû§½øÐÐÉí·ÝÑéÖ¤£¬È»ºó¸ù¾ÝÓû§Ö÷ÌåÃû³Æ (UPN) À´·Ö±ð»ñÈ¡ÏàÓ¦µÄ Kerberos Ʊ֤¡£ÔÚÕâÖÖÇé¿öÏ£¬ISA Server »áͨ¹ýÓ¦ÓóÌÐò¼¶±ðµÄɸѡºÍ·´Ïò´úÀí·þÎñÏò Exchange ǰ¶Ë·þÎñÆ÷Ìṩ Kerberos Ô¼ÊøÎ¯Åɹ¦ÄÜ¡£Èç¹û³¢ÊÔ²»Ê¹Ó÷´Ïò´úÀí½øÐÐίÅÉ£¬Ôò»áÔö¼Ó©¶´¹¥»÷µÄ·çÏÕ£¬´Ó¶øÓ°ÏìÍøÂç»ò Active Directory ÓòµÄÍêÕûÐÔ¡£
Exchange Server 2003 ºÍ Exchange Server 2007 ¾ùÔÊÐí»ù±¾Éí·ÝÑéÖ¤ºÍ¼¯³ÉÉí·ÝÑéÖ¤¡£µ«ÊÇÄúÐèÒª¶Ô Exchange Server 2003 ½øÐÐÈí¼þ¸üУ¬ÒÔ±ãÆôÓà OWA µÄ»ùÓÚÖÇÄÜ¿¨µÄÉí·ÝÑéÖ¤¡££¨ÓйØÏêϸÐÅÏ¢£¬Çë²ÎÔÄÎÄÕ¡°¶Ô Exchange Server 2003 ÖÐÖ§³Ö Outlook Web Access ÖÇÄÜ¿¨Éí·ÝÑéÖ¤µÄй¦ÄܵÄ˵Ã÷¡±¡££©Äú±ØÐëÓµÓÐÒ»¸ö´¦ÓÚ Windows Server® 2003 ±¾»ú¹¦ÄÜģʽµÄÓò£¬Éæ¼°µÄËùÓÐ Exchange Server 2003 ·þÎñÆ÷±ØÐëÓ¦Óà SP2 »ò¸üеİ汾£¬²¢ÇÒ±ØÐëÓÐÒ»¸ö ISA Server 2006 ·þÎñÆ÷×÷Ϊ OWA Õ¾µãµÄ·´Ïò´úÀí¡£
°²×°Èí¼þ¸üв¢¶Ô ISA ºÍ Exchange ·þÎñÆ÷½øÐÐÅäÖú󣬱ã¿ÉÒÔʹÓÃÖÇÄÜ¿¨¶Ô OWA »á»°½øÐÐÉí·ÝÑéÖ¤ÁË¡£Í¼ 3 ÏÔʾÁËÖÇÄÜ¿¨ÑéÖ¤¹ý³ÌÖÐÐèÒª½øÐеÄһϵÁÐʼþ¡£Óû§ÏÈÔÚ Internet Explorer® Öдò¿ª OWA Õ¾µã (1)¡£ÊÂʵÉÏ£¬ÔÚÆô¶¯ OWA »á»°Ê±£¬Óû§»áʵ¼ÊÁ¬½Óµ½ ISA Server£¬²¢ÇÒ·þÎñÆ÷»áÌáʾÄúÊäÈëÖ¤Êé¶ø²»ÊÇÓû§ÃûºÍÃÜÂë¡£ÕýÈ·µÄÖ¤Êé´æ´¢ÔÚÖÇÄÜ¿¨ÖУ¬Óû§ÐèÒªÓÐÒ»¸ö PIN ²ÅÄÜ»ñȡ֤Êé¡£
Ö¤ÊéÑéÖ¤ (2) ÓÉÖ¤ÊéµõÏúÁбí (CRL) »òÔÚÏßÖ¤Êé״̬ÐÒé (OCSP) ÇëÇóÀ´´¦Àí£¬Õâ¸ù¾Ý ISA Server µÄÅäÖúͰ²×°µÄÆäËûÈí¼þ¶ø¶¨¡£ISA Server »áÏòÓò¿ØÖÆÆ÷ (DC) ·¢ËÍÒ»¸öÑéÖ¤Óû§Æ¾¾ÝµÄÇëÇó¡£Èç¹ûÇëÇóʧ°Ü£¬ISA Server »áÏòÓû§Ìṩһ¸ö´íÎóÒ³Ãæ£¬²¢ÇÒûÓÐÇëÇó»áµ½´ï Exchange ǰ¶Ë·þÎñÆ÷¡£
ƾ¾Ý¾ÑéÖ¤ºó£¬»áÉú³É Kerberos Ʊ֤²¢»á½«ÇëÇó´«ËÍÖÁʹÓü¯³ÉÉí·ÝÑéÖ¤µÄ Exchange ǰ¶Ë·þÎñÆ÷ (3)¡£Exchange ǰ¶Ë·þÎñÆ÷ÊÕµ½ÇëÇóºó£¬»á¶Ô Kerberos Ʊ֤½øÐÐÑéÖ¤²¢»áÕÒµ½Óû§µÄºó¶ËÓÊÏä·þÎñÆ÷ (4)¡£
ǰ¶Ë·þÎñÆ÷»áͨ¹ý Kerberos Ô¼ÊøÎ¯ÅÉΪÏàÓ¦µÄºó¶Ë·þÎñÆ÷ÇëÇóÒ»¸ö Kerberos Ʊ֤£¬²¢»á½«ÓÊÏäÇëÇó´úÀíµ½Ê¹Óü¯³ÉÉí·ÝÑéÖ¤µÄºó¶Ë·þÎñÆ÷ (5)¡£ºó¶Ë·þÎñÆ÷»á´¦ÀíÇëÇó (6)£¬²¢»á½«ÓÊÏäÊý¾Ý·µ»Ø¸ø Exchange ǰ¶Ë·þÎñÆ÷ (7)¡£OWA Ò³µÄ HTML Êý¾Ý½«±»´«ËÍÖÁ ISA Server (8)£¬È»ºóÊý¾Ý»á·µ»ØÖÁ¿Í»§¶Ë»úÆ÷ (9)¡£
ÏÈǰÌáµ½µÄ֪ʶ¿âÎÄÕÂ¶Ô Exchange Server 2003 Èí¼þ¸üнøÐÐÁË˵Ã÷£¬²¢°üº¬Ö¸µ¼ÄúÍê³ÉʹÓà ISA Server 2006 ºÍ Exchange Server 2003 ÆôÓà Kerberos Ô¼ÊøÎ¯ÅÉÕâ¸ö¹ý³ÌµÄÐÅÏ¢¡£
Èí¼þ¸üкóÆôÓõÄÖ÷Òª²Ù×÷ÊÇʹ´Ó Exchange ǰ¶Ë·þÎñÆ÷µ½¸÷×Եĺó¶Ë·þÎñÆ÷µÄ Kerberos Ô¼ÊøÎ¯Åɹý³Ì×Ô¶¯»¯¡£ÓÉÓÚ ISA Server ²»ÊÇ Exchange ×éÖ¯µÄÒ»²¿·Ö£¬Òò´Ë¸ÃÏî¸üв»»á½«´Ó ISA Server µ½Ç°¶Ë·þÎñÆ÷µÄ Kerberos Ô¼ÊøÎ¯Åɹý³Ì×Ô¶¯»¯¡£ÕâÖÖ ISA Server ʵÀýµ½ Exchange ǰ¶Ë·þÎñÆ÷Ö®¼äµÄίÅÉÐèÒ»Ò»ÊÖ¶¯ÆôÓá£
Èí¼þ¸üлáÔÚ Exchange ϵͳ¹ÜÀíÆ÷ (ESM) ÖÐÌí¼ÓÒ»¸öеÄÑ¡Ï£¬¸ÃÑ¡Ï¿ÉÈÃÄú½«Ä³¸ö Exchange ǰ¶Ë·þÎñÆ÷Ö¸¶¨Îª KCD-FE£¨²Î¼ûͼ 4£©£¬ÕâÑù±ã¿ÉÒÔÈø÷þÎñÆ÷ÔÚÿ¸ö Exchange ºó¶Ë·þÎñÆ÷µÄίÅÉÑ¡ÏÉϽøÐÐÌî³ä¡£

Õâ¸öÐ嵀 UI »¹¿ÉÈÃÄúÔÚ¹ÜÀí×éÊôÐÔÖÐÖ¸¶¨ÓÃÄĸöƾ¾ÝÀ´Ìî³ä msDS-AllowedToDelegateTo (A2D2) ÊôÐÔ£¬Èçͼ 5 Ëùʾ¡£¸ÃÊôÐÔÓÃÓÚ½øÐÐ Kerberos Ô¼ÊøÎ¯ÅÉ¡£

¸ù¾Ý×îµÍȨÏÞÔÔò£¬Äú¿ÉÒÔʹÓÃÒ»¸ö±ê×¼µÄÓû§ÕÊ»§£¬²¢ÊÚÓèËüͨ¹ý×é²ßÂÔ¶ÔÏó (GPO) À´Î¯ÅÉÓû§ºÍ¼ÆËã»úµÄÄÜÁ¦¡£ÎªÕÊ»§ÊÚÓèÕâ¸öÌáÉýµÄȨÏ޺󣬸ÃÕÊ»§±ã¿É×÷Ϊһ¸ö·þÎñÕÊ»§£¬Ê¹Ã¿¸ö¹ÜÀí×éµÄ Kerberos Ô¼ÊøÎ¯Åɹý³Ì×Ô¶¯»¯¡£
ÇëÎñ±Ø²ÉÓÃÕýÈ·µÄ²½Ö裬ÒÔÈ·±£¶ñÒâÓû§ÎÞ·¨ÆÆ»µ Kerberos Ô¼ÊøÎ¯ÅÉ·þÎñÕÊ»§¡£¼´Ê¹ÕÊ»§²»ÊÇÒ»¸öÓò¹ÜÀíÔ±£¬ÀûÓà Kerberos ίÅÉ¶ÔÆä½øÐзÃÎÊÒ²¿Éµ¼ÖÂÊܵ½¸´ÔӵĹ¥»÷¡£ÓÉÓÚÕÊ»§¾ßÓн¨Á¢Ð嵀 Kerberos ¹ØÁªµÄ¹¦ÄÜ£¬Òò´ËʹÓÃʱӦ·Ç³£Ð¡ÐÄ¡£ÎªÈ·±£ÕÊ»§µÄ°²È«ÐÔºÍÍêÕûÐÔ£¬Ó¦²ÉÈ¡±ØÒªµÄ´ëÊ©£¬È糤¶ø¸´ÔÓµÄÃÜÂë¡¢ÔöÇ¿ÉóºË¡¢ÕÊ»§Í£Óü¼ÊõµÈ¡£
Exchange Èí¼þ¸üл¹Ê¹ ESM ½Ó¿ÚÓйؼ¯³ÉÉí·ÝÑéÖ¤·½Ãæ·¢ÉúÁËÖØ´ó±ä»¯¡£ÏÈǰÔÚ Exchange Server 2003 ÖУ¬µ±Ä³¸ö·þÎñÆ÷±»Ö¸¶¨ÎªÇ°¶Ë·þÎñÆ÷ºó£¬ÓÃÓÚÆôÓà HTTP ÐéÄâĿ¼£¨HTTP ÐéÄâ·þÎñÆ÷Ï£©µÄ¼¯³É Windows Éí·ÝÑéÖ¤µÄÑ¡Ïî¾Í»á±ä»Ò£¨²Î¼ûͼ 6£©¡£


·¢ÉúÕâÖÖÇé¿öµÄÔÒòÊÇ£¬ÓÉÓÚ¼¼Êõ·½ÃæµÄÎÊÌ⣨Èç´úÀí·þÎñÆ÷»áÖÐ¶Ï NTLM »á»°¡¢Ê¹Óà Kerberos Éí·ÝÑéÖ¤µÄÓû§ÐèÒªÁ¬½Óµ½ Active Directory£¬ÒÔ¼° Internet Óû§Í¨³£²»ÊôÓÚ¸ÃÓò£©£¬Exchange ǰ¶Ë·þÎñÆ÷²»Ö§³Ö¼¯³ÉÉí·ÝÑéÖ¤¡£ÉÏÃæÌáµ½µÄ֪ʶ¿âÎÄÕÂÖÐËùÃèÊöµÄ¸üÐÂÈ¡ÏûÁËÕâЩÏÞÖÆ¡£°²×°Á˸üкó£¬ÄúÖ»Ðèתµ½ÐéÄâĿ¼£¬È»ºóÑ¡ÖС°¼¯³É Windows Éí·ÝÑéÖ¤¡±¸´Ñ¡¿ò£¬½«Æä×÷ΪÑéÖ¤Óû§Æ¾¾ÝµÄ»úÖÆ¡£Ñ¡Öиø´Ñ¡¿òºó£¬Ëü»áÔÚ Active Directory ÖеÄÐéÄâĿ¼¶ÔÏóÉÏÉèÖÃÒ»¸öÃûΪ msexchAuthenticationFlags µÄÊôÐÔ£¨Ê¹Óà Microsoft ¹ÜÀí¿ØÖÆÌ¨µÄ Adsiedit.msc ²å¼þ¿ÉÒÔ¿´µ½¸ÃÊôÐÔ£©¡£
ͨ¹ý OWA À´¼ì²éÓʼþµÄÓû§¿ÉÄÜÖªµÀËûÃÇµÄ Exchange ºó¶Ë·þÎñÆ÷µÄÃû³Æ£¬²¢ÇÒµ±ËûÃÇλÓÚ¹«Ë¾ÄÚ²¿ÍøÂçʱ¿ÉÒÔʹÓü¯³ÉÉí·ÝÑéÖ¤Á¬½Óµ½ÕâЩºó¶Ë·þÎñÆ÷¡£Ê¹Óü¯³ÉÉí·ÝÑéÖ¤µÄÓû§ÌåÑéµÄ²»Í¬Ö®´¦ÔÚÓÚ£¬ÓÉÓÚÄúÒѾµÇ¼µ½ÍøÂçÖУ¬ÏµÍ³±ã²»»áÌáʾÄúÊäÈëÓû§ÃûºÍÃÜÂëÁË£¬ÒòΪ Internet Explorer »á×Ô¶¯¶ÔÄú½øÐÐÉí·ÝÑéÖ¤²¢µÇ¼µ½ÍøÕ¾ÖС£ÕâÒ»µã¶ÔÓÚλÓÚ¹«Ë¾ÍøÂçµÄÓû§À´ËµÊǷdz£°ôµÄ£¬µ«ÍⲿÓû§£¨OWA Óû§¸ü³£¼ûµÄÊÇÍⲿÓû§£©Í¨³£ÔÚ´ÓÍøÂçÍⲿ·ÃÎÊ Exchange ǰ¶Ë·þÎñÆ÷ʱ²»»áµÇ¼µ½Ä³¸öÓòÖС££¨ÖªÊ¶¿âÎÄÕ¡°IIS ÈçºÎÑéÖ¤ä¯ÀÀÆ÷¿Í»§¶Ë¡±ÖжÔÕâ¸ö¹ý³Ì½øÐÐÁËÏêϸµÄ˵Ã÷¡££©
ÔÚ Exchange Server ÖУ¬¸üлá¶Ô¡°Î¯ÅÉ¡±Ñ¡Ï½øÐÐÌî³ä£¬ÒÔ±ãʹÓà Active Directory ÖÐµÄ A2D2 ÊôÐÔ£¬¶ø²»ÊÇ·þÎñÖ÷ÌåÃû³Æ (SPN)¡£Èç¹ûÄúʹÓà Adsiedit.msc À´²é¿´ Exchange ¼ÆËã»ú¶ÔÏó£¬Äú¾Í»á×¢Òâµ½Á½¸ö½ØÈ»²»Í¬µÄÊôÐÔ£ºA2D2 ÊôÐÔ£¬ËüÊÇ Kerberos Ô¼ÊøÎ¯ÅÉÁÐ±í£»SPN ÊôÐÔ£¬ËüÊÇ Kerberos ¶¨Î»Æ÷ºÍÕÊ»§¹æ·¶µã¡£ËäȻȷʵÊÇÕâÁ½¸öÊôÐÔͬʱ´Ù³ÉÁË Kerberos Ô¼ÊøÎ¯ÅÉ£¬µ«ÄúÖ»Ðèͨ¹ýͼÐνçÃæÐÞ¸Ä A2D2 ÊôÐÔ¼´¿É¡£
Windows ¿ÉÒÔʹÓÃÄÚÖÃµÄ HOST SPN ×÷Ϊ±ðÃûÀ´Ñ°ÕÒÆäËû·þÎñ¡£ÕâÒâζ×Å Kerberos Ô¼ÊøÎ¯ÅÉÎÞÐèʹÓà setspn.exe À´½øÐÐ Exchange ǰ¶Ëµ½ºó¶ËµÄίÅÉ¡££¨ËäȻʹÓÃÕâ¸ö½â¾ö·½°¸¿ÉÒÔÔÚ SPN ÊôÐÔÁбíÖÐÃ÷È·Ö¸¶¨ HTTP/Servername£¬µ«Õâ»áÒýÆð¸ü¶àÓɹÜÀíÔ±Ôì³ÉµÄ´íÎ󣬲¢ÇÒÕâÒ²²»ÊÇ Kerberos Ô¼ÊøÎ¯ÅÉÔËÐÐËù±ØÐèµÄ¡££©Kerberos Ô¼ÊøÎ¯ÅÉ»áÔÚ Active Directory ÖвéÕÒ A2D2 ÊôÐÔ¡£µ±Î´¶Ô¸ÃÊôÐÔ½øÐÐÌî³ä£¨»òÌî³äµÄ SPN Öµ³ö´í£©Ê±£¬Kerberos Ô¼ÊøÎ¯Åɽ«²»»áÔÚ¸÷×ԵķþÎñÆ÷¼ä½øÐС£µ«ÊÇÔÚÒ»¸ö Exchange Ⱥ¼¯ÖУ¬Ö»Ð轫À´×Ôǰ¶ËµÄ A2D2 ÊôÐÔÖ¸ÏòȺ¼¯½Úµã¼ÆËã»úÕÊ»§±ã¿ÉÈÃίÅÉ˳Àû½øÐС£
ÕýÈçÇ°ÃæÌáµ½µÄ£¬Windows Server 2003 Óò°üº¬µÄ Exchange 2003 ·þÎñÆ÷±ØÐë´¦ÓÚ Windows Server 2003 ±¾»ú¹¦ÄÜģʽ¡£ÔÚδ´ïµ½ÕâÒ»¼¶±ðµÄÓò¹¦ÄÜǰ£¬Kerberos Ô¼ÊøÎ¯Åɽ«²»ÄÜʹÓá£Èç¹ûÄúµÄÓòÈÔ´¦ÓÚ»ìºÏģʽ£¬µ«Äú°²×°ÁËÇ°ÃæÌáµ½µÄÈí¼þ¸üУ¬ÄÇôίÅÉ¿´ËÆÊÇ¿ÉÒÔ½øÐе쬵« SPN ×¢²áʵ¼ÊÉÏÊÇʧ°ÜµÄ¡£Kerberos Ô¼ÊøÎ¯ÅÉ»¹ÊÇÒ»ÏîÓò¹¦ÄÜ£¬¶ø²»ÊÇÁÖ¼¶¹¦ÄÜ¡£ÕâÒâζ×Å£¬¶ÔÓÚ Exchange Server 2003 À´Ëµ£¬ISA Server ÒÔ¼° Exchange ǰ¶ËºÍºó¶Ë·þÎñÆ÷±ØÐëÊÇͬһÓòÖеijÉÔ±£¨ËäÈ»²»Í¬ÓòÖеÄÓû§ÈÔÈ»¿ÉÒÔͨ¹ý Kerberos Ô¼ÊøÎ¯ÅɵÄÉí·ÝÑéÖ¤£©¡£·ÇÓò³ÉÔ±µÄ ISA Server ʵÀý£¬»òÊÇÆäËûÓòÖÐµÄ ISA Server ʵÀý½«²»×÷Ϊ¸Ã½â¾ö·½°¸µÄÒ»²¿·ÖÔËÐС£
IIS Admin ²»¿ÉÓÃÓÚÕë¶Ô OWA µÄÈκÎÀàÐ͵ÄÉí·ÝÑéÖ¤¸ü¸Ä¡£¼´Ê¹ OWA ÊÇÔÚ IIS ÏÂÔËÐУ¬²¢ÇÒ»áÏñÈÎºÎÆäËûÍøÕ¾Ò»ÑùÏìÓ¦ÔªÊý¾Ý¿âÖеı仯£¬µ« Exchange ºÍĿ¼·þÎñµ½ÔªÊý¾Ý¿â (DS2MB) ½ø³ÌʹÊÂÇé±äµÃÓе㸴ÔÓ¡£DS2MB ½ø³Ì»á½« Active Directory Öеĸü¸Ä¸´ÖƵ½ IIS ÔªÊý¾Ý¿âÖУ¬ÕâÖÖ¸´ÖÆÊǵ¥ÏòµÄ£¬Ëü»á¸²¸ÇÏÈǰֱ½Ó¶Ô IIS ½øÐеÄËùÓиü¸Ä¡£¸Ã½ø³ÌÔì³ÉµÄÓ°ÏìÊÇ£¬Èç¹û¹ÜÀíÔ±Ö±½Ó¶Ô IIS ÔªÊý¾Ý¿â½øÐиü¸Ä£¨ÈçÉèÖü¯³ÉÉí·ÝÑéÖ¤£©£¬¸Ã½â¾ö·½°¸¿´ËÆ¿ÉÒÔÕý³£ÔËÐУ¬µ«ÊÇÒ»µ©ÏÂÒ»´Î DS2MB ¸´ÖÆÑ»·¿ªÊ¼£¬½â¾ö·½°¸¾Í½«±»ÆÆ»µ¡£
ESM ÖÐΪ HTTP ÐéÄâĿ¼ÆôÓü¯³É Windows Éí·ÝÑéÖ¤µÄÑ¡ÏîÊÇ¿ÉÓõģ¬ÒòΪ ESM ¿ÉÒÔÖ±½Ó¶Ô Active Directory ½øÐб༣¬È»ºó½«Ëù×öµÄ¸ü¸Ä¸´ÖƵ½ IIS ÔªÊý¾Ý¿âÖС£Çë¼Çס£¬ËäȻֹͣϵͳÖúÀí·þÎñ»áÍ£Ö¹ DS2MB ½ø³Ì£¬ÒÔ±ãÈÃÄú¶Ô IIS ÔªÊý¾Ý¿â½øÐиü¸Ä¶ø²»±»¸²¸Ç£¬µ«ÎÒÃDz»½¨Òé²ÉÓÃÕâÖÖ·½·¨¡£ÏµÍ³ÖúÀíÏÂ´ÎÆô¶¯Ê±£¬»áÂÖѯ Active Directory Öеĸü¸Ä£¬È»ºó½â¾ö·½°¸½«×Ô¶¯±»Í£Óá£
¡°Î¯ÅÉ¡±Ñ¡ÏÏÔʾÁË¡°½öʹÓà Kerberos¡±Ñ¡ÏîºÍ¡°Ê¹ÓÃÈÎÒâµÄÉí·ÝÑéÖ¤ÐÒ顱ѡÏî¡£¼ÈÈ»ÎÒÃÇÌÖÂ۵Ľâ¾ö·½°¸ÊÇʹÓà Kerberos Ô¼ÊøÎ¯Åɵģ¬ÄÇôÎÒÃǾͲ»ÄÑÖªµÀÓ¦¸ÃÑ¡Ôñ¡°½öʹÓà Kerberos¡±£¬µ«ÊÇÐí¶à IT ×éÖ¯µÄÇé¿öÊDz»ÊÊÓÃÕâÖÖÒ»°ãÂß¼µÄ¡£Òò´Ë£¬ÎÒÃÇӦѡÔñ¡°Ê¹ÓÃÈÎÒâµÄÉí·ÝÑéÖ¤ÐÒ顱Õâ¸öÑ¡ÏÈçͼ 7 Ëùʾ£©£¬ÒòΪÇëÇó²¢²»ÊÇ×÷Ϊ Kerberos ÇëÇ󣬶øÊÇ×÷Ϊ HTTP ÇëÇó½øÈëµÄ£¬ËüÓÐÒ»¸öÓëÖ®Ïà¶ÔÓ¦µÄÖ¤ÊéÓ³Éäµ½ Active Directory ÕÊ»§¡£

ÔÚ´ËÀýÖУ¬ISA Server ÊÇͨ¹ý SSL À´ÇëÇóÓû§ PKI Ö¤ÊéµÄ¡£´«ÈëµÄÇëÇó²»ÊÇ Kerberos Ʊ֤£¬Òò´ËΪÁËÈà Kerberos Ô¼ÊøÎ¯ÅÉ˳Àû½øÐУ¬¾Í±ØÐë½øÐÐת»»¡£Òò´Ë£¬Ö¸¶¨¡°½öʹÓà Kerberos¡±ÕâÖÖÉèÖý«»áÆÆ»µ ISA Server ÉϵÄͨÐÅÁ´¡£µ«ÊÇÇë×¢Ò⣬¡°½öʹÓà Kerberos¡±Ñ¡ÏîÔÚ Exchange ǰ¶Ëµ½ºó¶Ë·þÎñÆ÷µÄίÅÉÖÐÊÇÊÊÓõģ¬ÒòΪǰ¶Ë·þÎñÆ÷Ö»»á½ÓÊÕÀ´×Ô ISA Server µÄ Kerberos Ʊ֤¡£
\Exchange ºÍ \Public ÐéÄâĿ¼ÊÇΨһ°üº¬×¨ÓÃÓû§ºÍ¹«¹²Îļþ¼ÐÐÅÏ¢µÄλÖá£Exchange ÖÐµÄ SSL ÅäÖöÔÓÚ Kerberos Ô¼ÊøÎ¯ÅÉ»òË«ÖØÉí·ÝÑéÖ¤À´Ëµ¶¼²»ÊÇеÄÊÂÎËüÊǶԲÉÓûù±¾Éí·ÝÑé֤ƾ¾ÝµÄ OWA µÄ±ê×¼ SSL ÆôÓõÄÒ»´Î¼Ì³Ð¡£ÄúÓ¦°´ÕÕÎÄÖÐÃèÊöµÄ·½·¨ÔÚ OWA ÉÏÆôÓà SSL£¬ÒòΪ´íÎóµØÇ¿ÖÆÆôÓà SSL »áÆÆ»µ OWA£¬Í¬Ê±Ò²»áʹ ESM ³öÏÖÎÊÌâ¡£
ʵʩ¸Ã½â¾ö·½°¸Ê±£¬ÏÈÒÔ±ê×¼·½Ê½²¿Êð ISA Server ºÍ Exchange ¿ÉÒÔÈù¤×÷±äµÃ¸ü¼Ó¼òµ¥¡£Ç벻ҪʵʩÕû¸ö Kerberos Ô¼ÊøÎ¯Åɽâ¾ö·½°¸²¢ÅäÖÃËùÓÐÉèÖã¨ÌرðÊÇÔÚ²¿ÊðÖл¹Ã»ÓÐ ISA Server ʱ£©¡£ÕâÑù»áʹµÃµ±´¦Àí¹ý³ÌÖеÄij¸ö×é¼þ»ò²½Öè³öÏÖ¹ÊÕÏʱµÄ¹ÊÕÏÅųý¹ý³Ì±äµÃ¸üΪ¸´ÔÓ¡£¶øÒÔ±ê×¼·½Ê½£¨Ê¹ÓÃÓû§ÃûºÍÃÜÂ룬µ«²»Ê¹ÓûùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤£©²¿Êð ISA Server ºÍ Exchange ¿ÉÒÔÈù¤×÷±äµÃ¸ü¼Ó¼òµ¥£¬¿ÉÈ·±£°²×°¿ÉÒÔÕý³£¹¤×÷£¬È»ºóת»»Îª Kerberos Ô¼ÊøÎ¯ÅɺÍÖ¤ÊéÉí·ÝÑéÖ¤¡£
Ò»°ãÀ´Ëµ£¬»ùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤²»ÄÜÓëÆôÓÃÖÇÄÜ¿¨µÄ OWA һͬʹÓ᣻ùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤ÐèÒªÓû§Í¨¹ý±ê×¼µÄ Outlook ±íµ¥Ìá½»Óû§ÃûºÍÃÜÂë¡£µ«ÊÇʹÓûùÓÚÖÇÄÜ¿¨µÄË«ÖØÉí·ÝÑéÖ¤£¬Óû§½«Ö»ÓµÓÐÒ»¸öÖÇÄÜ¿¨¶øÃ»ÓÐÃÜÂë¡£Òò´Ë»ùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤¾Í²»¾ßÓÐÈκÎͨ¹ý½ö½ÓÊÜ»òÌá½»Ö¤ÊéÀ´½øÐÐÉí·ÝÑéÖ¤µÄ·½·¨¡£ÔÚͨÐÅÁ´ÖеÄÈκÎÒ»´¦£¨ÀýÈçÔÚ ISA Server ºóµÄij¸öǰ¶Ë·þÎñÆ÷ÉÏ£©Ê¹ÓûùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤¶¼½«ÆÆ»µÆôÓÃÖÇÄÜ¿¨µÄ OWA ÅäÖá£Èç¹ûÄúÆôÓûùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤£¬Exchange ÐéÄâĿ¼½«±»Ç¿ÖÆÉèÖÃΪ¡°»ù±¾¡±Éí·ÝÑéÖ¤£¬Í¬Ê± IIS ÔªÊý¾Ý¿âÒ²½«±»ÉèÖÃΪ¡°»ù±¾¡±Éí·ÝÑéÖ¤¡£
Èç¹ûÄúµÄÓû§¼ÈÓÐÓû§Ãû/ÃÜÂëÓÖÓÐÖÇÄÜ¿¨£¬ÔòÄú¿ÉÒÔÔÚ ISA Web ÕìÌýÆ÷ÉÏÆôÓûØÍËÉí·ÝÑéÖ¤£¬µ±Óû§ÔÚÊÕµ½ÌáʾÊäÈë»ùÓÚÖ¤ÊéµÄƾ¾ÝµÄÐÅÏ¢ºóµã»÷ ESC °´Å¥Ê±£¬ÏµÍ³½«ÌáʾÊäÈë±ê×¼µÄÓû§Ãû/ÃÜÂëÆ¾¾Ý£¬¼´Ê¹ÔÚ Exchange ·þÎñÆ÷É쵀 ISA Server ºóÆôÓÃÁ˼¯³ÉÉí·ÝÑéÖ¤Ò²Èç´Ë¡£´ËÍ⣬ISA Server ¿ÉÈà SSL »á»°³¬Ê±£¬¸Ã¹¦ÄÜÓë»ùÓÚ±íµ¥µÄÉí·ÝÑéÖ¤ÀàËÆ¡£
Ö§³ÖÓÃÖÇÄÜ¿¨À´Îª OWA ½øÐÐÉí·ÝÑéÖ¤ÊÇ Exchange Server 2003 ºÍ Exchange Server 2007 ÖеÄÒ»ÏîÉîÊܹã´óÓû§»¶ÓµÄÐÂÔö¹¦ÄÜ¡£ÓÐÁËÕâÖÖʹÓÃÖ¤ÊéµÇ¼ OWA µÄÄÜÁ¦£¬Óû§¾Í²»ÔÙÐèҪΪ¼ÇסÄÇЩÓÖ³¤ÓÖ¸´ÔÓµÄÃÜÂë¶øµ£ÐÄ£¬¶ø¹ÜÀíÔ±ÏÖÔÚÒ²ÓÐÁËÓÐЧµÄ¹¤¾ßÀ´·ÀÖ¹»÷¼ü¼Ç¼Æ÷ºÍÆäËûÐÎʽµÄ¶ñÒâÈí¼þ£¬±ÜÃâÁËËüÃÇ´ÓÊܸÐȾµÄϵͳÖÐÕÒµ½Óû§Æ¾¾ÝµÄ·çÏÕ¡£ÓйØÏêϸÐÅÏ¢£¬Çë²Î¼û²àÀ¸Éϵġ°×ÊÔ´¡±¡£
ΪʹÓÃÖÇÄÜ¿¨µÄË«ÖØÉí·ÝÑéÖ¤ÕýÈ·ÅäÖà ISA Server£¬Í¨¹ýÔÚÒÑ·¢²¼µÄ OWA Ó¦ÓóÌÐòÉÏʵʩӦÓóÌÐò¼¶µÄɸѡ£¬¿ÉÒÔ½øÒ»²½ÔöÇ¿×ÜÌåµÄ°²È«ÐÔ¡£´ËÍ⣬ISA Server 2006 ÄÚÖÃÁ˶Ôͨ¹ý¼òµ¥µÄ·¢²¼Ïòµ¼À´·¢²¼ Exchange Server 2003 ºÍ Exchange Server 2007 µÄÖ§³Ö£¬Òò´Ë¶ÔÓÚÕýÔÚתΪʹÓà Exchange Server 2007 µÄ×éÖ¯À´Ëµ£¬ÏÈǰ¶Ô ISA Server Ëù×öµÄͶ×ÊÒÀÈ»ÓÐЧ¡£
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |