<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: SAN Certificates and ISA Server 2006</title>
	<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/</link>
	<description>Written by Henrik Walther, Microsoft MVP, the intention of this blog is to deliver the best content when it comes to information, news, tips and tweaks for the Microsoft Exchange Server product on topics such as mobile messaging, MONAD, and Active Directory integration. There is a discussion on various aspects of Exchange administration and management with a very special focus on Exchange Server 2007.</description>
	<pubDate>Thu, 24 Jul 2008 15:13:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: OCS 2007 Installation - Part 2 &#124; Confused Amused</title>
		<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-126113</link>
		<pubDate>Wed, 05 Mar 2008 18:41:31 +0000</pubDate>
		<guid>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-126113</guid>
					<description>[...] Note: The reason the first SAN listed must be the same as the subject name is because of how ISA 2006 handles the reverse proxy. If we only left sip.confusedamused.com as the sole SAN entry everything would work fine internally, but we&amp;#8217;d run into problems with the reverse proxy later. Since we&amp;#8217;ll later tell ISA the internal site name is tap-ocs-2k7.ptown.com, but when it connects it tries to match the subject name to the first SAN listed. When it doesn&amp;#8217;t line up ISA throws an Error 500 - Service Principal Name Incorrect. Doing the certificate this way now removes some unnecessary work later. You can read some more about this ISA issue here. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Note: The reason the first SAN listed must be the same as the subject name is because of how ISA 2006 handles the reverse proxy. If we only left sip.confusedamused.com as the sole SAN entry everything would work fine internally, but we&#8217;d run into problems with the reverse proxy later. Since we&#8217;ll later tell ISA the internal site name is tap-ocs-2k7.ptown.com, but when it connects it tries to match the subject name to the first SAN listed. When it doesn&#8217;t line up ISA throws an Error 500 - Service Principal Name Incorrect. Doing the certificate this way now removes some unnecessary work later. You can read some more about this ISA issue here. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Henrik Walther</title>
		<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-92059</link>
		<pubDate>Thu, 30 Aug 2007 17:49:29 +0000</pubDate>
		<guid>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-92059</guid>
					<description>Thanks for clarifying this Jim...</description>
		<content:encoded><![CDATA[<p>Thanks for clarifying this Jim&#8230;
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Harrison</title>
		<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91903</link>
		<pubDate>Wed, 29 Aug 2007 20:58:41 +0000</pubDate>
		<guid>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91903</guid>
					<description>No hotfix plans have &quot;changed&quot;; no hotfix plans ever existed.
Your sources were &quot;misinformed&quot;.
Please feel free to send them my way for gentle correcting.</description>
		<content:encoded><![CDATA[<p>No hotfix plans have &#8220;changed&#8221;; no hotfix plans ever existed.<br />
Your sources were &#8220;misinformed&#8221;.<br />
Please feel free to send them my way for gentle correcting.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Henrik Walther</title>
		<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91881</link>
		<pubDate>Wed, 29 Aug 2007 19:29:36 +0000</pubDate>
		<guid>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91881</guid>
					<description>That is really bad news... :(

My sources are actually individuals within MS, but I guess plans have changed then?</description>
		<content:encoded><![CDATA[<p>That is really bad news&#8230; <img src='http://blogs.msexchange.org/walther/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>My sources are actually individuals within MS, but I guess plans have changed then?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Harrison</title>
		<link>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91875</link>
		<pubDate>Wed, 29 Aug 2007 18:01:44 +0000</pubDate>
		<guid>http://blogs.msexchange.org/walther/2007/03/28/san-certificates-and-isa-server-2006/#comment-91875</guid>
					<description>Feel free to yell at your &quot;sources&quot;.
No hotfix is currently planned.
The ISA SE team is investigating the proper fix methodology.
Watch the ISABlog on this subject for the &quot;real word&quot;.</description>
		<content:encoded><![CDATA[<p>Feel free to yell at your &#8220;sources&#8221;.<br />
No hotfix is currently planned.<br />
The ISA SE team is investigating the proper fix methodology.<br />
Watch the ISABlog on this subject for the &#8220;real word&#8221;.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
