Configuration Steps for MTLS Communication between Internal LCS 2005 SP1 Server SE and Office Communicator 2005 Clients

In this entry I review the configuration steps for validating Mutual Transport Layer Security (MTLS) is enabled for traffic between an LCS 2005 SP1 Standard Edition Server and any Office Communicator 2005 Clients interacting with this Server within the Corporate Enterprise.  I include installation of a Windows 2003 R2 Enterprise Certification Authority to issue the Enhanced Key Usage (EKU) Server Authentication Certificate Template to the LCS2k5 SP1 Server.  Then, I configure the LCS2k5 SP1 Server to offer this Certificate to Office Communicator 2005 Clients when connecting.  Additionally, I then show how to manually configure the Office 2005 Communicator clients to use MTLS over TCP instead of just TCP.  There are several practices offered here that should be used only in a 'testing scenerio'.  Those practice include:

Installation of an Enterprise Root Certification Authority (ER-CR) on an Active Directory Domain Controller
Installation of a Single Certification Authority (CA)
Not Reviewing Backup and Restore Procedures for Key Management Components of the Certification Authority
Not Reviewing use of the Security Configuration Wizard (SCW) along with Group Policy Objects to further reduce Public Key Infrastructure (PKI) attack vectors

Here is the Network Environment detail (the specific Installation Steps are here):

LCS2k5 SP1 Standard Edition
MSDE Database
No Federation
No Archiving
No Access Proxy

Single Forest
Single Domain
Enterprise Client IM 'Text Only'
TCP Transport - Client to Server and Server to Client (I change this to MTLS over TCP)
Client Configuration - Manually Configured
No IPSec - Client to Server


































 






































 




























































































 

Lynn Lunik
Independent Security Consultant
Windows(R) Platform
IT Pro Secure Corporation
and
exchangesummit.net
http://itprosecure.com and http://www.exchangesummit.net
blog <at> itprosecure.com

      


Posted Mar 10 2007, 04:38 AM by lynn lunik
Copyright IT Pro Secure Corporation 2009-2010 - All Rights Reserved Worldwide
Powered by Community Server (Non-Commercial Edition), by Telligent Systems
Locations of visitors to this page