Configuring Single Sign-On for Microsoft Exchange 2010
-
Using the forms based authentication on Microsoft Exchange 2010.
-
Load balancing virtual server with authentication, authorization, and auditing traffic management policy.
-
The Action URL for SSO form is different in OWA 2010. Modify the traffic management policy accordingly.
-
You require a rewrite policy to set the
PBackcookie in the logon.aspx request. In normal scenarios, you set thePBackcookie at the client and click Submit. -
When you are using SSO, the response to logon.aspx is consumed and the NetScaler Gateway generates the form request. The cookie is not attached in the form submission request.
-
The OWA server expects the
PBackcookie in the form submission request. The rewrite policy is required to attach thePBackcookie in the form submission request.
Perform the following by using the CLI
-
Configure the authentication, authorization, and auditing traffic management
add tm formSSOAction OWA_Form_SSO_SSOPro -actionURL "/owa/auth.owa" -userField username -passwdField password -ssoSuccessRule "http.RES.SET_COOKIE.COOKIE(\"cadata\").VALUE(\"cadata\").LENGTH.GT(70" -responsesize 15000 -submitMethod POST -
Configure the traffic management policy and bind the policy
-
add tm trafficAction OWA_2010_Prof -appTimeout 1 -SSO ON -formSSO Action OWA_Form_SSO_SSOPro -
add tm trafficPolicy owa2k10_pol "HTTP.REQ.URL.CONTAINS(\"owa/auth/logon.aspx\")" OWA_2010_Prof -
bind tm global -policyName owa2k10_pol -priority 100
-
Rewrite configuration using CLI
-
add rewrite action set_pback_cookie insert_after "http.REQ.COOKIE.VALUE(\"OutlookSession\")" "\";PBack=0\"" -bypassSafetyCheck YES -
add rewrite policy set_pback_cookie "http.REQ.URL.CONTAINS(\"logon.aspx\")" set_pback_cookie -
bind rewrite global set_pback_cookie 100 END -type REQ_DEFAULT
Alternate rewrite configuration
Pback cookies might also not get inserted. The issue might occur after you have run the preceding commands to implement the rewrite configuration.
-
add rewrite action set_pback_cookie insert_http_header "Cookie" '"PBack=0"' -
add rewrite policy set_pback_cookie "http.REQ.URL.CONTAINS(\"logon.aspx\")" set_pback_cookie -
set rewrite policy set_pback_cookie -action set_pback_cookie -
bind rewrite global set_pback_cookie 100 END -type REQ_DEFAULT