The information in this article applies to:
SUMMARYMicrosoft Exchange Server versions 5.0 and 5.5 support a variety of Internet-focused protocols, including POP3, HTTP, LDAP, and NNTP. This article explains the different authentication forms for each protocol. POP3POP3 allows for multiple types of user authentication. These can be configured using the Authentication Property Page on the POP3 object located in the Exchange Server Administrator program under Protocols. Specifically, three types of authentication can be used: Basic (Clear Text), Windows NT Challenge/Response, and Secure Sockets Layer (SSL).Basic (Clear Text)This authentication method sends the username and the password in an unencrypted format. It connects using port 110.NTLM (Windows NT Challenge/Response)The Windows NT Challenge/Response (NTLM) authentication method is much more secure because it uses a randomization algorithm and an encrypted password to authenticate users.The NTLM protocol is described by the following process:
Secure Sockets LayerThe Secure Sockets Layer (SSL) authentication method uses public/private key technology to ensure privacy. The SSL protocol resides at the Open Systems Interconnection (OSI) presentation layer and moves data from the application layer to the TCP transport layer. It is responsible for authentication, encryption, and verification of data integrity.The authentication function assures the data is being sent to the correct server and that the server is secure. Encryption ensures that data cannot be read by anyone other than the target server. Data integrity ensures the data has not been corrupted or altered in transit. All client/server communication occurs on an SSL-encrypted channel on port 995. SSL functions in the following manner:
Active Server Pages (HTTP)Access to the Microsoft Exchange Server computer through the Internet is provided by logging on with a secure connection as a validated user or as an anonymous user. Secure sockets layer (SSL) must be enabled on the Microsoft Internet Information Server computer.Using an Internet browser (such as Internet Explorer or Netscape), a user accesses the logon page and logs on to a Microsoft Exchange Server computer. During the logon process, an authenticated and encrypted session is established between the browser and the Microsoft Internet Information Server computer. To gain access to the Microsoft Exchange Server computer, the user's Microsoft Windows NT domain account password must be validated before permission is granted to use the program and its data. Validated UserThe Active Server Component uses Microsoft Windows NT authentication to grant access to users' mailboxes. To log on, users must enter their Microsoft Windows NT account name, password, and mailbox name. After validation is successfully completed, users have the same permissions in their mailbox as they have when they log on to a computer directly connected to the network.Anonymous UserAn anonymous user is a non-validated Web user who is not recognized by the Microsoft Exchange Server computer. Users can log on to a Microsoft Exchange Server computer anonymously but are restricted to viewing and accessing only the published public folders and address lists. The administrator can specify which folders and address lists to publish using the Microsoft Exchange Server Administrator program.LDAPThe Lightweight Directory Access Protocol (LDAP) provides a standard protocol for accessing and updating directory information in a client- server model. The LDAP standard describes how applications can add, delete, and modify objects and their attributes within a directory. Exchange Server 5.0 only supports read access to a limited subset of the Exchange Server directory, primarily the Recipients containers.LDAP allows for Simple Authentication, Windows NT Challenge/Response, and MCIS Membership System. Exchange Server 5.0 only supports Simple Authentication. Each authentication protocol has an additional option to use an SSL- encrypted channel for authentication and all session traffic. There are two modes of Simple Authentication, one where the client provides a password and the other where no password is provided. When no password is required, it is referred to as anonymous access. The Authentication Property Page allows the administrator to choose the forms of authentication that clients are allowed to use. Basic (Clear Text)Enables authentication through an unencrypted user name and password.Windows NT Challenge/Response (Exchange Server 5.5)Enables authentication through Windows NT network security and an encrypted password. Microsoft Exchange Server attempts to access the directory objects using the Windows NT user account that the user is logged on as. For example, if you are logged on as Domain\Drewc, with Windows NT Challenge/Response enabled, Microsoft Exchange Server will check the directory object's access control list (ACL) for permissions granted to Domain\Drewc.MCIS Membership System (Exchange Server 5.5)Enables authentication through Windows NT network security and the Microsoft Commercial Information Server (MCIS) Membership System.Secure Sockets LayerEnables authentication and all client-server communication to occur through an SSL-encrypted channel on port 636. SSL is a protocol that provides secure data communication using data encryption and decryption.Anonymous AccessThe Anonymous property page allows the administrator to permit or deny anonymous access. When anonymous access is allowed, no password is required by the LDAP client to retrieve information. The available attributes for a client that has not been authenticated are typically a subset of those for clients that have been authenticated. The administrator can control the Directory attributes that are made available using the Attributes property page on the DS Site Configuration object.NNTPNNTP specifies a protocol for the distribution, retrieval, and posting of news articles using a stream-based transmission. NNTP is designed so that the news articles are stored in a database allowing subscribers to select only those items they wish to read. Indexing, cross-referencing, and expiration of aged messages are also provided.In order for an NNTP client to log on to the Microsoft Exchange Server computer, one of the authentication methods that the client supports must be enabled on the server. Specifically, three types of authentication can be used: Basic (Clear Text), Windows NT Challenge/Response, and Secure Sockets Layer (SSL). Basic (Clear Text)Enables authentication through an unencrypted user name and password. Most NNTP clients support this method.Windows NT Challenge/ResponseEnable authentication through Windows NT network security and an encrypted password. This method is supported by Microsoft Internet Mail and News version 3.0 and later. With Windows NT Challenge/Response and Internet Mail and News, it is not possible to specify the name of the Microsoft Exchange Server mailbox or custom recipient you are using for authentication. By default, Microsoft Exchange Server attempts to access the mailbox associated with the Windows NT user account that the user is logged on as. For example, if you are logged on as Domain\Drewc, with Windows NT Challenge/Response enabled, Microsoft Exchange Server attempts to use the mailbox or custom recipient for Drewc.Secure Sockets LayerEnables authentication and all client-server communication to occur through an SSL-encrypted channel on port 563. SSL is a protocol that provides secure data communication using data encryption and decryption.MORE INFORMATION
For information on how to enable SSL, refer to the Knowledge Base article,
Q175439 Enabling SSL for Exchange Server
Keywords : XFOR |
Last Reviewed: March 9, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |