Article ID: 917064 - Last Review: December 22, 2006 - Revision: 3.2 How to configure SharePoint Portal Server 2003 for off-box SSL termination by using ISA Server 2004On This PageSUMMARYThis article describes how to configure Microsoft Office SharePoint Portal Server 2003 for off-box SSL termination by using Microsoft Internet Security and Acceleration (ISA) Server
2004. (The steps in this article may also work for other SSL termination devices. For more information, see the "Known Issues" section.) SharePoint Portal Server 2003 Service Pack 2 (SP2) supports advanced extranet configurations. This includes configurations that use reverse proxy, alternate URLs, and off-box Security Sockets Layer (SSL) termination. The advanced extranet configuration that is described in this article uses SharePoint Portal Server 2003 SP2, Microsoft Windows SharePoint Services Service Pack 2 (SP2), and ISA Server 2004. INTRODUCTIONThis article discusses how to configure SharePoint Portal Server 2003 for off-box SSL termination by using ISA Server 2004. MORE INFORMATIONIf your organization wants to implement extranet deployments of SharePoint Portal Server 2003, you can use a reverse proxy and load balancers to help protect and manage access to the front end servers that host the virtual servers. However, this kind of configuration may change the protocol, the host header, or the port that is received by SharePoint Portal Server 2003. Several functions in SharePoint Portal Server 2003 generate links and e-mail messages that are based on the host header that is received from the client. If the host header is changed, an incorrect URL is returned to the client.
In the original release version of SharePoint Portal Server 2003 and of SharePoint Portal Server Service Pack 1 (SP1), any configuration that changes the protocol, the host header, or the port causes SharePoint Portal Server 2003 to return an incorrect URL to the client. This action occurs because SharePoint Portal Server 2003 generates replies that are based on the protocol, on the host header, or on the port that is received in the client request. Therefore, the original release version of SharePoint Portal Server 2003 and of SharePoint Portal Server 2003 Service Pack 1 (SP1) do not support advanced extranet configurations. SharePoint Portal Server 2003 Service Pack 2 (SP2) supports advanced extranet configurations. This includes configurations that use a reverse proxy, alternate URLs, and off-box SSL termination. This article describes an example that you can use to configure SharePoint Portal Server 2003 SP2 for off-box SSL termination by using ISA Server 2004. This example assumes that all the following conditions are true, in the order that they are presented:
How to configure off-box SSL terminationTo configure off-box SSL termination, you must configure Microsoft Windows SharePoint Services Service Pack 2 (SP2), ISA Server 2004, and SharePoint Portal Server 2003 SP2. This example uses the following URLs:
Step 1: Configure Windows SharePoint ServicesUse the Stsadm.exe command-line tool to configure the incoming URL and the outgoing URL in Windows SharePoint Services. To do this, follow these steps:
Step 2: Configure ISA Server 2004Create a Web publishing rule in ISA Server 2004. To do this, follow these steps:
Step 3: Configure SharePoint Portal Server 2003Configure alternate URLs for intranet access and for extranet access. To do this, follow these steps:
Known IssuesAfter you complete these steps, you will still encounter the following two known issues:
REFERENCESSupport for advanced extranet configurations was first included in SharePoint Portal Server 2003 SP2 and in Windows SharePoint Services SP2. For more information, visit the following Microsoft Web sites: http://office.microsoft.com/en-us/assistance/HA100214291033.aspx
(http://office.microsoft.com/en-us/assistance/HA100214291033.aspx)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ABBA20F2-3625-4C9C-A412-AB9BBEBDB5E8&displaylang=en
(http://www.microsoft.com/downloads/details.aspx?FamilyId=ABBA20F2-3625-4C9C-A412-AB9BBEBDB5E8&displaylang=en)
For more information about the Stsadm.exe command-line tool, see the "Command-Line Operations" topic, the "Command-Line Parameters" topic, and the Command-Line-Properties" topic in the "Reference" chapter of the Microsoft Windows SharePoint Services Administrator's Guide. To obtain this guide, visit the following Microsoft Web site:
http://www.microsoft.com/downloads/details.aspx?FamilyID=a637eff6-8224-4b19-a6a4-3e33fa13d230&displaylang=en
(http://www.microsoft.com/downloads/details.aspx?FamilyID=a637eff6-8224-4b19-a6a4-3e33fa13d230&displaylang=en)
| Article Translations
|
Back to the top
