<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>SharePoint Notes &#187; Extranet</title>
	<atom:link href="http://sharepointnotes.wordpress.com/category/extranet/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointnotes.wordpress.com</link>
	<description>Bleeding on the cutting edge ...</description>
	<lastBuildDate>Tue, 17 Nov 2009 17:00:01 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='sharepointnotes.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/cfc6f27c049b1e05717367d38558cd59?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>SharePoint Notes &#187; Extranet</title>
		<link>http://sharepointnotes.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://sharepointnotes.wordpress.com/osd.xml" title="SharePoint Notes" />
		<item>
		<title>MOSS Single SignOn with ISA Server</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/28/moss-single-signon-with-isa-server/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/28/moss-single-signon-with-isa-server/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 08:52:01 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=86</guid>
		<description><![CDATA[If you publish multiple Web Applications through ISA Server you might have experienced that users are asked to re-validate when one published site is linking to another published site even thought the sites are using the same user repository to validate users.
Fortunately, there is an easy fix for that: ISA Server SSO
ISA SSO offers Single Sign-on between site in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=86&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If you publish multiple Web Applications through ISA Server you might have experienced that users are asked to re-validate when one published site is linking to another published site even thought the sites are using the same user repository to validate users.</p>
<p>Fortunately, there is an easy fix for that: ISA Server SSO</p>
<p>ISA SSO offers Single Sign-on between site in the same <strong>DNS domain</strong>, provided:</p>
<ul>
<li>the published sites share the same Web Listener</li>
<li>the same port number and protocol is used</li>
<li>the users must be validated in the same user repository using the same authentication method</li>
</ul>
<p>This means that SSO between <a href="http://sales.contoso.com">http://sales.contoso.com</a> and <a href="http://marketing.contoso.com">http://marketing.contoso.com</a> is possible but SSO between <a href="http://sales.contoso.com">http://sales.contoso.com</a> and <a href="http://sales.contoso.org">http://sales.contoso.org</a> is not.</p>
<p>ISA SSO is enabled on the <strong>SSO</strong> tab in the Web Listener.</p>
<p><strong>More information:</strong></p>
<ul>
<li><a href="http://www.microsoft.com/technet/isa/2006/authentication.mspx" target="_blank">Authentication in ISA Server 2006</a></li>
<li><a href="http://www.microsoft.com/technet/isa/2006/secure_web_publishing.mspx" target="_blank">Secure Application Publishing</a></li>
</ul>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/86/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/86/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/86/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=86&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/28/moss-single-signon-with-isa-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 8: Publishing</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/23/sharepoint-extranet-solutions-with-isa-server-2006-part-8-publishing/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/23/sharepoint-extranet-solutions-with-isa-server-2006-part-8-publishing/#comments</comments>
		<pubDate>Wed, 23 Apr 2008 20:23:35 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=65</guid>
		<description><![CDATA[Finally, we&#8217;ve arrived at the last part of the series where everything should come together!
Let the SharePoint publishing begin!

On the right pane, select the Tasks tab and click Publish SharePoint sites
Name the publishing rule and click Next
Select Publish a single Web site or load balancer and click Next 
Use SSL to connect to the published Web [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=65&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Finally, we&#8217;ve arrived at the last part of the series where everything should come together!</p>
<p>Let the SharePoint publishing begin!</p>
<ol>
<li>On the right pane, select the <strong>Tasks</strong> tab and click <strong>Publish SharePoint sites</strong></li>
<li>Name the publishing rule and click <strong>Next</strong></li>
<li>Select <strong>Publish a single Web site or load balancer</strong> and click <strong>Next</strong> </li>
<li><strong>Use SSL to connect to the published Web server or server farm</strong> and click <strong>Next</strong> </li>
<li>Enter the <strong>Internal site name</strong>. The internal name is in this case the host header in the Extranet Web application that was extended to the Extranet zone: dmz.extranet.sharepointnotes.local</li>
<li>If the ISA server cannot resolve the internal site name (e.g. if it is not created as a A record in DNS), specify the <strong>computer name or IP address</strong>. Click <strong>Next</strong></li>
<li>Accept requests for <strong>This domain name (type below)</strong>, enter the <strong>Public name</strong> and click <strong>Next</strong>. The public name is the web site name, the clients will use to access the site. In this case extranet.sharepointnotes.local</li>
<li>Select the <strong>Web listener</strong> to use. If you haven&#8217;t one already, here&#8217;s how to create one:
<ul>
<li>Click <strong>New</strong> </li>
<li>Name the listener and click <strong>Next</strong></li>
<li>Select <strong>Require SSL secured connection with clients</strong> and click <strong>Next</strong></li>
<li>Select the <strong>External</strong> network interface and click <strong>Select IP Addresses</strong></li>
<li>Select <strong>Specified IP Addresses on the ISA Server computer in the selected network</strong> and select the IP Address that is used to server internal users coming from the Internet. Click <strong>Add</strong> and <strong>OK</strong></li>
<li>Back on the <strong>Web Listener IP Addresses</strong> page click <strong>Next</strong></li>
<li>Select <strong>Assign a certificate for each IP address</strong> and click <strong>Select Certificate</strong> </li>
<li>Choose the certificate issued to <strong>extranet.sharepointnotes.local</strong> and click <strong>Select </strong>and then <strong>Next</strong> </li>
<li>Use <strong>HTML Forms Authentication</strong> and let ISA validate using <strong>LDAP (Active Directory)</strong>. Click <strong>Next</strong></li>
<li>Do not enable SSO and click <strong>Next</strong></li>
<li>Click <strong>Finish</strong> and <strong>OK</strong> to accept the warning</li>
</ul>
</li>
<li>Make sure the newly created listener is selected and click <strong>Next</strong> </li>
<li>Use <strong>Basic authentication</strong> and click <strong>Next</strong> </li>
<li>Select <strong>SharePoint AAM is already configured</strong> and click <strong>Next</strong></li>
<li><strong>Remove All Authenticated users</strong> and click <strong>Add</strong> to add the <strong>User Set</strong> you created earlier. Click <strong>Next</strong></li>
<li>Click <strong>Finish</strong> and <strong>Apply</strong> the changes</li>
<li>Right-click the new rule and select <strong>Properties</strong></li>
<li>Select the <strong>To</strong> tab. Since we are forwarding requests from one URL to another, make sure the <strong>Forward the original host header</strong> option is not selected.</li>
<li>Select the <strong>Bridging</strong> tab</li>
<li>Since we are redirecting from SSL to HTTP, make sure the <strong>Redirect requests to HTTP port 80</strong> is selected and that <strong>Redirect requests to SSL port</strong> is not selected</li>
<li>Click <strong>OK</strong> and <strong>Apply</strong> the changes</li>
</ol>
<p>The rule is now created and out Extranet site is published and available for external users. Let&#8217;s test it:</p>
<ol>
<li>To test external access, browse to <a href="https://extranet.sharepointnotes.local">https://extranet.sharepointnotes.local</a></li>
<li>Login using a administrative user in the format <a href="mailto:user@dmzad.local">user@dmzad.local</a></li>
<li>Once the credentials are validated by ISA Server, the request is forwarded to MOSS and the user is presented with a new Sign In page. Log in again using the same credentials.</li>
<li>A good method to test access and especially Alternate Access Mappings is to create a new site:
<ul>
<li>From <strong>Site Actions</strong> select <strong>Create</strong></li>
<li>In the <strong>Web Pages</strong> section select <strong>Sites and Workspaces</strong></li>
<li>Enter a <strong>Title, URL name</strong> and select <strong>a site template</strong>. </li>
<li>Leave other settings with their default values and click <strong>Create</strong></li>
</ul>
</li>
<li>Verify the new site was created and displayed correctly. If that isn&#8217;t the case it normally indicates that the Alternate Access Mappings is configured incorrectly. </li>
</ol>
<p>Done! I hope you enjoyed the series. If so, drop me a note <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Please also drop me a note, if you know how to avoid to enter crendetials twice (once on ISA and again on MOSS)!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/65/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/65/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=65&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/23/sharepoint-extranet-solutions-with-isa-server-2006-part-8-publishing/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 7: Creating LDAP User Sets</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-7-creating-ldap-user-sets/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-7-creating-ldap-user-sets/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 21:05:56 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=82</guid>
		<description><![CDATA[The last thing we need before we can create the SharePoint Publishing rules, are two ISA User Sets. ISA Server user sets are used to segment internal and external users into groups that the ISA Server uses when granting or denying access.
It is assumed that the following groups are created and populated with appropriate users:

External [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=82&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The last thing we need before we can create the SharePoint Publishing rules, are two ISA User Sets. ISA Server user sets are used to segment internal and external users into groups that the ISA Server uses when granting or denying access.</p>
<p>It is assumed that the following groups are created and populated with appropriate users:</p>
<ul>
<li><strong>External Extranet Users</strong> exists in the DMZ Active Directory</li>
<li><strong>Internal Extranet Users</strong> exists in the corporate domain</li>
</ul>
<p><strong>Creating a User Set for External users</strong></p>
<ol>
<li>
<div>In the <strong>ISA Server Management Console</strong> navigate to <strong>Array -&gt; &lt;instance&gt; -&gt; Firewall Policy</strong></div>
</li>
<li>
<div>On the right pane select <strong>Toolbox</strong> and then <strong>Users</strong>. Select <strong>New</strong> to create a new user set</div>
</li>
<li>
<div>Name the set and click <strong>Next</strong></div>
</li>
<li>
<div>Select <strong>Add -&gt; LDAP</strong></div>
</li>
<li>
<div>Select the <strong>LDAP server set</strong> from the drop-down box. If a server set is not available, create one as described <a href="http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-6-configuring-isa-to-use-ldap/" target="_blank">part 6</a></div>
</li>
<li>
<div>In <strong>Specified group or user</strong> enter the <strong>External Extranet Users</strong> group created for External Access and click <strong>OK</strong></div>
</li>
<li>
<div>Enter credentials to the LDAP Server and click <strong>OK</strong></div>
</li>
<li>
<div>Verify the group is added to the list and click <strong>Next</strong></div>
</li>
<li>
<div>Click <strong>Finish</strong> and <strong>Apply</strong></div>
</li>
</ol>
<p><strong>Creating a User Set for Internal users</strong></p>
<ol>
<li>In the <strong>ISA Server Management Console</strong> navigate to <strong>Array -&gt; &lt;instance&gt; -&gt; Firewall Policy</strong></li>
<li>On the right pane select <strong>Toolbox</strong> and then <strong>Users</strong>.<strong> </strong>Select <strong>New</strong> to create a new user set</li>
<li>Name the set and click <strong>Next</strong></li>
<li>Select <strong>Add -&gt; Windows users and groups</strong></li>
<li>Click <strong>Locations&#8230;</strong></li>
<li>Expand <strong>Entire Directory</strong> and select the corporate domain. Click <strong>OK</strong></li>
<li>In the <strong>Enter the object names to select text</strong> box, enter <strong>Internal Extranet Users</strong> and click <strong>Check Names. </strong>Verify the group name is underlines and click <strong>OK</strong></li>
<li>Verify the group is added to the list and click <strong>Next</strong>. Note the group name is listed as a GUID and not the actual user name. Click <strong>Next</strong></li>
<li>Click <strong>Finish</strong> and <strong>Apply</strong></li>
</ol>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/82/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/82/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/82/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=82&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-7-creating-ldap-user-sets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 6: Configuring ISA to use LDAP</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-6-configuring-isa-to-use-ldap/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-6-configuring-isa-to-use-ldap/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 21:00:22 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=84</guid>
		<description><![CDATA[OK, let&#8217;s turn our attention to the ISA Server configurations again. It&#8217;s time to configure the LDAP connectivity! 
Create Connectivity Verifier
To test and verify the LDAP connection to the Active Directory in the DMZ, a Connectivity verifier can be created:

In the ISA Server Management Console navigate to Array -&#62; &#60;Instance&#62; -&#62; Monitoring
Select the Connectivity Verifiers tab
On [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=84&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>OK, let&#8217;s turn our attention to the ISA Server configurations again. It&#8217;s time to configure the LDAP connectivity! </p>
<p><strong>Create Connectivity Verifier</strong><br />
To test and verify the LDAP connection to the Active Directory in the DMZ, a Connectivity verifier can be created:</p>
<ol>
<li>In the <strong>ISA Server Management Console</strong> navigate to <strong>Array -&gt; &lt;Instance&gt; -&gt; Monitoring</strong></li>
<li>Select the <strong>Connectivity Verifiers</strong> tab</li>
<li>On the right pane click <strong>Create New Connectivity Verifier</strong></li>
<li>Name the Verifier and click <strong>Next</strong></li>
<li>Enter the IP address or server name of the LDAP Server</li>
<li>In <strong>Group type used to categorize the connectivity verifier</strong> select <strong>Active Directory</strong></li>
<li>Verify the <strong>Establish a TCP connection to port</strong> is set to <strong>LDAP</strong> and click <strong>Next</strong></li>
<li>Click <strong>Finish</strong> and <strong>Apply</strong></li>
</ol>
<p>The connectivity is now being verified and the Result should evaluate to Good in a few seconds. The status is also being propagated to the Dashboard view</p>
<p><strong>Add LDAP Server</strong></p>
<ol>
<li>In the <strong>ISA Server Management Console</strong> navigate to <strong>Array -&gt; &lt;Instance&gt; -&gt; Configuration -&gt; General</strong></li>
<li>Click <strong>Specify RADIUS and LDAP Servers</strong></li>
<li>Select the <strong>LDAP Servers</strong> Tab</li>
<li>Click <strong>Add</strong></li>
<li>Name the <strong>LDAP Set</strong> and click <strong>Add</strong></li>
<li>Enter <strong>Server name</strong>,<strong> Server description</strong> and <strong>Time-out</strong> and click <strong>OK</strong>. The <strong>Server name</strong> must either be an IP address or a name that is resolvable in DNS</li>
<li>Enter the <strong>fully-qualified domain name</strong> (e.g. dmzad.local) and clear the option to <strong>Use Global Catalog</strong></li>
<li>Enter the <strong>User name</strong> and <strong>Password</strong> of the user account that is used to lookup users in the DMZ Active Directory Domain</li>
<li>Click <strong>OK</strong></li>
<li>Back on the <strong>Authentication Servers page</strong>, click <strong>New</strong></li>
<li>Enter the <strong>Login expression</strong> and <strong>LDAP server set</strong>. The Login expression is the string that the users enters when they authenticate, is it usually in the form of a Active Directory login or an email address, for example:<br />
     DMZAD\*<br />
     <a href="mailto:*@dmzad.local">*@dmzad.local</a><br />
Since we configured the MOSS LDAP connection the way we did, use <a href="mailto:*@dmzad.local">*@dmzad.local</a></li>
<li>It is possible to create several login expressions for the same LDAP server set if you want to allow for more flexibility</li>
<li>Click <strong>OK</strong></li>
<li>Click <strong>Close</strong></li>
<li>Finally, <strong>Apply</strong> the changes</li>
</ol>
<p> </p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/84/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/84/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/84/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=84&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/16/sharepoint-extranet-solutions-with-isa-server-2006-part-6-configuring-isa-to-use-ldap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Forefront codename &#8220;Stirling&#8221; Beta</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/10/microsoft-forefront-codename-stirling-beta/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/10/microsoft-forefront-codename-stirling-beta/#comments</comments>
		<pubDate>Thu, 10 Apr 2008 17:08:01 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=83</guid>
		<description><![CDATA[The next version of ISA Server is available online.
Overview:
Microsoft® Forefront™ codename “Stirling” is an integrated security system that delivers comprehensive, coordinated protection across endpoints, messaging and collaboration servers and the network edge that is easier to manage and control.
By delivering simplified management and providing critical visibility into threats, vulnerabilities, and configuration risks, Forefront codename &#8220;Stirling&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=83&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The next version of ISA Server is available <a href="https://www.microsoft.com/downloads/info.aspx?na=22&amp;p=1&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=&amp;u=%2fdownloads%2fdetails.aspx%3fFamilyID%3d65bd5f8a-d94c-457a-9f88-2046597130e1%26DisplayLang%3den" target="_blank">online</a>.</p>
<p><strong>Overview:</strong></p>
<p>Microsoft® Forefront™ codename “Stirling” is an integrated security system that delivers comprehensive, coordinated protection across endpoints, messaging and collaboration servers and the network edge that is easier to manage and control.</p>
<p>By delivering simplified management and providing critical visibility into threats, vulnerabilities, and configuration risks, Forefront codename &#8220;Stirling&#8221; helps reduce costs and achieve greater insight into the enterprise security state.</p>
<p>At release, “Stirling” will include:</p>
<ul>
<li>A central management console and dashboard for security configuration and enterprisewide visibility.</li>
<li>The next-generation versions of Forefront products: the next generation of Forefront Client Security, Forefront Security for Exchange Server, Forefront Security for SharePoint and the Internet Security &amp; Acceleration Server (to be renamed the Forefront Threat Management Gateway).</li>
<li>Dynamic Response, an innovative Microsoft technology built into each component of &#8220;Stirling&#8221; that allows the entire system to share and use security information to dynamically respond to threats across multiple layers of the organization.</li>
</ul>
<p style="padding-left:30px;"> </p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/83/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/83/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=83&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/10/microsoft-forefront-codename-stirling-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 5: Installing a Stand-alone root CA</title>
		<link>http://sharepointnotes.wordpress.com/2008/04/02/sharepoint-extranet-solutions-with-isa-server-2006-part-5-installing-a-stand-alone-root-ca/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/04/02/sharepoint-extranet-solutions-with-isa-server-2006-part-5-installing-a-stand-alone-root-ca/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 19:56:19 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=64</guid>
		<description><![CDATA[In part three we created an Alternate Access Mapping http://dmz.extranet.sharepointnotes.local/, and assigned them the public URL https://extranet.sharepointnotes.local.  This implies that our Extranet solution must support SSL from the client to the ISA Server, so let&#8217;s install the Stand-alone CA so we can issue some certificates:


The Cerficate Services are installed through Add/Remove Programs (Start -&#62; Control Panel -&#62; Add or Remove Programs)


Click [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=64&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In <a href="http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-3-configuring-alternate-access-mappings/" target="_blank">part three</a> we created an Alternate Access Mapping <a href="http://dmz.extranet.sharepointnotes.local/">http://dmz.extranet.sharepointnotes.local/</a>, and assigned them the public URL <a href="https://extranet.sharepointnotes.local/">https://extranet.sharepointnotes.local</a>.  This implies that our Extranet solution must support SSL from the client to the ISA Server, so let&#8217;s install the Stand-alone CA so we can issue some certificates:</p>
<ol>
<li>
<div>The <strong>Cerficate Services</strong> are installed through <strong>Add/Remove Programs</strong> (Start -&gt; Control Panel -&gt; Add or Remove Programs)</div>
</li>
<li>
<div>Click <strong>Add/Remove Windows Components</strong></div>
</li>
<li>
<div>Select <strong>Cerficate Services</strong> (remember to select both <strong>Certificate Services CA</strong> and <strong>Certificates Services Web Enrollment support</strong>)</div>
</li>
<li>
<div>Click <strong>Yes</strong> to continue and then <strong>Next</strong></div>
</li>
<li>
<div>Select <strong>Stand-alone root CA</strong> and click <strong>Next</strong></div>
</li>
<li>
<div>Enter the <strong>Common name for this CA</strong> and click <strong>Next</strong> </div>
</li>
<li>
<div>Select where to place the <strong>Certificate Database</strong> files and click <strong>Next</strong></div>
</li>
<li>
<div>Click <strong>Yes</strong> to stop the <strong>Internet Information Services</strong> </div>
</li>
<li>
<div>If prompted, select <strong>Yes</strong> to enable ASP</div>
</li>
<li>
<div>Click <strong>Finish</strong></div>
</li>
</ol>
<p>Next, Let&#8217;s issue some certificates to extranet.sharepointnotes.local:</p>
<ol>
<li>
<div>Point your browser to <a href="http://localhost/certsrv">http://localhost/certsrv</a></div>
</li>
<li>
<div>Select <strong>Request a certificate</strong></div>
</li>
<li>
<div>Submit an <strong>Advanced certificate request</strong></div>
</li>
<li>
<div>Select <strong>Submit and submit an request to this CA</strong></div>
<ul>
<li>
<div>Name: the public name of the web site (extranet.sharepointnotes.local)</div>
</li>
<li>
<div>Type of Certificate Needed: Server Authentication Certificate</div>
</li>
<li>
<div>Mark keys as exportable</div>
</li>
<li>
<div>Store the certificate in the local computer store</div>
</li>
<li>
<div>Friendly Name: same as Name</div>
</li>
</ul>
</li>
<li>
<div>Hit <strong>Submit</strong></div>
</li>
<li>
<div>Select <strong>Yes </strong>to request a certificate</div>
</li>
<li>
<div>To issues the pending certificate, start <strong>Certification Authority</strong> (Start -&gt; Administrative Tools -&gt; Certification Authority)</div>
</li>
<li>
<div>Select <strong>Pending Requests</strong></div>
</li>
<li>
<div>Right click the certificate and select <strong>All Tasks -&gt; Issue</strong></div>
</li>
<li>
<div>
<div>Point your browser once again to <a href="http://localhost/certsrv">http://localhost/certsrv</a></div>
</div>
</li>
<li>
<div>
<div>Click <strong>View the status of a pending certificate request</strong></div>
</div>
</li>
<li>
<div>
<div>Click the server certificate link</div>
</div>
</li>
<li>
<div>
<div>Select <strong>Install this certificate</strong> and <strong>Yes </strong>to confirm</div>
</div>
</li>
<li>
<div>
<div>The certificate is now installed in the Personal certificate store of the local computer</div>
</div>
</li>
</ol>
<p>Export the certificate (skip this part if the certificates are already installed on the ISA Server):</p>
<ol>
<li>
<div>Start a MMC console (Start -&gt; Run -&gt; mmc)</div>
</li>
<li>
<div>Add/Remove Snapp-in (File -&gt; Add/Remove Snapp-in)</div>
</li>
<li>
<div>Click <strong>Add</strong></div>
</li>
<li>
<div>Select <strong>Certificates</strong> and click <strong>Add</strong></div>
</li>
<li>
<div>Select to manage the <strong>Computer account</strong> and click <strong>Next</strong></div>
</li>
<li>
<div>Select to manage the <strong>Local computer</strong> and click <strong>Finish</strong></div>
</li>
<li>
<div>Click <strong>Close </strong>and <strong>OK</strong></div>
</li>
<li>
<div>Navigate to <strong>Personal Certificates</strong> (Console -&gt; Certificates -&gt; Personal -&gt; Certificates)</div>
</li>
<li>
<div>Right click the certificate created above and select <strong>All Tasts -&gt; Export</strong></div>
</li>
<li>
<div>In the <strong>Certificates Export Wizard</strong> click <strong>Next</strong></div>
</li>
<li>
<div><strong>Export the private key</strong> and click <strong>Next</strong></div>
</li>
<li>
<div>Make sure <strong>Include all certificates in the certification path if possible</strong> and <strong>Enable strong encryption</strong> is selected and click <strong>Next</strong></div>
</li>
<li>
<div>Enter and confirm a <strong>Password</strong> and click <strong>Next</strong></div>
</li>
<li>
<div>Select a path and file name and click <strong>Next</strong></div>
</li>
<li>
<div>Click <strong>Finish</strong> and <strong>OK</strong> </div>
</li>
<li>
<div>Copy the certificate file to the ISA Server</div>
</li>
</ol>
<p>Import the certificate (skip this part if the certificates are already installed on the ISA Server)</p>
<ol>
<li>
<div>On the ISA Server, perform steps 1 to 7 in the Export-section above</div>
</li>
<li>
<div>
<div>Navigate to <strong>Personal</strong> (Console -&gt; Certificates -&gt; Personal)</div>
</div>
</li>
<li>
<div>Right click <strong>Personal</strong> and select <strong>All Tasks -&gt; Import</strong></div>
</li>
<li>
<div>In the <strong>Certificates Export Wizard</strong> click <strong>Next</strong> </div>
</li>
<li>
<div>Change the file type filter to <strong>All Files</strong> and browse to the location where the certificate is stored. Select the certificate and click <strong>Open</strong> and <strong>Next</strong> </div>
</li>
<li>
<div>Enter the password if the certificate is password protected and click <strong>Next</strong></div>
</li>
<li>
<div>Make sure the certificate is placed in the <strong>Personal</strong> certificate store and click <strong>Next</strong></div>
</li>
<li>
<div>Click <strong>Finish</strong> and <strong>OK</strong></div>
</li>
</ol>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/64/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/64/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=64&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/04/02/sharepoint-extranet-solutions-with-isa-server-2006-part-5-installing-a-stand-alone-root-ca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 4: LDAP authentication in SharePoint</title>
		<link>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-4-ldap-authentication-in-sharepoint/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-4-ldap-authentication-in-sharepoint/#comments</comments>
		<pubDate>Sun, 30 Mar 2008 20:30:30 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=81</guid>
		<description><![CDATA[In this post we will configure our Extranet Web Application to authenticate users in the Extranet Zone using LDAP.  However, not any LDAP server can be used since it must be supported by ISA Server 2006, so we are using a Active Directory in the DMZ.
The trick is to configure web.config files are the Central [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=81&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In this post we will configure our Extranet Web Application to authenticate users in the Extranet Zone using LDAP.  However, not any LDAP server can be used since it must be supported by ISA Server 2006, so we are using a Active Directory in the DMZ.</p>
<p>The trick is to configure web.config files are the Central Administration IIS site as well as all IIS sites for that is part of the Extranet Web Application. When that is done, the Authentication Provider for the extended web application must be changed to use the new provider. Finally, we add some Site Collection Administrators and users.</p>
<p>Still with me? Good, let&#8217;s go!</p>
<p>Oh, BTW, the web.config for a SharePoint Web Application is normally located at this location:</p>
<p>     <span style="font-size:11pt;line-height:115%;font-family:'Courier New';">C:\Inetpub\wwwroot\wss\VirtualDirectories\xxx</span></p>
<p>where xxx is the directory for the Web Application. If the exact location is not known, use the Internet Information Services (IIS) Manager to locate it:</p>
<ol>
<li>
<div>Start <strong>Internet Information Services (IIS) Manager</strong>(Start -&gt; Administrative Tools -&gt; Internet Information Services (IIS) Manager)</div>
</li>
<li>
<div>Navigate to <strong>&lt;Server&gt; -&gt; Web Sites</strong></div>
</li>
<li>
<div>Right-click the Web Application in question and select <strong>Properties</strong></div>
</li>
<li>
<div>Select the <strong>Home Directory</strong> tab</div>
</li>
<li>
<div>The <strong>Local Path</strong> setting is the Web Application path</div>
</li>
</ol>
<p><strong>Step 1: Edit Web.config for Central Administration</strong><br />
Modifying the web.config for Central Administration is needed in order to add a Site Collection administrator or to add users in a Policy for Web Application.</p>
<ol>
<li>
<div>Open Web.config for <strong>Central Administration</strong></div>
</li>
<li>
<div>Between the <span style="font-size:10pt;font-family:'Courier New';">&lt;/configSections&gt;</span> and <span style="font-size:10pt;font-family:'Courier New';">&lt;SharePoint&gt;</span>tags, create a LDAP connection string.</div>
</li>
<div>
<div><span style="font-size:8pt;font-family:'Courier New';">&lt;connectionStrings&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"><span></span>  &lt;add name=&#8221;<b><font color="#ff0000">ADConnectionString</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';">    connectionString=</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';">      &#8220;LDAP://<b><font color="#ff0000">dmz.dmzad.local</font></b>:389/<b><font color="#ff0000">CN=Users,DC=DMZAD,DC=local</font></b>&#8220;/&gt;</span></div>
<p class="MsoBodyText" style="margin:0 0 6pt;"><span style="font-size:8pt;font-family:'Courier New';">&lt;/connectionStrings&gt;</span></p>
</div>
<li>
<div>Between <span style="font-size:10pt;font-family:'Courier New';">&lt;system.web&gt;</span> and <span style="font-size:10pt;font-family:'Courier New';">&lt;securityPolicy&gt;</span> tags add the following:</div>
</li>
<div><span style="font-size:8pt;font-family:'Courier New';">&lt;membership defaultProvider=&#8221;<b><font color="#ff0000">LDAP</font></b>&#8220;&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>  </span>&lt;providers&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>    </span>&lt;add</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>name=&#8221;<b><font color="#ff0000">LDAP</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>connectionStringName=&#8221;<b><font color="#ff0000">ADConnectionString</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>connectionUsername=&#8221;<b><font color="#ff0000">DMZAD\administrator</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>connectionPassword=&#8221;<b><font color="#ff0000">password</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>enableSearchMethods=&#8221;true&#8221;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>attributeMapUsername=&#8221;userPrincipalName&#8221;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>type=&#8221;System.Web.Security.ActiveDirectoryMembershipProvider,</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>       </span>System.Web, Version=2.0.0.0,</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>       </span>Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a&#8221; /&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>  </span>&lt;/providers&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';">&lt;/membership&gt;</span><span style="font-family:'Courier New';"></span></div>
<li>
<div>The settings in <strong><font color="#ff0000">bold </font></strong>are provided as an example and are customizable. The settings must be changed to match the settings in your environment. Under normal circumstances these settings are the same as the ones used for the Extranet Web Application below.</div>
</li>
</ol>
<p><strong>Step 2: Edit Web.config for the Extranet Web Application</strong><br />
Modifying the web.config for Extranet Web Application is needed in order to add a Site Collection administrator or to add users in a Policy for Web Application. Modifying web.config for the extended web application (dmz.extranet.sharepointnotes.local) is necessary for authenticating external users. Modifying the web.config in the Default Zone will allow a site administrator in that zone to add users in the Extranet Zone.</p>
<ol>
<li>
<div>Open Web.config for the <strong>(Extended)</strong> <strong>Extranet Web Application</strong></div>
</li>
<li>
<div>Between the <span style="font-size:10pt;font-family:'Courier New';">&lt;/configSections&gt;</span> and <span style="font-size:10pt;font-family:'Courier New';">&lt;SharePoint&gt;</span>tags, create a LDAP connection string.</div>
</li>
<div>
<div><span style="font-size:8pt;font-family:'Courier New';">&lt;connectionStrings&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"><span></span>  &lt;add name=&#8221;<b><font color="#ff0000">ADConnectionString</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';">    connectionString=</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';">      &#8220;LDAP://<b><font color="#ff0000">dmz.dmzad.local</font></b>:389/<b><font color="#ff0000">CN=Users,DC=DMZAD,DC=local</font></b>&#8220;/&gt;</span></div>
<p class="MsoBodyText" style="margin:0 0 6pt;"><span style="font-size:8pt;font-family:'Courier New';">&lt;/connectionStrings&gt;</span></p>
</div>
<li>
<div>Between <span style="font-size:10pt;font-family:'Courier New';">&lt;system.web&gt;</span> and <span style="font-size:10pt;font-family:'Courier New';">&lt;securityPolicy&gt;</span> tags add the following:</div>
</li>
<div><span style="font-size:8pt;font-family:'Courier New';">&lt;membership defaultProvider=&#8221;<b><font color="#ff0000">LDAP</font></b>&#8220;&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>  </span>&lt;providers&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>    </span>&lt;add</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>name=&#8221;<b><font color="#ff0000">LDAP</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>connectionStringName=&#8221;<b><font color="#ff0000">ADConnectionString</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>connectionUsername=&#8221;<b><font color="#ff0000">DMZAD\administrator</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>connectionPassword=&#8221;<b><font color="#ff0000">password</font></b>&#8220;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>enableSearchMethods=&#8221;true&#8221;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>     </span>attributeMapUsername=&#8221;userPrincipalName&#8221;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>      </span>type=&#8221;System.Web.Security.ActiveDirectoryMembershipProvider,</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>       </span>System.Web, Version=2.0.0.0,</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"> </span><span style="font-size:8pt;font-family:'Courier New';"><span>       </span>Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a&#8221; /&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';"><span>  </span>&lt;/providers&gt;</span></div>
<div><span style="font-size:8pt;font-family:'Courier New';"></span><span style="font-size:8pt;font-family:'Courier New';">&lt;/membership&gt;</span><span style="font-family:'Courier New';"></span></div>
<li>
<div>Again, the settings in <strong><font color="#ff0000">bold</font></strong> are provided as an example and are customizable. The settings must be changed to match the settings in your environment. Under normal circumstances these settings are the same as the ones used for Central Administration above.</div>
</li>
</ol>
<p><strong>Step 3: Change the Authentication Provider the Extranet Zone</strong><br />
Follow these instructions to chance the authentication provider:</p>
<ol>
<li>
<div>Go to the <strong>Application Management</strong> section of <strong>Central Administration</strong></div>
</li>
<li>
<div>In the <strong>Application Security</strong> section click <strong>Authentication Providers</strong></div>
</li>
<li>
<div>Select the Extranet Web Application</div>
</li>
<li>
<div>Click the <strong>Extranet Zone</strong></div>
</li>
<li>
<div>In the <strong>Authentication Type</strong> section select <strong>Forms</strong></div>
</li>
<li>
<div>In the <strong>Membership Provider Name</strong> enter the same provider name that was used in step 1 and 2, for example <strong>LDAP</strong></div>
</li>
<li>
<div>Click <strong>Save</strong></div>
</li>
<li>
<div>Verify that the <strong>Membership Provider Name</strong> for the <strong>Extranet Zone</strong> has changed from <strong>Windows</strong> to the new name, for example <strong>LDAP</strong></div>
</li>
</ol>
<p><strong>Step 4: Add Site Administrators<br />
</strong>Follow these instructions to add LDAP user as a Site Administrator:</p>
<ol>
<li>
<div>Go to the <strong>Application Management</strong> section of <strong>Central Administration</strong></div>
</li>
<li>
<div>In the <strong>SharePoint Site Management</strong> section click <strong>Site collection administrators</strong></div>
</li>
<li>
<div>In the <strong>Site Collection</strong> section select the <strong>Extranet Web Application</strong></div>
</li>
<li>
<div>In the <strong>Secondary Site Collection Administrator</strong> add a user account from the DMZ Active Directory. Remember that the format is: <a href="mailto:*@dmzad.local">*@dmzad.local</a></div>
</li>
<li>
<div> Click <strong>OK</strong></div>
</li>
</ol>
<p>Site Collection administrators can also be added through the Site Settings interface:</p>
<ol>
<li>
<div>Log on to <a href="http://extranet.sharepointnotes.local/">http://extranet.sharepointnotes.local</a> as a site administrator</div>
</li>
<li>
<div>Navigate to <strong>Site Actions -&gt; Site Settings</strong></div>
</li>
<li>
<div>In the <strong>Users and Permissions</strong> section click <strong>Site collection administrators</strong></div>
</li>
<li>
<div>In the <strong>Site Collection Administrators</strong> section, add the user or group you want to add and select the <strong>Check Names</strong>-icon (or press CTRL+K). Verify that the user/group was found.</div>
</li>
</ol>
<p><strong>Step 5: Add Users to the Extranet Web Application<br />
</strong>Follow these instructions to add users to the Extranet Web Application</p>
<ol>
<li>
<div>Log on to <a href="http://extranet.sharepointnotes.local/">http://extranet.sharepointnotes.local</a> as a site administrator</div>
</li>
<li>
<div>Navigate to <strong>Site Actions -&gt; Site Settings</strong></div>
</li>
<li>
<div>In the <strong>Users and Permissions</strong> section click <strong>People and groups</strong></div>
</li>
<li>
<div>Select the group that suite the user or groups of users you want to add</div>
</li>
<li>
<div>Select <strong>New -&gt; Add users</strong></div>
</li>
<li>
<div>In the <strong>Add Users</strong> section, add the user or group you want to add and select the <strong>Check Names</strong>-icon (or press CTRL+K). Verify that the user/group was found.</div>
</li>
<li>
<div>In the <strong>Give Permission</strong> section check the correct permission level is granted and click <strong>OK</strong></div>
</li>
</ol>
<p>This completes the configuration on the SharePoint site of thing. In the coming posts, we&#8217;ll install the Root CA, issue and install some certificates, create some ISA User Sets and finally publish the Extranet Web Application through ISA Server.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/81/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/81/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=81&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-4-ldap-authentication-in-sharepoint/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 3: Configuring Alternate Access Mappings</title>
		<link>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-3-configuring-alternate-access-mappings/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-3-configuring-alternate-access-mappings/#comments</comments>
		<pubDate>Sun, 30 Mar 2008 17:23:01 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=80</guid>
		<description><![CDATA[In part 2 of this series, we created and exended the Extranet Web Application. In this part we will configure the Alternate Access Mapping to be able to access the Web Application from multiple locations using the same URL.


Go to the Operations section of Central Administration


In the Global configuration section click Alternate access mappings


Click Add [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=80&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In <a href="http://sharepointnotes.wordpress.com/2008/03/02/sharepoint-extranet-solutions-with-isa-server-2006-part-2-creating-the-extranet-web-application/" target="_blank">part 2</a> of this series, we created and exended the Extranet Web Application. In this part we will configure the Alternate Access Mapping to be able to access the Web Application from multiple locations using the same URL.</p>
<ol>
<li>
<div>Go to the <strong>Operations</strong> section of <strong>Central Administration</strong></div>
</li>
<li>
<div>In the <strong>Global configuration</strong> section click <strong>Alternate access mappings</strong></div>
</li>
<li>
<div>Click <strong>Add Internal URLs</strong></div>
</li>
<li>
<div>Select the Extranet Web Application and the host header for the extended web application, in this case <a href="http://dmz.extranet.sharepointnotes.local/">http://dmz.extranet.sharepointnotes.local</a></div>
</li>
<li>
<div>Assign the <strong>Internal URL</strong> to the <strong>Extranet zone</strong> and click <strong>Save</strong></div>
</li>
</ol>
<p>The Alternate Access Mappings should now be the following for the extranet.sharepointnotes.local Web Application:</p>
<p> </p>
<table class="MsoTableGrid" style="border-collapse:collapse;border:medium none;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="width:154.25pt;background-color:transparent;border:black 1pt solid;padding:0 5.4pt;" width="206" valign="top">
<p class="MsoNoSpacing" style="margin:0;"><strong><span style="font-size:8pt;"><span style="font-family:Calibri;">Internal URL</span></span></strong></p>
</td>
<td style="border-right:black 1pt solid;border-top:black 1pt solid;border-left:#d4d0c8;width:38.35pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="51" valign="top"><strong><span style="font-size:8pt;"><span style="font-family:Calibri;">Zone</span></span></strong></td>
<td style="border-right:black 1pt solid;border-top:black 1pt solid;border-left:#d4d0c8;width:138.85pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="185" valign="top"><strong><span style="font-size:8pt;"><span style="font-family:Calibri;">Public URL for zone</span></span></strong></td>
</tr>
<tr>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:black 1pt solid;width:154.25pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="206" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">http://extranet.sharepointnotes.local</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:38.35pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="51" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">Default</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:138.85pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="185" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">http://extranet.sharepointnotes.local</span></span></td>
</tr>
<tr>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:black 1pt solid;width:154.25pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="206" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">https://extranet.sharepointnotes.local</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:38.35pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="51" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">Extranet</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:138.85pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="185" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">https://extranet.sharepointnotes.local</span></span></td>
</tr>
<tr>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:black 1pt solid;width:154.25pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="206" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">https://dmz.extranet.sharepointnotes.local</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:38.35pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="51" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">Extranet</span></span></td>
<td style="border-right:black 1pt solid;border-top:#d4d0c8;border-left:#d4d0c8;width:138.85pt;border-bottom:black 1pt solid;background-color:transparent;padding:0 5.4pt;" width="185" valign="top"><span style="font-size:8pt;"><span style="font-family:Calibri;">https://extranet.sharepointnotes.local</span></span></td>
</tr>
</tbody>
</table>
<p><a href="https://extranet.sharepointnotes.local/"></a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/80/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/80/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=80&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/03/30/sharepoint-extranet-solutions-with-isa-server-2006-part-3-configuring-alternate-access-mappings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>External Collaboration Toolkit for SharePoint Released</title>
		<link>http://sharepointnotes.wordpress.com/2008/03/22/external-collaboration-toolkit-for-sharepoint-released/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/03/22/external-collaboration-toolkit-for-sharepoint-released/#comments</comments>
		<pubDate>Sat, 22 Mar 2008 20:11:52 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[MOSS]]></category>
		<category><![CDATA[WSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=72</guid>
		<description><![CDATA[I got this email today, stating that the External Collaboration Toolkit for SharePoint has been released. No big surprise, really, since it has been available on TechNet since February 28, but still good news:
I&#8217;m happy to announce that the External Collaboration Toolkit for SharePoint has been released and is now available on Microsoft TechNet at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=72&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I got this email today, stating that the External Collaboration Toolkit for SharePoint has been released. No big surprise, really, since it has been available on TechNet since February 28, but still good news:</p>
<blockquote><p>I&#8217;m happy to announce that the External Collaboration Toolkit for SharePoint has been released and is now available on Microsoft TechNet at <a target="_blank" href="http://www.microsoft.com/collabkit">http://www.microsoft.com/collabkit</a>. This accelerator helps you easily deploy a SharePoint-based external collaboration facility at your organization. Once this facility is in place, end users can quickly create a new collaboration site (using a SharePoint site collection) and add internal and external users to that site. Both these process can be workflow enabled so that an administrator must approve both site and user creation.</p>
<p>The toolkit runs on both MOSS 2007 and Windows SharePoint Services 3.0. It also leverages SQL Server 2005 and ADAM. All external users are created in the ADAM directory so they are segregated from your primary user store.</p>
<p>Thank you for your help during development of the External Collaboration Toolkit for SharePoint. If you have any questions, please let me know.</p>
<p>Bill Canning<br />
Senior Program Manager<br />
Solution Accelerators</p></blockquote>
<p>I find it slightly odd that ADAM has been chosen as a user repository for an <strong>External</strong> solution since ISA Server 2006 does not support ADAM, not even when using LDAP. The people within Microsoft I have talked to about ISA/ADAM support cannot even confirm if ADAM is supported when the next version of ISA is released in Q1 2009.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/72/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/72/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=72&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/03/22/external-collaboration-toolkit-for-sharepoint-released/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Extranet Solutions with ISA Server 2006 &#8211; Part 2: Creating the Extranet Web Application</title>
		<link>http://sharepointnotes.wordpress.com/2008/03/02/sharepoint-extranet-solutions-with-isa-server-2006-part-2-creating-the-extranet-web-application/</link>
		<comments>http://sharepointnotes.wordpress.com/2008/03/02/sharepoint-extranet-solutions-with-isa-server-2006-part-2-creating-the-extranet-web-application/#comments</comments>
		<pubDate>Sun, 02 Mar 2008 16:35:52 +0000</pubDate>
		<dc:creator>Christian Dam</dc:creator>
				<category><![CDATA[Extranet]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[MOSS]]></category>

		<guid isPermaLink="false">http://sharepointnotes.wordpress.com/?p=61</guid>
		<description><![CDATA[Update: The previous post was a bit too complex. It has been modified a bit so now it should actually work   
Let&#8217;s create and extend the Extranet Web Application. Since we need to access it in three different ways, the web application will be extended so it covers two zones:


Default Zone: extranet.sharepointntes.local. This zone [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=61&subd=sharepointnotes&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Update: The previous post was a bit too complex. It has been modified a bit so now it should actually work <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </strong> </p>
<p>Let&#8217;s create and extend the Extranet Web Application. Since we need to access it in three different ways, the web application will be extended so it covers two zones:</p>
<ul>
<li>
<div>Default Zone: extranet.sharepointntes.local. This zone is used for access by internal corporate users as well as services like search. Will use Windows authentication.</div>
</li>
<li>Extranet Zone: dmz.extranet.sharepointnotes.local. This zone is used for external partners. Will use a DMZ AD for authentication</li>
</ul>
<p><strong>Step 1: Create the Extranet Web Application</strong></p>
<ol>
<li>
<div>In <strong>Central Administration</strong> navigate to <strong>Application Management</strong> </div>
</li>
<li>
<div>In the <strong>SharePoint Web Application Management</strong> section select <strong>Create or extend Web application</strong></div>
</li>
<li>
<div>Select <strong>Create a new Web application </strong></div>
</li>
<li>
<div>In the <strong>IIS Web Site</strong> section opt to <strong>Create a new IIS web site</strong> and enter the required information, e.g:</div>
<ul>
<li>
<div>Description: SharePoint Extranet &#8211; 80</div>
</li>
<li>
<div>Port: 80</div>
</li>
<li>
<div>Host Header: extranet.sharepointnotes.local</div>
</li>
<li>
<div>Path: use default</div>
</li>
</ul>
</li>
<li>
<div>Keep the default selections for <strong>Security Configuration</strong></div>
</li>
<li>
<div>In the <strong>Load Balanced URL </strong>change the <strong>URL</strong> to <a href="https://extranet.sharepointnotes.local/">http://extranet.sharepointnotes.local</a> (remove :80)</div>
</li>
<li>In the <strong>Application Pool</strong> section select to <strong>Create new application pool</strong>. Name the new application pool and enter user name and password.</li>
<li>
<div>In the Database Name and Authentication section, enter the <strong>Database server</strong> and<strong>  Database Name.</strong>Is is recommended not to accept the suggested database name, but rather to name your database something that is specific related to your Web Application, e.g WSS_Content_Extranet</div>
</li>
<li>
<div>Finally, select which Search Server that should be used if you have more than one</div>
</li>
<li>
<div>Click <strong>OK</strong> to create the Web Application.</div>
</li>
<li>
<div>Click <strong>Create Site Collection </strong>to create the site collection to be hosted by the new Web App. Use the template and quota settings that are applicable in your environment, This Web Application will be used to host an partner collaboration site, so the <strong>Collaboration Portal</strong>-template is used.</div>
</li>
<li>
<div>Once the Site Collection is created, test that it can be accessed using the Host Header name you specified when the Web Application was created</div>
</li>
</ol>
<p><strong>Step 2: Extend the Web Application to facilitate external access for partners</strong></p>
<div>
<ol>
<li>
<div>In <strong>Central Administration</strong> navigate to <strong>Application Management</strong> </div>
</li>
<li>
<div>In the <strong>SharePoint Web Application Management</strong> section select <strong>Create or extend Web application</strong></div>
</li>
<li>
<div>Select <strong>Extend an existing new Web application </strong></div>
</li>
<li>
<div>In the <strong>IIS Web Site</strong> section opt to <strong>Create a new IIS web site</strong> and enter the required information, e.g:</div>
<ul>
<li>
<div>Description: SharePoint Extranet (Extranet Zone) &#8211; 80</div>
</li>
<li>
<div>Port: 80</div>
</li>
<li>
<div>Host Header: dmz.extranet.sharepointnotes.local</div>
</li>
<li>
<div>Path: use default</div>
</li>
</ul>
</li>
<li>
<div>For now, go with the default selections for <strong>Security Configuration</strong></div>
</li>
<li>
<div>In the <strong>Load Balanced URL </strong>change the <strong>URL</strong> to <a href="https://extranet.sharepointnotes.local/">https://extranet.sharepointnotes.local</a> and set the <strong>zone</strong> to <strong>Extranet</strong></div>
</li>
<li>Click <strong>OK</strong> to extend the Web Application.</li>
<li>The external partners will authenticate using AD and LDAP, but we&#8217;ll configure that in a later post</li>
<li>Go to the <strong>Operations</strong> section of <strong>Central Administration</strong> </li>
<li>In the <strong>Global configuration</strong> section<strong> </strong>click <strong>Alternate access mappings</strong> </li>
<li>Click <strong>Add Internal URLs </strong></li>
<li>Select the Extranet Web Application and the host header for the extended web app, in this case <a href="http://dmz.extranet.sharepointnotes.local/">http://dmz.extranet.sharepointnotes.local/</a></li>
<li>Assign the Internal URL to the <strong>Extranet</strong> zone and click <strong>Save</strong></li>
</ol>
</div>
<p>So far so good. Now we have the web application created and extended to use different zones. Next step is to use ISA Server 2006 to publish the Extranet for corporate users across the Internet.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointnotes.wordpress.com/61/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointnotes.wordpress.com/61/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointnotes.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointnotes.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointnotes.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointnotes.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointnotes.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointnotes.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointnotes.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointnotes.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointnotes.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointnotes.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointnotes.wordpress.com&blog=2431838&post=61&subd=sharepointnotes&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointnotes.wordpress.com/2008/03/02/sharepoint-extranet-solutions-with-isa-server-2006-part-2-creating-the-extranet-web-application/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2c8d3ef56b5236c477880d1f83e88af1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Christian Dam</media:title>
		</media:content>
	</item>
	</channel>
</rss>