Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Users cannot change password from OWA 1

Status
Not open for further replies.
Oct 2, 2002
104
0
0
US
We run an exchange 2000 server on windows 2000, most users use windows 20000, and IE 5.5 or better.

After logging on to OWA, users can check email no problem, but when they click options, then "change password"...
a pop up screen comes up that says page cannot be displayed... any ideas?
 
If I remember correctly, this occurs if you're not using SSL to access the OWA pages. To do so, install a current certificate on the exchange server, and point the users to https:// -vs- http://

But, it's been awhile since I had that problem. MapMan [americanflag]

Assume nothing, question everything, be explicit not implicit, and you'll always be covered.
 
How do I install certificates? And does SSL need to be installed on the client, or server, and where should it be installed?
 
SSL needs to run on the server. Also make sure your clients are connecting using a browser version that supports 128 bit encryption.

You simply direct your clients to a URL like


Notice the "s" in the http portion of the URL

For more step by step information on how to setup SSL on your exchange server try checking out this link.


Hope you find this useful.

Cheers,

JR JR

Tech Forums and news group user "Microgeek".
 
Just a thought for you - IIS Change Password is considerd a large security hole. I would not recommend enabling it. Microsoft has a utility called IISLockdown (or something similar***warning do not run this without understanding it*****) that will also disable this feature. My thoughts on this are only to express that this is a potential security flaw. My intent is not to scare you from doing it, I just want to pass along what I know.

Cheers! jamk555
 
Hi all!
Interesting stuff. I will look into those. I was curious does OWA run under exchange 2000 server is really vunerable to privacy. Once a domain user access the OWA website, they can just view any other domain user email by putting /user name at the end without entering the password? This is really strange
Love always,
KEvin zhang
Techncial Support specailist
kevin@hsmc.com
 
kevin

looks like your security settings aren't correct anymore,

check your security, as by default no user can access another users mailbox. (even admins can't)

someone is giving away rights......

/Bart
 
Evilbart,
That what I question the consulant lady who set up this up in the first place. It's so vunerable that even changing password in the active directory is useless. A temp who is able to get into the OWA can look into the management mailbox. I believe this occur only with IE 5.5 and not IE 6. BUt still, I would appreciate whoever encounter the same problem. Love always,
KEvin zhang
Techncial Support specailist
kevin@hsmc.com
 
"Once a domain user access the OWA website, they can just view any other domain user email by putting /user name at the end without entering the password? This is really strange"


Indeed only exchange admins should be able to do this, are you saying *any* user can switch into anyone elses mailbox?

Id make sure you have full IIS logging on OWA, auditing turned up and check event viewer :)
 
Dbrasco,
Good work!! yes indeed this is what happening withour exchange server. I have managment complaintts. anycase long story. .

Good I try to figure did those help or not Love always,
KEvin zhang
Techncial Support specailist
kevin@hsmc.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top