16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 27: Securing an Extranet Using SSL <strong>and</strong> Certificates 739<br />

1. On the Site Settings page, in the User Profile, Audiences, <strong>and</strong> Personal Sites<br />

section, click Manage profile database.<br />

2. On the Manage Profile Database page, in the Profile <strong>and</strong> Import Settings<br />

section, click the link next to Source of user set.<br />

3. On the Configure Profile Import page, in the Source section, click Custom<br />

source, <strong>and</strong> then click OK.<br />

4. On the Manage Connections page, rest the pointer on the name of your connection,<br />

click the arrow that appears, <strong>and</strong> then click Edit on the menu that appears.<br />

5. On the Edit Connection page, in the Connection Settings section, ensure that<br />

the Use SSL-secured connection check box is selected.<br />

6. Click OK.<br />

Note You must have secure LDAP enabled on your domain. For instructions<br />

on configuring secure LDAP, refer to http://go.microsoft.com/fwlink<br />

/?LinkId=20732 <strong>and</strong> http://go.microsoft.com/fwlink/?LinkId=20735.<br />

To require client certificates (optional)<br />

This step is optional. You might require client certificates to provide additional<br />

security for accessing your portal site from outside the firewall. When you request<br />

certificates from the clients, it means that clients that do not have certificates<br />

installed will not be able to access the portal site. For example, you might require<br />

client certificates if you need a stronger two-level authentication, in which clients<br />

are required to provide something they have (a certificate) <strong>and</strong> users are asked to<br />

provide something they know (authentication credentials).<br />

To require client certificates, do the following on each front-end Web server:<br />

1. Open Internet Information Services (IIS) Manager. In the Internet Information<br />

Services management console, exp<strong>and</strong> the tree view, <strong>and</strong> then exp<strong>and</strong> Web<br />

Sites. Right-click Default Web Site, <strong>and</strong> then click Properties.<br />

2. Click the Directory Security tab.<br />

3. In the Secure communications section, click Edit.<br />

4. In the Secure Communications dialog box, make sure the Require secure<br />

channel (SSL) check box is selected, <strong>and</strong> in the Client certificates section,<br />

click Require client certificates.<br />

5. Click OK to close the Secure Communications dialog box, <strong>and</strong> then click<br />

OK to close the Default Web Site Properties page.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!