<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Can&amp;#39;t publish OWA web page - No signature found error</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/95012/can-t-publish-owa-web-page---no-signature-found-error</link><description>I&amp;#39;m migrating from TMG to Sophos firewall and I have faced a problem - I can&amp;#39;t setup the OWA webpage to work .. All rules set according to Sophos manual ( see : sophserv.sophos.com/.../Exchange WAF Guide - UTM 9.3 - Nov 2015.pdf). 
 ActiveSync service</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Can't publish OWA web page - No signature found error</title><link>https://community.sophos.com/thread/344787?ContentTypeID=1</link><pubDate>Fri, 18 Aug 2017 09:26:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:31e6661d-166d-4397-8bd7-5df811188a3b</guid><dc:creator>Michael Altynikov</dc:creator><description>&lt;p&gt;Hi Bob,&lt;/p&gt;
&lt;p&gt;Yes, Form hardening option is unchecked for this WAF profile ... and after adding &amp;quot;/owa*&amp;quot; exception the logging form began to appear. WAF probably does know how to handle form&amp;#39; url that looks like that &amp;quot;/owa_xxxxxxxxxx_form..&amp;quot;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can't publish OWA web page - No signature found error</title><link>https://community.sophos.com/thread/344657?ContentTypeID=1</link><pubDate>Thu, 17 Aug 2017 12:03:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3e128916-21d0-4b27-9435-e6043f0168c5</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Have you tried to skip form hardening for that Virtual Server?&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can't publish OWA web page - No signature found error</title><link>https://community.sophos.com/thread/344381?ContentTypeID=1</link><pubDate>Tue, 15 Aug 2017 13:45:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6f12b384-1108-455b-8610-9827ec476d3a</guid><dc:creator>Michael Altynikov</dc:creator><description>&lt;p&gt;Well, all OWA WAF rules have been set exactly according to that manual .. By the way, ActiveSync, that sat in the same WAF rule works fine .. autodiscovery rule - works too ..only OWA web page - does not ... :(&lt;/p&gt;
&lt;p&gt;Update: After adding additional exclusion like that &amp;quot;/owa*&amp;quot; the sophos default login form is finally start to appear when hitting &lt;a href="https://owa.domain.com/owa"&gt;https://owa.domain.com/owa&lt;/a&gt;&amp;nbsp;page .. but after entring login credentials popups a new window with login to owa web server ... Probably, there is a reverse auth problem... Still looking :)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Update2: After playing with URL hardening exceptions and Reverse Auth profiles here what I have found (Sophos Firmware version is 9.502-4):&lt;/p&gt;
&lt;p&gt;1. All OWA Sophos manuals define some URL exceptions to set, but in my case I needed to add one more URL exception &amp;quot;/owa*&amp;quot; (all manual says you only need &amp;quot;/owa/*&amp;quot; exclusion to work )&lt;/p&gt;
&lt;p&gt;2. After solving the problem of utm&amp;#39; frontend form authentication I have faced another problem - the backend auth to exchange server in case of OWA webpage account did not work (but ActiveSync and autodiscovery services work fine at that time). In my case there were 2 Reverse auth profiles (as it was written in OWA Sophos manual) one for form based and another for basic authentication method.&lt;/p&gt;
&lt;p&gt;In my case in the basic method form I have an Active Direct auth on fronend and basic on Real server backend with Suffix like &amp;quot;domain.com&amp;quot;. In that case the UTM form worked good, but the backend auth did not worked and the CAS server asked for login credential again... Long story in short - I have created another Reverse auth profile with different Domain Suffix like &amp;quot;@domain.com&amp;quot; .. for /owa and /ecp site path routes, and finally OWA webpage start to work properly.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So, maybe its a bug of reverse proxy mechanism?&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can't publish OWA web page - No signature found error</title><link>https://community.sophos.com/thread/344351?ContentTypeID=1</link><pubDate>Tue, 15 Aug 2017 09:15:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4c2885eb-8cd1-4576-a94d-98be91bc731d</guid><dc:creator>Shaun Raven</dc:creator><description>&lt;p&gt;Hi.&lt;/p&gt;
&lt;p&gt;I suggest checking your method against the one found here, which works fine.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://networkguy.de/?p=998"&gt;https://networkguy.de/?p=998&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>