Reverse Proxy Certificate Requirements

When Mobility is being deployed as part of a new deployment or this functionality is being added to an existing environment, the key change to the reverse proxy solution is certificates. When the LyncDiscover service is being deployed through a reverse proxy, there are two possible solutions:

• Include LyncDiscover.<sipdomain> as a subject alternative name (SAN) entry on the web services public certificate. This can become costly when there are many SIP domains supported in the environment.

• Publish the LyncDiscover service over HTTP. When the service allows connections on port 80, the initial request will not be over TLS; clients are then redirected to the external web services FQDN for the Front End Server pool, resulting in no requirement for a LyncDiscover entry on the certificate.

Initial requests to the LyncDiscover service, whether they are over HTTPS or HTTP, are not authenticated; as such, there is not a great security risk with publishing this service over HTTP. The initial connection will simply be used to identify the full URL to connect to for the LyncDiscover service, and this information is given to connecting clients whether they connect over HTTP or HTTPS.

For details on configuring a reverse proxy for Lync Server 2013, see Chapter 12, “Firewall and Security Requirements.”

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset