Author Topic: EWS Setup with double Authentication Layer  (Read 8137 times)

berdesz

  • Newbie
  • *
  • Posts: 5
EWS Setup with double Authentication Layer
« on: June 27, 2015, 09:31:43 pm »
Dear Aquamail

I'm having a problem with your app atm. When I'm in the office and connected to corporate wifi, it works beaatifully. When outside in the office I'm required to put in my special account, which lets me login to the actual server.

Is there a way to do this or could you please implement this feature ?

Now I'm getting the HTTP1./4.0.1 Authentication error because of it. :(

Regards

A FAN


Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: EWS Setup with double Authentication Layer
« Reply #1 on: June 28, 2015, 10:19:51 pm »
Sorry, I don't know what "double Authentication Layer" is, can you provide the technical details?

Oh, and if your IT people are soooo seeeerious about "security", do they not mind your using a "non-certified" (whatever it means) mail app?
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

berdesz

  • Newbie
  • *
  • Posts: 5
Re: EWS Setup with double Authentication Layer
« Reply #2 on: June 29, 2015, 12:15:02 pm »
Double Authentication Layer means that you are prompted with a Login and Password before getting to the actual site. Its like a two step verification. And regarding the IT ppl, they don't mind, normally the process is you have to go VIA browser, login there with this 2 step verification method, then you can read your emails in the browser.

Or you can get an Iphone and you will get a specific software which gives you access directly to the server. (I'm not really an Apple FAN)

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: EWS Setup with double Authentication Layer
« Reply #3 on: July 02, 2015, 11:28:31 pm »
What I'm saying is -- I understand what it looks like to a user, but I have no idea about the technical bits.

Is it a third party "Corporate Security Shield" from Symantec, McAfee, etc. which works as an add-on to Exchange?

Something built into Exchange?

To the point: how is a mail app supposed to interact with it?
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

berdesz

  • Newbie
  • *
  • Posts: 5
Re: EWS Setup with double Authentication Layer
« Reply #4 on: July 03, 2015, 07:56:33 pm »
Its before I loging into the OWA.

I think easier to write down the process.

So I'm typing in the Outlook Web Access address into my browser.
Before I can access the site, a seperate authentication layer comes up, to type in a username and password.
When I typed that in, and the authentication is successful, then I will get into the OWA site, where I can put in my actual corporate login and password.

(I've attached a screenshot what kind of pop I get before I can login into the OWA site)
« Last Edit: July 03, 2015, 07:59:01 pm by berdesz »

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: EWS Setup with double Authentication Layer
« Reply #5 on: July 08, 2015, 01:21:37 am »
Looks like regular (not special in any way) authentication to me.

And I can't develop anything from screenshots, sorry.

If you can find and provide the technical details, I would be able to take a look.

But a screenshot is not much use, sorry.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

berdesz

  • Newbie
  • *
  • Posts: 5
Re: EWS Setup with double Authentication Layer
« Reply #6 on: July 19, 2015, 03:52:49 pm »
Sorry, I didn't wanted to "promote" any other programs on this site, but for example OWA for Android has this functionality. There it is called : Owa server protected by an extra layer of HTTP Authentication.

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: EWS Setup with double Authentication Layer
« Reply #7 on: July 19, 2015, 09:25:38 pm »
Knowing that "app A" or "app B" or "app Z" supports this feature does nothing to help me understand the underlying technology, which I'd need to implement in Aqua.

And, sorry, I just don't understand what "extra layer of HTTP authentication" means.

EWS (Exchange Web Services) is HTTP based already, and it uses authentication already (or else you'd not be getting *you* mailbox).

https://msdn.microsoft.com/en-us/library/office/dn626019(v=exchg.150).aspx

has three types of authentication: OAUTH, NTLM, and Basic.

AquaMail supports NTLM and Basic, but not OAUTH.

Does your corporate system require OAUTH?

Or maybe it requires the use of client certificates? This is another "security hardening" method, and is entirely different and unrelated to OAUTH.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

berdesz

  • Newbie
  • *
  • Posts: 5
Re: EWS Setup with double Authentication Layer
« Reply #8 on: July 30, 2015, 06:38:08 pm »
Judging by reading your link this should be Oauth. And it uses GeoTrust Global CA certificate.

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: EWS Setup with double Authentication Layer
« Reply #9 on: July 30, 2015, 09:26:38 pm »
The link describes all the available options.

So which one?

OAUTH has nothing to do with certificates. If it's OAUTH, that's one thing.

If it's "client side certificates", that's a different thing.

And one more thing -- can you or your IT people provide a test account for me? The only thing I have access to is Office 365.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/