{{letter}}

Загрузка

ASProxy

Mobile access to Exchange ActiveSync using certificates, with no VPN or MDM

Protecting MS Exchange

MS Exchange is a core communication platform tightly integrated into the MS Windows infrastructure. Compromising a mail server can lead not only to theft of confidential information, but also to a takeover of the entire domain infrastructure followed by its disruption.

Common issues when organizing mobile access to MS Exchange ActiveSync

Login and password are easily intercepted by a keylogger.

A user may reuse the same password for the corporate infrastructure and for personal services; a leak from those services may allow attackers to reuse the password to access the corporate environment.

Having compromised a password, an attacker gains access not only to correspondence, but also the ability to send malicious content directly to company employees via Exchange, bypassing mail gateways and sandboxes.

Exchange services may contain vulnerabilities that allow remote code execution. The proxyShell vulnerability is one example: it allowed an unauthenticated user to execute code remotely. Given the rapid development of AI for vulnerability discovery, history may well repeat itself.

The standard certificate-based authentication is usually implemented with ADCS, which is tightly integrated into the Active Directory infrastructure. If a user certificate is compromised, an attacker can gain access not only to mail, but also to other Windows resources, such as file servers, web applications and MSSQL databases.

Modern authentication adds multi-factor authentication, but does not address the possibility of exploiting vulnerabilities in Exchange services exposed to the Internet.

The corporate VPN must be activated to sync emails and calendar events.

Corporate and personal VPNs cannot run simultaneously.

Corporate and personal VPNs cannot run simultaneously.

Some specialized EMM solutions do not support multiple corporate mailboxes on a single mobile device.

EMM solutions typically containerize all content, including the calendar, which may inconvenience users when a calendar widget cannot be placed on the smartphone home screen.

Users may be skeptical about installing EMM/MDM solutions on their personal devices.

ASProxy is an mTLS reverse proxy for Exchange ActiveSync and EWS that performs the following tasks:

  • A self-service portal that lets users generate certificates not tied to the Active Directory infrastructure
  • mTLS authentication of users by certificate before proxying the request to Exchange
  • Access control per function: mail, attachment downloads, calendar and address book synchronization
  • A set of measures to protect the user certificate's private key from theft

Certificate generation and delivery to the user's device

  1. User authenticates on the web portal and requests a certificate
  2. A PFX container and QR code are generated
  3. Scanning the QR code, downloading the PFX (Android) or mobileconfig (iOS)
Generating a certificate for MS ActiveSync

To install the certificate, the user must enter a random password shown on screen during certificate generation; once the download limit is reached, the PFX container is deleted from the portal's memory

Installing a certificate for MS ActiveSync

Certificate-based access to Exchange

  1. mTLS authentication on NGINX
  2. Certificate and device checks
    • Certificate validity period, revocation status
    • Verification of the DeviceID and DeviceType identifiers associated with the certificate (binding happens on first use)
  3. Extracting the user account from the certificate, checking whether it is locked in Active Directory, retrieving group membership
  4. Access rights check based on configured profiles
  5. Generating the user's Kerberos ticket for the Exchange SPN (Constrained Delegation, S4U2Proxy)
  6. Proxying the request to Exchange, passing the Kerberos ticket as an SPNEGO token
Certificate-based access to Exchange

Settings required for ASProxy to operate

To enable generation of user Kerberos tickets for Exchange, a technical account must be created and configured for constrained delegation to the Exchange SPN

Configuring Kerberos Constrained Delegation

Kerberos authentication must also be enabled on the IIS endpoint serving ActiveSync

Configuring Kerberos on IIS

ASProxy supports multiple Exchange servers, both with a shared ASA account using the same SPN and without one

ASProxy capabilities

  • mTLS authentication and access control in front of Exchange
  • Protection of the certificate PFX container with a random password
  • Restricting the administrator's ability to remotely wipe the entire device
  • The certificate can only be used from the first activated device
  • Access control for mail, attachments, calendar and address book
  • Access from macOS via EWS using the built-in Mail app
  • OIDC integration for SSO
  • Integration with external 2FA (RADIUS, API)
  • SIEM integration (CEF)
  • Load balancing across Exchange servers (round robin)

Certificate authority settings

Access profile settings