Microsoft Exchange Download Domains CVE 2021-1730


Product: Load Master

Version: all

Platform: all

Application: Microsoft Exchange

Setup download domains through Virtual service

Cause: Microsoft advisory on CVE-2021-1730

Create a new FQDN for a "Download Domain" such as "" and add this domain to your virtual directories in exchange. Create a new public certificate to use for this FQDN or add the new FQDN as a SAN entry to your existing public cert. Setup the DNS to point to a new dedicated Virtual Service on the LM and set it up either as pass-through or SSL offloaded/re-encrypted

With download domains there are 2 options. 

  1. To use download domains with SSL offloading you must have the same public cert on the LM Virtual Service as is on the Exchange servers themselves and it must have its own DNS entry (FQDN) and also have no ESP or pre-auth on the service. 
  2. The other option is to have a SSL pass through service on port 443 for the dedicated DNS name (FQDN) and have the public cert installed on the exchange servers directly.

on both options ESP is not supported for the download domains directory.




