# Browzer for MS Exchange OWA

**URL:** https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595
**Category:** BrowZer
**Created:** [May 21, 2024, 1:37pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595 "2024-05-21T13:37:36Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![ghibsch](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@ghibsch](https://openziti.discourse.group/u/ghibsch)
#### Post date: [May 21, 2024, 1:37pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/1 "2024-05-21T13:37:36Z")

</div>

I'm very interested in combining BrowZer with our on-prem Exchange server. IMO Exchange has a questionable history of security issues and using BrowZer to decouple it from the internet is a compelling idea.

I've got my OpenZiti overlay working. I believe I've got BrowZer working too. The bootstrapper starts, I login to the auth provider, and eventually I'm shown the login page for OWA. But the login process just loops. Put in password, click login, back to login page again.

I compared the network activity from a good (no browzer) login vs a browzer login. There's supposed to be a POST that returns a bunch of cookies. Those cookies are present in the next request which eventually loads the mailbox. In the browzer session the cookies don't come through and are absent on the following request.

I confirmed that OWA doesn't seem to care which FQDN I use to reach it. I setup a hosts file entry and ran a test w/o browzer. Works fine. It doesn't seem to mind being behind a reverse proxy.

Any thoughts or suggestions on how to debug this further or tweak browzer?

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [May 21, 2024, 2:34pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/2 "2024-05-21T14:34:07Z")

</div>

Hi @ghibsch,

Thanks for trying out browZer with your private Exchange/OWA. I'm excited you're doing this because this use case is one on our list that we haven't gotten to yet.

Which version of browZer are you running right now?

If you are willing, here are some suggestions that will help me troubleshoot (via private msgs):

- Set your client-side trace level to TRACE (set env var ZITI\_BROWZER\_RUNTIME\_LOGLEVEL=trace in bootstrapper), then open dev tools, go through the failing flow, then save the Console log and send it to me, and save the Network har file and send that to me.

---

<div class="post-metadata">

### Author: ![ghibsch](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@ghibsch](https://openziti.discourse.group/u/ghibsch)
#### Post date: [May 21, 2024, 2:56pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/3 "2024-05-21T14:56:59Z")

</div>

I'm happy to do what I can. I'll work up that trace and send your way.

BrowZer version appears to be 0.60.3. It's just the github zip file from main as of yesterday I think.

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [May 21, 2024, 3:03pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/4 "2024-05-21T15:03:08Z")

</div>

OK, you have the `latest`. I recently fixed a similar Cookie issue to what you described (in `0.60.2`), so wanted to make sure you had that fix.  
Also, see my "private Discourse chat" msg to you.

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [May 22, 2024, 3:04am UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/5 "2024-05-22T03:04:05Z")

</div>

Hey Bobby, I have good news... OWA over browZer is a reality... see below:

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/f/f2cfcd1d5779d9c9c717e73fa99e8a1794376968.png)

I have a bit more testing to do tomorrow (Wed) but I'll release the fix for you soon.

---

<div class="post-metadata">

### Author: ![ghibsch](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@ghibsch](https://openziti.discourse.group/u/ghibsch)
#### Post date: [May 22, 2024, 11:22am UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/6 "2024-05-22T11:22:58Z")

</div>

That's VERY good news! Thank you!

---

<div class="post-metadata">

### Author: ![ghibsch](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@ghibsch](https://openziti.discourse.group/u/ghibsch)
#### Post date: [May 24, 2024, 7:06pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/7 "2024-05-24T19:06:24Z")

</div>

I just updated to the latest browzer code from Github and OWA is working!

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [May 28, 2024, 2:25pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/8 "2024-05-28T14:25:59Z")

</div>

Terrific. Thanks for the update, Bobby.

---

<div class="post-metadata">

### Author: ![McGonagall666](https://avatars.discourse-cdn.com/v4/letter/m/51bf81/32.png) [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)
#### Post date: [February 24, 2025, 7:23am UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/9 "2025-02-24T07:23:46Z")

</div>

[browzer-cookie.txt](https://openziti.discourse.group/uploads/short-url/tLkU7NpbRwHdcYWUTU8l13UadzE.txt) (58.0 KB)  
Hello curt, I have a local service called zentao. You can search for this open source project on github. Currently, direct access is fine. You can access the login page through the browzer, but you cannot jump after entering the account and password and clicking login. This is my browzer trace record. I compared their interfaces and found that the cookie was not carried when the browzer accessed

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/e/e8487980b1224d1d3bec007cd165edad3ee4fdb1.png)  
 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/1/160274a3d5088a7df2976b0398c3437450b1c229.jpeg)

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [February 24, 2025, 2:55pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/10 "2025-02-24T14:55:28Z")

</div>

I'll take a peek at `zentao` under browZer today. Stand by.

---

<div class="post-metadata">

### Author: ![McGonagall666](https://avatars.discourse-cdn.com/v4/letter/m/51bf81/32.png) [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)
#### Post date: [March 5, 2025, 1:14am UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/11 "2025-03-05T01:14:24Z")

</div>

Hi, have you reproduced the problem of zentao being unable to log in? What help do I need?

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [March 5, 2025, 2:17pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/12 "2025-03-05T14:17:43Z")

</div>

I am on PTO this week, and will pick this up again when I return to the office next week.

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [March 11, 2025, 9:20pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/13 "2025-03-11T21:20:19Z")

</div>

I have reproduced the issue, and I see the problem. ZBR is doing an inappropriate transformation on the HTML returned from the request to ZenTao's `/index.php?m=user&f=refreshRandom` endpoint, which leads to bogus data being sent in the form data on the subsequent request to `/index.php?m=user&f=login`. I am working on a fix now.

---

<div class="post-metadata">

### Author: ![curt](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/curt/32/6_2.png) [@curt](https://openziti.discourse.group/u/curt)
#### Post date: [March 25, 2025, 1:28pm UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/14 "2025-03-25T13:28:14Z")

</div>

Please try the latest browZer release (0.83.0) and let us know if things have improved for you.

---

<div class="post-metadata">

### Author: ![McGonagall666](https://avatars.discourse-cdn.com/v4/letter/m/51bf81/32.png) [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)
#### Post date: [April 8, 2025, 3:43am UTC](https://openziti.discourse.group/t/browzer-for-ms-exchange-owa/2595/15 "2025-04-08T03:43:47Z")

</div>

@curt Sorry, there was a problem with the network at home some time ago, so I came to test the new version of browZer now

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/e/e19a196fb9e1de65fad6d9ce51f3aa4a53a95435.jpeg)

I used version 0.87.1, and the following error was prompted when accessing zentao

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/c/cc2f80e21045092f94221393a376ee8b82ce6934.jpeg)  
 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/c/cfb7ae7ae0588fb1b6fcce2f272108a26e8dce4b.png)

I changed to another test service and it can be accessed, but the situation is the same as the previous zentao, it cannot carry cookies and cannot jump

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/b/beefffda055c815d1879949dd4daaebead6409fd.png)  
 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/d/dea82a2a4ecdaf6cfad61c9de0aec82cabd57500.png)
