Question

Certificate error with Outlook 2007 clients to Exchange 2007 server

Asked by: Aico

Hi,
I've got the following problem.

I'm currently migrating to an Exchange 2007 server. Whenever one of my Outlook 2007 clients connect to their mailbox on the Exchange 2007 server he gets the following message:

"Name on the Security Certificate is Invalid or Does Not Match the Name on the Certificate".

I've done some searching and I found the following article:

http://www.sembee.co.uk/archive/2007/01/21/36.aspx

In this article they recommend creating a new website with new virtual directories and assign it to a second IP-adress which you assign to your Exchange server. On this new website you can assign a certificate with the correct name and route your internal clients to it.

Now the following problem occurs: My Exchange 2007 server is also a domain controller. And you know what they say! Don't use a multihomed domain controller in your domain, because this means trouble!

So, does anybody have any idea how I can make my Outlook 2007 clients connect to their Exchange 2007 mailboxes without breaking down my Outlook web access and Mobile Access clients?

Kind regards,

Aico

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-03-05 at 05:26:23ID22428066
Tags

2007

,

certificate

,

outlook

,

error

,

exchange

Topics

Exchange Email Server

,

Outlook Groupware Software

Participating Experts
13
Points
500
Comments
26

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. SSL Certificates OWA/Mobile 5
    We currently use OWA in a server 2003 /Exchange 2003 sp2 environment: We use an internal certificate authority for SSL. My issues are: 1/ The certificate expires in 2 months and I would like to update to a purchased certificate. is this possible before the cert expires, a...
  2. Export SSL Root certificate to Windows Mobile
    I have this scenario: - one ISA server 2004 as a firewall and frontend for OWA and OMA - Exchange 2003 on LAN as mailserver - Windows Mobile smartphones (Qtek) I want to syncronize mail on my smartphones. The case is that I use a SSL certificate that is not trusted on the ...
  3. windows mobile sync problem (certificate is not valid)
    Hi All, I was trying to install certificate (issued by godaddy) on my treo750v using spaddcert but im getting error "This certificate is not valid root certificate. Please select a valid root certificate" The i have added the certificate using .cab file. It appears...
  4. Adding Certificate for Outlook mobile access
    I need to add a certificate to allow access to my Exchange server 2003 by a Verizon BlackBerry. We already have OWA running. Our Exchange is running behind an ISA 2004 box. What do I need to do to configue in both ISA and Exchange to add this certificate. I plan on buying a c...
  5. Exchange certificate
    I recently built exchange server 2007 and installed a digital certificate to allow activesync for mobile devices. Here is the setup: From the internet, the server is server.mycompany.net (digital certificate name) Internally, the server is server.mycompany.local (AD domain)....

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SembeePosted on 2007-03-05 at 07:30:38ID: 18654866

That is my article.

You are aware that it is not best practises to run Exchange on a domain controller? It should be run on a member server.

The method I have outlined is not dual homing. It is a second IP address on the server. Dual homing a DC is where there are two network cards connected to two different subnets. Running two IP addresses on the same domain controller when they are connected to the same LAN is not a problem, I have been doing it for years.

Simon.

 

by: busbarPosted on 2007-03-05 at 08:14:23ID: 18655215

Well,
I disagree with Sembee because you can use the following cmdlet to change the internal SCP and external SCP using the following cmdlet:
Set-WebServicesVirtualDirectory -Identity "EWS*" -ExternalUrl "Https://Contoso.mail.com/EWS/Exchange.asmx" -InternalUrl "Https://Contoso.mail.com/EWS/Exchange.asmx"

we used commercial Certificates and internal O12 and xternal O12 and IE users were able to connect with noe warning
if you are worry about the autodiscovery service only you can use the following cmdlet:
Set-ClientAccessServer -Identity <ClientAccessServerIdParameter> [-AutoDiscoverServiceInternalUri <Uri>] [-AutoDiscoverSiteScope <MultiValuedProperty>] [-DomainController <Fqdn>]  to set the internal URL to match the certificate

 

by: SembeePosted on 2007-03-05 at 09:45:49ID: 18655956

If you are using the same URL inside and outside then it is fine.
However the problem is that Outlook 2007 tries to connect to https://servername/
where servername is the real name of the server. You then get the error.

The blog posting was heavily researched and discussed with some of my other MVP peers. If your domain uses .local then the solution I have outlined is the only way I have found to get round all the issues with SSL, as I have not found anyone who will issue a certificate with a subject alternative name that contains a .local domain name.

Simon.

 

by: busbarPosted on 2007-03-05 at 10:13:43ID: 18656159

I know that this issue raised and i discussed it also with some MS consultants and MVP as well, and this drags us to the point, how O12 client locate the service point it is from AD?.
i will refer to the autodiscovery architecture in the following link:
http://msdn2.microsoft.com/en-us/library/bb204047.aspx
So if i updated the SCP in the AD to the external name and used properly managed split DNS infrastructure then i will be able to solve the problem because internal clients will be able to connect to the auto-discovery SCP using the external FQDN and will use the certificate bound to IIS (which contains external FQDN which users connect to it).
i used instructions and concepts explained in the following links:
·How to Configure the Availability Service for Network Load Balanced Computers
http://technet.microsoft.com/en-us/library/aa997237.aspx
·Deployment Considerations for the Autodiscover Service
http://technet.microsoft.com/en-us/library/aa997633.aspx
unless you want to use 2 certificates (1 for internal names and 1 for external names)
i used this configuration in my test and production environment and works great under Microsoft supervision unless there is something missing and i can't see it so i will kindly ask from you to explain it further from me.

Regards...

 

by: AicoPosted on 2007-03-06 at 00:36:34ID: 18660165

Thank you very much for all your input. Due to some time limitations I've chosen to follow Sembee's article (great article by the way!), despite of the fact that Exchange is running on a DC.

I've configured a second IP-address on the NIC and created the second website as described in your article and everything seems to be working fine uptill now. Even after a few reboots. Let's hope it stays that way.

Sembee, thank you for helping. The points will come your way!

 

by: AicoPosted on 2007-03-07 at 06:23:53ID: 18670191

Ok, guys. I did some more research and found that the following article solved all my problems, without having to assign a second IP-address or create a second website:

http://technet.microsoft.com/en-us/library/04284d82-b1cf-4582-b784-f5aaed5b23c9.aspx

It discusses how to assign multiple Host Names to 1 certificate. It works like a charm!

 

by: busbarPosted on 2007-03-07 at 06:56:12ID: 18670492

Yes AICO
but you can't use commercial certificate with multiple names i think that verisign don't allow that.
so this is why me and Sembee used our approches

 

by: pboustaniPosted on 2007-10-16 at 10:49:32ID: 20087503

We almost had it working this way, except we ran into the problem that the server would keep re-registering itself to our DNS. This server was a DC, not the PDC, but we have 4 DC in our org.

Anyways, it would keep registering the second IP address into dns. So we would have 2 entries in our DNS for the same IP address. And when Outlook 2007 would query the name of the server, it would randomly get one of the 2 IPs. If it got the wrong one, we got an SSL error as the second IP has a certificate with a different name than the host.

So now we're going the real way and getting a SAN certificate.

 

by: rimba_Posted on 2007-11-13 at 03:16:19ID: 20270719

you present some smarts solutions here.
I got the same problem and i found this solution more easy to apply:
First you create a new DNS zone in your DNS server using the address configured in your commercial certificate, lets say: mail.supermail.com
Then you create a  Host (A) type to point to your mail server´s IP : mail.supermail.com  192.168.0.5
Then you just change the following values thru the Exchange shell console:
Set-ClientAccessServer -Identity CAS_Server_Name -AutodiscoverServiceInternalUri https://mail.supermail.com/autodiscover/autodiscover.xml

Set-WebServicesVirtualDirectory -Identity "CAS_Server_Name\EWS (Default Web Site)" -InternalUrl https://mail.supermail.com/ews/exchange.asmx

Set-OABVirtualDirectory -Identity "CAS_Server_name\oab (Default Web Site)" -InternalUrl https://mail.supermail.com/oab

Set-UMVirtualDirectory -Identity "CAS_Server_Name\unifiedmessaging (Default Web Site)" -InternalUrl https://mail.supermail.com/unifiedmessaging/service.asmx

*please note that you must change: "CAS_Server_Name" to your exchange server name and mail.supermail.com with the correct address.

I hope this helps.

 

by: slypig61Posted on 2008-02-14 at 11:22:36ID: 20896267

Just wanted to add that the solution posted by rimaba worked like a charm.

Thanks!

 

by: rimba_Posted on 2008-02-15 at 00:30:26ID: 20900131

You re welcome!

 

by: scsiPosted on 2008-07-28 at 07:11:03ID: 22103280

This worked great for me also. I was getting two certificate errors though and still get an autodiscover.domainname.com certificate error, as i have multiple domains on my exchange server.

 

by: vit-joePosted on 2008-09-22 at 12:56:23ID: 22543427

rimba solution worked for me! thanks

 

by: rimba_Posted on 2008-09-23 at 02:52:54ID: 22547705

np ;)

 

by: BMRTPosted on 2008-11-18 at 17:19:54ID: 22990709

Hi rimba,
Thanks for your solution.
How do I create a new DNS zone in  DNS server using the address configured in commercial certificate if :
my domain: location.supermail.com  (mail server looks like : servername.location.supermail.com)
on certificate : mail.supermail.com

thanks.

 

by: rimba_Posted on 2008-11-19 at 02:21:31ID: 22992917

The new DNS zone have to be using the Certificate DNS name, regarding order internals subdomains. If they dont mach (certificate domain and new DNS Zone) you will get a certificate mismatch error.

 

by: keithdarlPosted on 2008-12-01 at 09:06:34ID: 23070319

We're in the process of trying Rimba's solution, just wanted to clarify, should we delete the default Microsoft certificate once the Commercial certificate has been applied?

thanks

 

by: rimba_Posted on 2008-12-02 at 00:36:57ID: 23075233

I believe only one cetifiticate can be used per domain, there fore it will be replaced on exchange configuration but it wont be deleted itself, I dont think it is neccesary tho

 

by: ZulanPosted on 2009-01-15 at 02:04:32ID: 23381916

Thanks Rimba!

 

by: Brigh-GuyPosted on 2009-09-21 at 10:25:09ID: 25385267

Rimba's solution looks pretty straight forward and matches MS's KB on the matter.  My one big question, though, is how will these changes affect Outlook clients that are currently pointing to the netbios name?  Will they automatically adjust or will each Outlook client have to be touched?  While the cert pop-up is annoying, it's not nearly as bad as a few hundred people without Outlook access would be.

Thanks,
Gabe

 

by: rimba_Posted on 2009-09-22 at 06:32:17ID: 25392544

the netbios shouldnt be afected by these changes since it is not ip related, the changes are for the http connection of aoutlook to the Exchange server not to resolver the server´s name itself.

I hope it helps

Rimba

 

by: Brigh-GuyPosted on 2009-09-22 at 06:36:46ID: 25392597

Rimba,

Maybe Netbios wasn't the best term for me to use.  What I'm getting at is:  All the Outlook 07 clients are pointing to hostname.domain.local.  If I make all the changes above to mail.domain.com, will this break all the currently set up Outlooks?

Thanks,
Gabe

 

by: rimba_Posted on 2009-09-22 at 06:40:00ID: 25392641

Actually both dns ll point to the same ip anyways.... :) so u can use the actual or the new dns name. (you are not deleting the old dns, only adding a new zone)

 

by: johnexpertneededPosted on 2010-06-25 at 20:00:07ID: 33077638

I found this worked great.

http://support.microsoft.com/kb/940726

 

by: UAVCommPosted on 2010-06-28 at 12:03:10ID: 33090021

Thank you Rimba - It worked great!

 

by: rimba_Posted on 2010-06-29 at 03:05:23ID: 33094429

you are welcome :)

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...