Question

Why are my internal Outlook 2K7 clients getting certificate errors when connecting to Exch2K7?

Asked by: stedwardsitdept

Hello all. We are experiencing a problem where our internal Outlook 2007
clients are reporting a certificate error on startup/connection to our
Exchange 2007 server. Here is a brief overview of our setup:
Domain: Windows Server 2003 AD domain with 2 DCs running Windows Server 2008 (64)
Exchange setup: 1 member server running Server 2008 (64) w/ 1 HUB Server and
1 Mailbox Server - 1 member server running Server 2008 (64) w/ 1 CAS server. (All Exchange 2007 SP1).
On the CAS server, we've implemented 2 certificates. One is a 3rd party SAN cert containing all necessary
names for external access (which is working fine). We've also enabled the default simple cert that ships with Ex2K7 strictly for internal clients. We've done this because our external domain name is different than our internal domain name. This saved us quite a bit of money on the 3rd party cert what with not having to add the internal names to it. I read several posts at the Exchange Teams blog that gave me the impression that this would work fine as that cert would be trusted on the internal domain.
Now for the issue at hand - when an internal client w/ Outlook 2K7 opens
Outlook, they receive a cert error (twice) stating that the name on the cert doesn't
match the name of the site. When you view the cert, it is showing the external site name, not the internal localhost name of the CAS server. I've checked
both certs on the CAS server: both are correct and valid and the internal cert
does list both the internal NETBIOS and FQDN names of the CAS server. I've also checked
the SCP and it too is listing the correct internal names for the CAS server.
I've run "test-outlookwebservices -identity <my username>" and it only returns one error:
Id      : 1005
Type    : Error
Message : When accessing https://<localhostname>/Autodiscover/
          Autodiscover.xml the error "RemoteCertificateNameMismatch:CN=<here it lists the information that is on our extrnal certificate>" was reported.

Any help would be greatly appreciated.
Adam

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-10-28 at 08:09:54ID24851241
Tags

Outlook 2007

,

certificates

,

Exchange 2007

Topic

Exchange Email Server

Participating Experts
3
Points
500
Comments
13

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Certificate issue
    After adding a Geotrust certificate to the exchange server for use with OWA and Active sync for the PDA's I get an error when opening my Outlook using office 2007. When adding the certificate I did remove the default certificate that is created when you install Exchange. the ...
  2. Using Wildcard SSL certificates with ADAM
    We are using ADAM and I created a SSL certiciate and installed it via the instructions Microsoft gave on using ADAM over SSL. I was able to test it via LDP and it worked on the port we specified 9637. I want to be able to use a wildcard ssl certificate with the same usage...
  3. Exchange 2007 SSL Certificate Issue
    I just purchased a new SSL certificate to secure our Exchange environment. I created the cert request file using IIS, received the new certificate, installed via IIS, and all was working fine for Outlook Anywhere. I connect to the server via IMAP on my iPhone, and noticed tha...
  4. Exchange certificate to enable outlook anywhere
    Hi, I have exchange 2007 server installed in windows 2003 server. Now i want to enable outlook anywhere. So from IIS I created a certificate request and sent to CA authority and got 1 month temporary license. Imported the same. But now from outside i can access the outlook a...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: demazterPosted on 2009-10-28 at 08:17:33ID: 25684182

Your receiving it because the autodiscover service has not been configured correctly.

Mestha has a post here explaining what needs to be done: http://www.amset.info/exchange/singlenamessl.asp

 

by: jjdurrantPosted on 2009-10-28 at 08:24:55ID: 25684287

 

by: shauncroucherPosted on 2009-10-28 at 08:28:40ID: 25684337

Run through and check all the URL's and change any that don't look correct to you.

http://exchangeshell.wordpress.com/2009/10/17/exchange-2007-internal-and-external-url-urls-autodiscover-availability-imap-pop3-oof-oab

Also, I don't think using 2 certificates is a supported setup for the services provided by the CAS server, such as Autodiscover. You can only have 1 certificate attached to IIS (by using Enable-ExchangeCertificate), which one are you using?

Shaun

 

by: shauncroucherPosted on 2009-10-28 at 08:30:49ID: 25684363

Also, how much money can be saved? A SAN certificate valid for 5 years is £150-£200 or less nowadays.

Shaun

 

by: jjdurrantPosted on 2009-10-28 at 08:31:48ID: 25684378

Right.. you definately want a UC\SAN cert.. $60 a yea from https://DomainsForExchange.net/

 

by: stedwardsitdeptPosted on 2009-10-29 at 07:13:59ID: 25693871

Thanks for all the speedy replies all. Sorry it's taken so long to get back to you. Been trying to digest the wealth of info provided.
Just to provide some additional quick info:
My memory was failing me a bit on my initial post regarding our certificates. It wasn't down to saving money on the cert that we didn't have the netbios and internal fqdn of our CAS server added to the external SAN cert; it was because the cert provider, Digicert (and, for that matter, serveral other providers that we looked at), refused to add them (well, the FQDN anyway) to the cert because our internal domain name looks very similar to our external domain name. In fact, they are only different by one character! Don't ask me why, I know it's daft but this was all done before my time. Basically, every cert provider we looked at said pretty much the same thing: our internal domain name looks too much like a public domain name and that we either needed to register our internal domain name or change it to a .local name, neither of which we (well, my boss anyway) are willing to do. So we really had no choice but to go with having two certs; the Digicert SAN certificate for external access, and the default Ex2K7 single name cert for internal access.
shauncroucher - to answer your question, we've only got the IIS service enabled on the SAN cert (our Digicert external certificate).
If we added an SRV record to our internal DNS server that resolved our external name (mail1.ourexternaldomainname.com) to the internal IP address of the CAS server, would this help at all?

 

by: stedwardsitdeptPosted on 2009-10-29 at 08:21:52ID: 25694681

Disregard my last question...was getting desperate but no it won't work.
Is there a way of disabling the autodiscover service for internal clients and is this even something we'd want to try?
Thanks,
Adam

 

by: shauncroucherPosted on 2009-10-29 at 08:28:50ID: 25694777

In my experience you need to have both external and internal URL's on one certificate, and this certificate should then be used for IIS.

You may be able to fiddle with the URL's and SCP. If you set the internal DNS to use Split DNS (where you have a zone set up for your external domain URL's to resolve to internal IP's) and set all Internal URL's to the external URL in the certificate it may work but I just don't know, it is pretty far off normal design.

Shaun

 

by: stedwardsitdeptPosted on 2009-10-29 at 09:06:14ID: 25695160

After more trolling, it doesn't appear that you can disable the autodiscover service for internal clients (at least, not that I've found). Doesn't sound like a good idea anyway. Not sure the split dns option will work either but thanks for the suggestion shaun. Seems we're in quite the pickle. If you have any other idea's please do let me know. Will keep checking back.

 

by: shauncroucherPosted on 2009-10-29 at 09:12:41ID: 25695233

How about buying that domain name, it will probably only be £10 a year, then you can create a certificate with those entries. Still not great if they are not true Internal names though. If you buy the domain, there will be an external presence for it.

Shaun

 

by: stedwardsitdeptPosted on 2009-10-30 at 04:03:24ID: 25701723

Shauncroucher:
Going to go ahead and mark your last entry as the accepted solution. This looks very much like what we are going to be doing. Made the decision last night to contact Nominet today and discuss prices/fees. Once we can get a valid "whois" for our internal domain, we'll be able to have Digicert verify it and add the FQDN to our external cert. Seems like the only way to rectify this. Thanks all.
Adam

 

by: stedwardsitdeptPosted on 2009-10-30 at 04:06:43ID: 31647022

Shauncroucher's suggestion coincided with our own. He offered several different and very viable suggestions for a solution.

 

by: stedwardsitdeptPosted on 2009-10-30 at 04:07:55ID: 25701753

Hope I did alright with the ranking. First time doing this. Let me know if any complaints.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...