[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

9.2

Work around for certificate errors on internal clients using Ex2K7 via Outlook 2K7?

Asked by stedwardsitdept in Exchange Email Server

Tags: Exchange 2007, client access server, certificate, Outlook 2007, site name, error, mismatch

This may be a bit long winded so my apologies in advance!
We have a rather sticky problem with certificates on our new Exchange 2007 Client Access server set up. We are currently in the process of trying to migrate from Ex2K3 to Ex2K7. We've moved a few test clients over to the new Ex2K7 server and they are all getting certificate errors when Outlook 2007 starts up on domain joined machines (internal clients). The error states that the site name that Outlook is looking for is different from what is on the cert. And it is correct. Here is the whole sorry saga of our certificate tragedy:
We are a school in the UK. We have a publicly registered domain name that ends with .sch.uk. Our internal/private AD domain name is nearly identical to our public domain name and also ends in .sch.uk (dont ask, this was before my time) and looks very much like a public domain name. Because of this, we were unable to find a single commercial certificate provider that would include our internal FQDNs to any UCC certificate we wanted. In the end, we ended up purchasing a Digicert UCC cert that had only our external FQDNs for the CAS server and autodiscover services. We tried to work around this problem by enabling both our commercial cert as well as the default MS cert that ships with Ex2K7 which we added all of our internal FQDNs to. The hope was that the external clients would be able to use the commercial cert, while the internal clients would be able to use the default simple cert. This seemed to work for a brief time, but after a few weeks, Outlook 2K7 on the internal clients began ignoring the internal certificate and started using the commercial cert which, of course, didn't have any of the internal information on it and hence they started getting the certificate error on startup. After much wrestling with this issue, we made the decision to register our internal domain name so that we could provide Digicert with a "whois" for it and they would then be happy to add our internal FQDNs to our commercial cert. However, I then spoke to Nominet and was told that we could NOT register our internal domain name because it has the .sch.uk suffix and since we already have one .sch.uk domain name registered, we can't register another one.
We've been given two options by certificate providers, domain name registrants and Nominet alike:
1. Rename our external domain name so that it is the same as our internal domain name
2. Rename our internal domain name to use a suffix like .int or .local
Neither of these options is even slightly appealing to us so we are desperately trying to find a work-around.
I am now aware that having two active certificates running on the same CAS server is not supported. Is it possible to have two CAS servers in the same organisation and to force internal clients to use a specific one for autodiscover? If so, we could set the two up and just have the Digicert commercial cert on one for external access and have the MS default cert enabled on the other for internal access.
Any other thoughts or ideas would be greatly appreciated.  Many thanks,
Adam
 
Related Solutions
Keywords: Work around for certificate errors on in…
 
Loading Advertisement...
 
[+][-]11/03/09 05:09 AM, ID: 25728521Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zone: Exchange Email Server
Tags: Exchange 2007, client access server, certificate, Outlook 2007, site name, error, mismatch
Sign Up Now!
Solution Provided By: saakar_rao
Participating Experts: 1
Solution Grade: A
 
[+][-]11/03/09 08:12 AM, ID: 25730422Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81 - Hierarchy / EE_QW_3_20080625