Solved

SSL Web server issues with incorrect cert OWA

Posted on 2006-11-13
7
200 Views
Last Modified: 2010-04-18
Currently we has a ssl cert installed that has been registers with the CA.  We have it installed on our exchange server for a secured OWA connection.  the cert is mail.domainA.com.  The problem i am having is that we have an internal website that we have create to allow users to connect to OWA as well.  When we try and use https://mail.domainA.com as the link it just flashes and does not allow the user to connect.  If we set it up as https://mailserver/exchange, it works great but the ssl doesn't match so it gives a warning that you have to click yes to.  I have also tried https://mail.domainA.com/exchange, this gets to the login page without the ssl warning but doesn't allow you to login.

i guess my question is... can i add another cert from the webserver to the exchange server so there is no certificate error?

I am using the forms base authentication.

hope someone can help!
0
Comment
Question by:lgropper
  • 4
  • 3
7 Comments
 
LVL 25

Accepted Solution

by:
mikeleebrla earned 300 total points
ID: 17933301
this is yet another reason not to use different internal and external domain names.  But anyway, when you are on your lan and you go to https://mail.domainA.com/exchange, what IP address is it going to? the internal or external?  if you do nslookup mail.domaina.com it should tell you.  You shouldn't have to create another certificate if you properly setup your DNS so that you can reach your email server via its registered external domain internally (since that is the FQDN that you created the certificate for, it should work.

0
 

Author Comment

by:lgropper
ID: 17938695
it seems nslookup is saying the it can't find the name of the server.  It finds the ip of the DNS server but no name.  DNS is setup correctly and there is a ptr record for the dns server.  This is definitely the issue, i'm trying to track down the problem.  I have numerous other servers on the same subnet with the same settings and nslookup works fine.
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17938787
all that means is that you dont have a reverse DNS record for YOUR internal DNS server (assuming you are pointed to your internal DNS server)

think about it.  why would NSLOOKUP need to find the name of the server since YOU inputed the name of the server and you are asking it for the IP.

this really has nothing to do with the cert however.

0
Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

 

Author Comment

by:lgropper
ID: 17949591
thats the thing though, i do have one.  i have 5 other servers that don't have an issue looking up the name of the server. all the dns settings are the same across all servers.
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17949616
can you post the exact results you get from the nslookup please?
0
 

Author Comment

by:lgropper
ID: 17949648
This is from the server i am having issues.

C:\>nslookup
DNS request timed out.
    timeout was 2 seconds.
*** Can't find server name for address 192.160.100.13: Timed out
Default Server:  UnKnown
Address:  192.160.100.13

this is on another server in the same subnet and domain.

H:\>nslookup
Default Server:  server1.domainA.com
Address:  192.168.100.13

Please note i changed the servername as i don't want to post ours.
0
 

Author Comment

by:lgropper
ID: 17949790
i found the issue... long days and nights have typo's... dns server was wrong!

thanks for the point in the corret direction.

chad
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

827 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question