Solved

Exchange 2007 Certificate Principal Mismatch (Best Practices Anlyzer)

Posted on 2007-12-05
2
3,166 Views
Last Modified: 2012-05-05
We are setting up a new Exchange 2007 server and are running into a warning during the Best Practices Analyzer. The certificate we have created is a Comodo Multi-domain certificate that contains 4 names.

mail.mydomain.com (because Outlook 2007 requires it to work properly from what we have understood.)
autodiscover.mydomain.com (what people will be connecting to from the outside)
MX01 (name of the mail server in the domain)
MX01.mydomain.com (name of the mail server in the domain FQDN)


The error we get in the Best Practices Analyzer is this:
----------------------------------------------------
Certificate Principal Mismatch
The principal for SSL certificate 'https://mydomain.com' does not appear to match the host address. Host address: mydomain.com. Principal: C=SE, PostalCode=11641, S=STOCKHOLM, L=STO, STREET=Mystreet, O=MyCompanyname, OU=Management, OU=COMODO Multi-Domain SSL, CN=MX01.mydomain.com.
-------------------------------------------------


The command we issued to create the certificate request was:
-------------------------------------------------
New-ExchangeCertificate -generaterequest -subjectname "dc=com,dc=mydomain,o=Domain Controllers,cn=mydomain.com" -domainname mail.mydomain.com, MX01, MX01.mydomain.com,autodiscover.mydomain.com -PrivateKeyExportable $true -path c:\certrequest_mx01.txt
-------------------------------------------------


The certificate we get back from Comodo installed fine and from what I've seen so far both OWA and our older Outlook 2003 clients connect without any certificate warnings. Despite this we can't get rid of the warning in the analyze tool. Any ideas why this is? We have recalled the certificate and tried setting different domains as the primare name but this didn't help (we tried both mail.mydomain.com and MX01.mydomain.com as the primary). This might be nothing but I would really like to make sure before we go live with the system.

Thanks!
0
Comment
Question by:Debugger_systems
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Author Comment

by:Debugger_systems
ID: 20411010
> mail.mydomain.com (because Outlook 2007 requires it to work properly from what we have understood.)
> autodiscover.mydomain.com (what people will be connecting to from the outside)

Sorry, switched the explanations on those two. People will connect to "mail" and "autodiscover" is for Outlook 2006
0
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 20415267
BPA has been mentioning that error since version 1.0. I ignore it. No one has a certificate for domain.com - I don't know why Microsoft test for it.

Simon.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

742 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question