Solved

Certificate Error in Outlook - Installed 3rd Party SSL Certificate

Posted on 2010-08-16
6
696 Views
Last Modified: 2012-05-10
I recently setup an SBS 2008 Server. I purchased a UCC SSL certificate from godaddy so that users connecting to the Exchange server via outlook Web Access or their Windows Mobile/iPhone would not receive a certificate error. After importing the certificate OWA and Mobile devices could connect to the public address without a certificate warning however local users connecting to the exchange server using Outlook receive a security alert with an error message stating that "the name on the security certificate is invalid or does not match the name of the site". If you click yes to proceed outlook opens and functions correctly. However every time you reopen outlook you get prompted with the same security alert.

I looked at the Microsoft knowledge base article 940726 (www.support.microsoft.com/kb/940726) which describes my problem however when I try to execute step 3, 4 and 5 of the resolution I receive the following error "the operation could not be preformed because the object... could not be found on domain controller…
0
Comment
Question by:oetcc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 33451064
If you have a local CA, issue a local certificate to exchange server and make sure that clients connect to exchange using local name not public.
0
 

Author Comment

by:oetcc
ID: 33451115
To clarify... I need to add the local domain name of the local network to the certificate. As an example: currently the certificate is issued to the domain owa.xyz.com. The local network domain name is xyz.local. Should I add xyz.local or sbssrv.xyz.local to the certificate? Where sbssrv is the name of the server?
0
 
LVL 34

Accepted Solution

by:
Shreedhar Ette earned 500 total points
ID: 33451136
Hi,

SAN/UCC Certificate with the following names in is a must for Exchange 2007:
- autodiscover.domainname.com

- owa.domainname.com (the URL used for Outlook Web Access)

- remote.domainname.com (used in SBS 2008)

- servername.domainname.local (the internal FQDN of your Exchange Server)

- SERVERNAME (NETBIOS Name of your Server)

Hope this helps,
Shree
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:oetcc
ID: 33451220
Do I need to create a new CSR request to add domains to my existing certificate?
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 33451439
I humbly disagree with Shree here. You don't need all of those (and in many cases you can't get Godaddy to issue a certificate with just a Netbios name, for example) so the problem is with how your internal outlook clients are finding your server.
In short, I'd guess you need to re-run the IAMW so that the various LDAP, DNS, and other records get properly updated and autodiscover uses the same domain name internally as it does externally. Then, certificate issue solved because it will no longer be a mismatch.
-Cliff
 
0
 
LVL 34

Expert Comment

by:Shreedhar Ette
ID: 33451441
Yes, you have too.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchnage ./. Sophos Web Application Firewall 5 15
Exchange 2013 Hybrid 5 45
Flush end users Deleted Items via PowerShell 2 26
exchange 13 17
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question