Solved

Autodiscover Service: DNS Entry?

Posted on 2010-09-13
9
824 Views
Last Modified: 2012-05-10
Guys,
I am opening this question just to get a simplified steps which i need to work on.

Scenario:
I have 4 domains in the forest : NA-EUR-PAC-JPN
All except NA have got a SAN certificate for Exchange with the entry for : Autodiscover.Domain.com
In addition to that, each domain has their own webmail URL Like:

EUR: eurmail.doamin.com
PAC:pacmail.doamin.com
JPN:jpnmail.domain.com
NA: webmail.domain.com

however except eur, all domains are using webmail.domain.com for webmail

Having said that...
on the internal DNS server we have a entry for autodiscover in domain.com which is pointed to a CAS box in NA.domain.com , however we do not have any entry for autodiscover in the external DNS zone. Considering that we still have sometime to upgrade our certs to SAN in NA.
I believe creating an entry in the external DNS for autodiscover which inturn will point to : webmail.domain.com/autodiscover/autodiscover.xml , which is also set as internal URI for autodiscover for the domain, can resolve security cert warning issue.
.

I am not sure if i have put the description in correct or in more descriptive manner...
But i wanted to knwo what can i do to get rid of security cert errors.

Please do not provide me the ref. links.
I need suggestions on steps which i need to carry out in my environment.

I will try my best to explain the situation again if required....
0
Comment
Question by:amku03
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
9 Comments
 
LVL 5

Expert Comment

by:michael_b_smith
ID: 33663151
Your suggestion sounds like the right idea; however, depending on your site configuration, you may suddenly find your users getting redirected to their local webmail servers (not necessarily a bad thing).

Have you run through www.testexchangeconnectivity.com and seen what it has to suggest?
0
 
LVL 32

Accepted Solution

by:
endital1097 earned 500 total points
ID: 33668206
you may want to read this
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_3585-Exchange-Autodiscover-and-Web-Services-OOF-and-OAB.html

the portion you need to look at is the outlook selecting a service connection point and the -AutoDiscoverSiteScope setting
i think that will answer you autodiscover issue
0
 

Author Comment

by:amku03
ID: 33668217
endital, do you maintain any blog ??
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 32

Expert Comment

by:endital1097
ID: 33668221
i just started and need to get it public
http://jimthemcp.blogspot.com
0
 

Author Comment

by:amku03
ID: 33668223
thanks for the ref. Will go through it and probably come back with some more questions for you or the forum....
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33668252
if your external dns server can handle srv records you have more options
http://support.microsoft.com/kb/940881
0
 

Author Comment

by:amku03
ID: 33668307
This is what I am looking to do ... SRV record in external DNS
This will be till the time we get a SAN cert.

Does this makes sense?
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33668340
exactly. create an srv that points to your webmail.domain.com A record
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33668344
internally you need to run
set-clientaccessserver CASname -AutodiscoverServiceInternalURI https://webmail.domain.com/Autodiscover/Autodiscover.xml

does not require the srv record internally
0

Featured Post

Enroll in July's Course of the Month

July's Course of the Month is now available! Enroll to learn HTML5 and prepare for certification. It's free for Premium Members, Team Accounts, and Qualified Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
Suggested Courses
Course of the Month2 days, 18 hours left to enroll

622 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question