Solved

AutoDiscover Certificate gives warning error from computers outside the network

Posted on 2010-09-15
3
867 Views
Last Modified: 2012-06-21
I'm running Exchange 2007.  When Outlook users from outside our network open Outlook they receive a certificate warning.  It says that the certificate is valid and trusted, but "the name of the security certificate is invalid or does not match the name of the site".  I have two CAS servers configured with NLB.  My certificates has 3 names, cas1.domain.edu, cas2,domain.edu, jointname.domain.edu.  In DNS,  the autodiscover alias points to jointname.domain.edu.  I assume the warning is because it tries to use autodiscover.domain.edu and this isn't an actual altername name.  I've tried adding an SRV records per article:
http://support.microsoft.com/kb/940881, but it doesn't change anything.  I assume that is because the original attempt doesn't outright fail so that is tries the SRV record.  Aside from buying new certificates, doesn't anyone know how to make the warning go away. Outlook inside my network works fine - as does OWA.  This is specifcally related to Outlook Anywhere.
My test client is Outlook 2007, and think it will suffice to alleviate the warning just for Outlook 2007 if that is possible.
Thanks.
0
Comment
Question by:apsutechteam
3 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 167 total points
ID: 33687194
0
 
LVL 19

Assisted Solution

by:R--R
R--R earned 166 total points
ID: 33687261
0
 
LVL 58

Assisted Solution

by:tigermatt
tigermatt earned 167 total points
ID: 33687425

The problem is indeed your SSL certificate.

The underlying DNS infrastructure which maps autodiscover to jointname has no relevance when it comes to certificate trust. As far as Outlook and the cryptography system is concerned, the connection is to autodiscover.domain.edu so that name MUST be listed on the certificate.

If you create a SRV record to map to your jointname.domain.edu, you need to remove the old CNAME and allow time for the changes to propagate through DNS. Outlook only resorts to SRV records if conventional autodiscover.domain.edu fails, and it must be Outlook SP1 or higher.

I personally do not like the SRV record approach. Your public DNS provider must support it (many don't) and for the cost, it's much easier to replace the certificates.

-Matt
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

"Migrate" an SMTP relay receive connector to a new server using info from an old server.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now