Solved

AutoDiscover Certificate gives warning error from computers outside the network

Posted on 2010-09-15
3
870 Views
Last Modified: 2012-06-21
I'm running Exchange 2007.  When Outlook users from outside our network open Outlook they receive a certificate warning.  It says that the certificate is valid and trusted, but "the name of the security certificate is invalid or does not match the name of the site".  I have two CAS servers configured with NLB.  My certificates has 3 names, cas1.domain.edu, cas2,domain.edu, jointname.domain.edu.  In DNS,  the autodiscover alias points to jointname.domain.edu.  I assume the warning is because it tries to use autodiscover.domain.edu and this isn't an actual altername name.  I've tried adding an SRV records per article:
http://support.microsoft.com/kb/940881, but it doesn't change anything.  I assume that is because the original attempt doesn't outright fail so that is tries the SRV record.  Aside from buying new certificates, doesn't anyone know how to make the warning go away. Outlook inside my network works fine - as does OWA.  This is specifcally related to Outlook Anywhere.
My test client is Outlook 2007, and think it will suffice to alleviate the warning just for Outlook 2007 if that is possible.
Thanks.
0
Comment
Question by:apsutechteam
3 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 167 total points
ID: 33687194
0
 
LVL 19

Assisted Solution

by:R--R
R--R earned 166 total points
ID: 33687261
0
 
LVL 58

Assisted Solution

by:tigermatt
tigermatt earned 167 total points
ID: 33687425

The problem is indeed your SSL certificate.

The underlying DNS infrastructure which maps autodiscover to jointname has no relevance when it comes to certificate trust. As far as Outlook and the cryptography system is concerned, the connection is to autodiscover.domain.edu so that name MUST be listed on the certificate.

If you create a SRV record to map to your jointname.domain.edu, you need to remove the old CNAME and allow time for the changes to propagate through DNS. Outlook only resorts to SRV records if conventional autodiscover.domain.edu fails, and it must be Outlook SP1 or higher.

I personally do not like the SRV record approach. Your public DNS provider must support it (many don't) and for the cost, it's much easier to replace the certificates.

-Matt
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question