• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 741
  • Last Modified:

Exchange2007 certificates issue: "The name of the security certificate is invalid or does not match the name of the site"

Hi All,

Please have a look to the attached Image. The problem is  "The name of the security certificate is invalid or does not match the name of the site".

I have an exchange server 2007 (sp1) with the FQDN.  newserver.mycompany.local
DNS entry for newserver in mycompany.local fwd zone
A (record) ----- newserver.mycompany.local ----- 192.168.1.100
I have another A record entry in mycompany.com fwd zone
A (record) ------ mail1.mycompany.com ------- 192.168.1.100

I am facing this issue for last one week. I have followed the steps but no luck. So far what I can understand the issue is certificates are newserver but they are being recognized with mail1.mycompany.com but may be i am wrong or doing any minor mistake.

http://support.microsoft.com/kb/940726/en-us

Can any body help me ? Please mention if you need any outputs from me.
thanks,

 Outlook Error
0
sysbase
Asked:
sysbase
  • 6
  • 4
  • 3
  • +1
1 Solution
 
collins23Commented:
what certificate do you have configured in exchange ?
0
 
collins23Commented:
using the following procedure to change the exchange certificate to mail1.mycompany.com


http://www.sslshopper.com/article-how-to-use-ssl-certificates-with-exchange-2007.html
0
 
sysbaseAuthor Commented:
I am using selfsigned by default created certificated when we install exchange 2007.
0
Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

 
sysbaseAuthor Commented:
certificates*.....

On client side when we view the certificates it say certificate status is ok.

Details:
CN = newserver
DNS Name=newserver
DNS Name=newserver.mycompany.local
Enhanced Key Usage: Server Authentication (1.3.6.1.5.5.7.3.1)
Key usage: Digital Signature, Key Encipherment (a0)
Basic Constraints: Subject Type=End Entity; Path Length Constraint=None
Thumbprint algorithm: sha1


anything i can provide more to solve this issue?
0
 
Leon FesterSenior Solutions ArchitectCommented:
Is this certificate being installed on the Exchange Server? If yes, then don't use the FQDN.
The certificate must match the name of the host where it resides.
0
 
IvanSystem EngineerCommented:
Hi,

it seams that problem is with "Subject Alternative Name" field in certificates.
When creating certificate request have you used -DomainName part of command?
You can use it to specify more names for certificate such as...

New-ExchangeCertificate -DomainName newserver, newserver.mycompany.local, mail1, mycompany.local -Services SMTP or something like that

There is usefull link at http://technet.microsoft.com/en-us/library/bb851505(EXCHG.80).aspx 
0
 
sysbaseAuthor Commented:
Here is some more output if tht helps

[PS] C:\>Get-ExchangeCertificate  | fl


AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System
                     .Security.AccessControl.CryptoKeyAccessRule, System.Securi
                     ty.AccessControl.CryptoKeyAccessRule}
CertificateDomains : {newserver, newserver.mycompany.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=newserver
NotAfter           : 31/08/2011 11:48:47
NotBefore          : 31/08/2010 11:48:47
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 968586B5E0E0D48841B8537839961079
Services           : IMAP, POP, IIS, SMTP
Status             : Valid
Subject            : CN=newserver
Thumbprint         : 094ED70F1DB5DBA9957991A4AD8E357351213078


I think this is the problem ...  issuer is newserver and the certificates are installed with mail1.mycompany.com ...


what else I can look?
0
 
sysbaseAuthor Commented:
agreed with spriggan13 it will be ok if we have
CertificateDomains : {mail1, mail.mycompany.com, newserver, newserver.mycompany.local}
rather than
CertificateDomains : {newserver, newserver.mycompany.local}

how can we work on it ?
0
 
sysbaseAuthor Commented:
Would this be good approach to remvoe the existing certificates and then create and install new certificates?
any secure way to do that?
0
 
IvanSystem EngineerCommented:
Hi

I dont think there is any need for removing cert first, before creating new one.
If you generate a new and assigne it for services you need, than it should simple override curent cert and it will work.

First generate new cert (something like this + key lenght, subject name, export private key)

New-ExchangeCertificate -DomainName newserver, newserver.mycompany.local, mycompany.local,  mail1.mycompany.com, autodiscover.mycompany.local  -Services IMAP, POP, IIS, SMTP

Then enable new cert for services:

Enable-ExchangeCertificate (you will need thumbprint of new cert for this, wich you can get with Get-ExchangeCertificate  | fl command)

At the end you can remove old cert with Remove-ExchangeCertificate followed with thumbprint of old cert (094ED70F1DB5DBA9957991A4AD8E357351213078)
0
 
sysbaseAuthor Commented:
Hi spriqqan13,

Would you recommend to follow this URL
http://community.spiceworks.com/how_to/show/969

Waiting for a quick response.

Many thanks.

0
 
collins23Commented:
Yes, that procedure should work for you.
0
 
IvanSystem EngineerCommented:
Hi,

that link is ok.
 Basically you just need to generate cert the same way you did first time, but with that additional command " -DomainName newserver, newserver.mycompany.local, mycompany.local,  mail1.mycompany.com, autodiscover.mycompany.local " that will include all alternative names.

0
 
IvanSystem EngineerCommented:
If im not wrong this should be it.

New-ExchangeCertificate -KeySize 2048
-SubjectName "CN=newserver.mycompany.local, DC=mycompany, DC=local"
-DomainName newserver, newserver.mycompany.local, mycompany.local,  mail1.mycompany.com, autodiscover.mycompany.local
-PrivateKeyExportable $True


Enable-ExchangeCertificate "thumbprint" -services IIS, SMTP, POP, IMAP

Remove-ExchangeCertificate 094ED70F1DB5DBA9957991A4AD8E357351213078
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 6
  • 4
  • 3
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now