Solved

Outlook 2007 Cert/RPC over HTTP issue

Posted on 2010-09-20
13
669 Views
Last Modified: 2012-05-10
The sales team at a client’s company are using RPC over HTTP in outlook 2007 to connect to their emails from home. In outlook 2003 this always has and still does work fine. However they are now getting a certificate error (attached)
The interesting this is this is only happening in this version of outlook for machines that are attached to the corporate domain. If the machine is in a workgroup there is no issue.
The MSSTD proxy is set to the CN of the certificate but still we are getting errors. Short of turning the proxy feature off within exchange I am out of ideas. Any help would be much appreciated.
 Certificate Error
0
Comment
Question by:lil_dan
  • 5
  • 4
  • 2
13 Comments
 
LVL 26

Expert Comment

by:e_aravind
ID: 33716747
0
 

Author Comment

by:lil_dan
ID: 33716820
mail.pensionsfirst.com is working from the internet and internally, im not sure you are meant to hit a page when browsing to rpcproxy.dll are you?
0
 

Author Comment

by:lil_dan
ID: 33716865
Actually when browsing the dll it prompts for a username and password and authenticates successfully using corporate username and pw combination - both internet and internal.  
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 32

Expert Comment

by:endital1097
ID: 33717267
0
 
LVL 26

Expert Comment

by:e_aravind
ID: 33718550
Just curious, if you run
Set-OutlookProvider -Identity EXPR none

Note: its not $null but none and try to repair the OL2k7 profiles ...then test against the exchange server
0
 

Author Comment

by:lil_dan
ID: 33723512
The results from the article are as follows

Get-ExchangeCertificate | where { $_.Services.ToString(
).Contains("IIS") -eq $true } | fl Cert*


CertificateDomains : {ftp.pensionsfirst.com, mail.pensionsfirst.com}
CertificateRequest :

Get-ClientAccessServer uklonsvrex1 | fl AutoDiscoverSer
viceInternalUri


AutoDiscoverServiceInternalUri : https://mail.pensionsfirst.com/autodiscover/au
                                 todiscover.xml


Get-WebServicesVirtualDirectory | fl *Url


InternalNLBBypassUrl : https://uklonsvrex1.corp.pf.com/ews/exchange.asmx
InternalUrl          : https://mail.pensionsfirst.com/ews/exchange.asmx
ExternalUrl          :

Get-OabVirtualDirectory | fl *Url


InternalUrl : http://uklonsvrex1.corp.pf.com/OAB
ExternalUrl :


Get-AutodiscoverVirtualDirectory | fl *Url


InternalUrl :
ExternalUrl :


Get-OutlookAnywhere | fl External*


ExternalHostname : mail.pensionsfirst.com

Unfortunatley the Set-OutlookProvider -Identity EXPR none
 returns:

Set-OutlookProvider : A parameter cannot be found that matches parameter name '
none'.
At line:1 char:20
+ Set-OutlookProvider  <<<< -Identity EXPR none

and Set-OutlookProvider -Identity EXPR returns

WARNING: The command completed successfully but no settings of 'EXPR' have been
 modified.

either way its not working still. Thanks for your help so far - any further assistance would be really appreciated! :)

0
 
LVL 32

Expert Comment

by:endital1097
ID: 33724047
you need to update your oab vdir

set-oabvirtualdirectory oab* -InternalUrl https://mail.pensionsfirst.com/oab
0
 
LVL 32

Accepted Solution

by:
endital1097 earned 500 total points
ID: 33724061
also post the results from
get-outlookprovider expr | fl

server and certprincipalname should both be blank
if either are not run

set-outlookprovider expr -server $null -certprincipalname $null
0
 

Author Comment

by:lil_dan
ID: 33724586
@endital1097 - Should the cert pincipal name not be that of the cert with a prefix of msstd: ?
This means i can tick the "only connect to proxy servers with this principal name" box in outlook, ensuring the security of the connection does it not?
msstd.jpg
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33735252
no, this certprincipalname value should be blank except for a few circumstances
your configuration does not require a value
0
 

Author Closing Comment

by:lil_dan
ID: 33754306
The solution is a work around that fixes the problem - the issue is it allows people to connect without selecting SSL proxy settings within outlook, which in turn creates a security risk. However if you are looking for quick fix this definitely works.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question