Solved

Certification error connecting Outlook 2007/10 to Exchange 2007.

Posted on 2010-11-15
3
769 Views
Last Modified: 2012-08-13
Following on from another post i made:
HERE

I am having an issue with a certification error between my Outlook Clients and Exchange Server.

I enabled a purchased 3rd party UCC Certificate through Exchange Powershell to allow http over RPC from external. My initial problem was that I did not add all of the required alt names to my first cert. Now everything is working (external clients, OWA) but outlook clients are getting a certificate error on initial connection on our internal network.

The error is telling me that "the name on the security certificate is invalid or does not match the name of the site" and the site to which it is trying to cennect is "Sites"

Sites is a cname that SBS puts into DNS to resolve to it's IIS applications (e.g. http://sites/owa). I dont know why Outlook is coming back with this eror (it should be retrieving data from servername.domain.local, which is an alt name on my certificate).

I have even tried deleting my outlook profile and re-connecting to clear out any links that I may have previously created.

Any ideas why Outlook would connect to sites and get this error??

Outlook Certificate Error
0
Comment
Question by:noooodlez
  • 2
3 Comments
 
LVL 26

Expert Comment

by:e_aravind
ID: 34136004
Outlook uses the Exchnage and IIS to *fully* connect
For the autodiscover,EWS this will try using the cert. on the IIS

You could try configuring the URLs for the Autodiscover, EWS to see if you can avoid this warning
0
 
LVL 26

Accepted Solution

by:
e_aravind earned 500 total points
ID: 34136011
Security warning when you start Outlook 2007 and then connect to a mailbox that is hosted on a server that is running Exchange Server 2007 or Exchange Server 2010: "The name of the security certificate is invalid or does not match the name of the site"
http://support.microsoft.com/kb/940726
0
 

Author Comment

by:noooodlez
ID: 34136885
Hi, Cheers for getting back to me.

Sounds like the one. I have checked the locations of the XML files and they are valid URLs when I replace mail.contoso.com with the netbios name of the server.

Now I need to know how to configure. The kb article suggests I use mail.domain.com (the name on my certificate). If I use this internally I think I would need to either updated the hosts file or DNS!?

Should I use the netbios name (simpler config) or the mail.domain.com, and make that resolve to the exchange server nic? Will the netbios name cause problems further down the line?

Is there any way I can back up this config in case I need to revert back?

Many Thanks.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now