Avatar of isilva
isilva
 asked on

Autodiscover

Hello,

Just installed an SBS2008/Exchange 2007.  Autodiscover test (testexchangeconnectivity.com) continues to fail.  Outlook connected (interntally) conitnues to get popup to enter user name and password.  
Autodiscover.domain.com has been added (host) to point to the public (static) IP address and have also opened up the ports on the router.  

I have installed a basic (single) SSL cert from Godaddy and installed with no issues.  

Issues:  
*Autodiscover test fails (testexchagenconnectivity.com)

*Outlook continues to prompt for user name and password when connecting on the local network.
Note:  if you close the login prompt, exchange remains connected to exchange.

Receive (security alert) - Information you exchange with this site cannot be viewed or changed by others........
(two green checks for - This security cetificate is trusted.....-The security certificate is valid.
One red X on - The name on the security certificate is invalid or does not match the name of the site

ExchangeSBS

Avatar of undefined
Last Comment
jjoz

8/22/2022 - Mon
mittermueller

Your certificate does not include the autodiscover hostname...
MegaNuk3

Mittermuller is right, your cert doesn't include the autodiscover.yourdomain.com subject

Other than that ensure you install at least E2k7 SP2 (SP3 is out) as that resolves several password prompt issues
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
isilva

ASKER
MitterMueller - Does that mean I have to purchase another cert?  Should I have purchased a multiple domain cert?  

mittermueller

the certificate needs to to have multiple hostnames in it (not domains). So the certificate will respond to all hostnames of that server (e.g. msdc01, msdc01.mydomain.local, msdc01.dyndns.org, autodiscover.mydomain.local,
mydomain.local, etc.).

Maybe you can get Godaddy to setup a new one will ALL names you need (aliases for your hostname).
isilva

ASKER
Hello,

I ran the autodiscover active sync test and here are the results:

Attempting the Autodiscover and Exchange ActiveSync test (if requested).
  Testing of Autodiscover for Exchange ActiveSync failed.
   Test Steps
   Attempting each method of contacting the Autodiscover service.
  The Autodiscover service couldn't be contacted successfully by any method.
   Test Steps
   Attempting to test potential Autodiscover URL https://domain.com/AutoDiscover/AutoDiscover.xml 
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name aasdcs.org in DNS.
  The host name couldn't be resolved.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host aasdcs.org couldn't be resolved in DNS Exception details:
Message: The requested name is valid, but no data of the requested type was found
Type: System.Net.Sockets.SocketException
Stack trace:
at System.Net.Dns.GetAddrInfo(String name)
at System.Net.Dns.InternalGetHostByName(String hostName, Boolean includeIPv6)
at System.Net.Dns.GetHostAddresses(String hostNameOrAddress)
at Microsoft.Exchange.Tools.ExRca.Tests.ResolveHostTest.PerformTestReally()
.
 
 
 
 Attempting to test potential Autodiscover URL https://autodiscover.domain.com/AutoDiscover/AutoDiscover.xml 
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.XX.XX
 Testing TCP port 443 on host autodiscover.aasdcs.org to ensure it's listening and open.
  The port was opened successfully.
 Testing the SSL certificate to make sure it's valid.
  The SSL certificate failed one or more certificate validation checks.
   Test Steps
   Validating the certificate name.
  Certificate name validation failed.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host name autodiscover.aasdcs.org doesn't match any name found on the server certificate CN=remote.aasdcs.org, OU=Domain Control Validated, O=remote.aasdcs.org.
 
 
 
 
 
 Attempting to contact the Autodiscover service using the HTTP redirect method.
  The attempt to contact Autodiscover using the HTTP Redirect method failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.X.XX
 
 Testing TCP port 80 on host autodiscover.domain.com to ensure it's listening and open.
  The port was opened successfully.
 ExRCA is checking the host autodiscover.domain.com for an HTTP redirect to the Autodiscover service.
  ExRCA failed to get an HTTP redirect response for Autodiscover.
   Additional Details
  A Web exception occurred because an HTTP 404 - NotFound response was received from IIS7.
 
 
 
 Attempting to contact the Autodiscover service using the DNS SRV redirect method.
  ExRCA failed to contact the Autodiscover service using the DNS SRV redirect method.
   Test Steps
   Attempting to locate SRV record _autodiscover._tcp.domain.com in DNS.
  The Autodiscover SRV record wasn't found in DNS.
   Tell me more about this issue and how to resolve it
 
 I changed my domain info to show:  domain.com.

Hope this provides a little more info.  
 
 
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
MegaNuk3

Are you forwarding port 80/443 to the new exchange 2007 server?
isilva

ASKER
MegaNuk - Yes.
isilva

ASKER
Actuall no, I configured a virtual server.  I think it might have something to do with IIS.  It might be that the default sites are not set for remote.domain.com, could that be it?  Trying to test now.  
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
MegaNuk3

You can test autodiscover internally by holding down the CTRL key and then right clicking on the outlook icon in the bottom right hand side of your screen and selecting "Test Autoconfiguration" then select only the autodiscover options and enter credentials.
ASKER CERTIFIED SOLUTION
isilva

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
isilva

ASKER
Adding SRV record allowed users using Outlook locally to authenticate without a user name and password.  This also stopped the security warning when opening outlook (users outside the network).
jjoz

ok, many thanks for your clarification so I'll try to create the following records to match whatever I've got in my SAN certificate:

1. ExCAS01.domain.com - Exchange CAS A Record
2. Autodiscover.domain.com - Autodiscover CNAME to the CAS Server above
3. _autodiscover._tcp.domain.com - SRV type record

only number two (Autodiscover.domain.com) that is listed in my SAN certificate, do I need to create SAN entry for my ExCAS01.domain.com as well ?

I just want to make Outlook Anywhere working with external user with Outlook 2007 SP2
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.