Solved

Autodiscover

Posted on 2010-11-15
13
2,423 Views
Last Modified: 2012-08-13
Hello,

Just installed an SBS2008/Exchange 2007.  Autodiscover test (testexchangeconnectivity.com) continues to fail.  Outlook connected (interntally) conitnues to get popup to enter user name and password.  
Autodiscover.domain.com has been added (host) to point to the public (static) IP address and have also opened up the ports on the router.  

I have installed a basic (single) SSL cert from Godaddy and installed with no issues.  

Issues:  
*Autodiscover test fails (testexchagenconnectivity.com)

*Outlook continues to prompt for user name and password when connecting on the local network.
Note:  if you close the login prompt, exchange remains connected to exchange.

Receive (security alert) - Information you exchange with this site cannot be viewed or changed by others........
(two green checks for - This security cetificate is trusted.....-The security certificate is valid.
One red X on - The name on the security certificate is invalid or does not match the name of the site

0
Comment
Question by:isilva
  • 6
  • 3
  • 2
  • +2
13 Comments
 
LVL 5

Expert Comment

by:mittermueller
ID: 34138629
Your certificate does not include the autodiscover hostname...
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34138652
Mittermuller is right, your cert doesn't include the autodiscover.yourdomain.com subject

Other than that ensure you install at least E2k7 SP2 (SP3 is out) as that resolves several password prompt issues
0
 
LVL 3

Expert Comment

by:ggupta7
ID: 34138660
0
 

Author Comment

by:isilva
ID: 34138772
MitterMueller - Does that mean I have to purchase another cert?  Should I have purchased a multiple domain cert?  

0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34138965
the certificate needs to to have multiple hostnames in it (not domains). So the certificate will respond to all hostnames of that server (e.g. msdc01, msdc01.mydomain.local, msdc01.dyndns.org, autodiscover.mydomain.local,
mydomain.local, etc.).

Maybe you can get Godaddy to setup a new one will ALL names you need (aliases for your hostname).
0
 

Author Comment

by:isilva
ID: 34139156
Hello,

I ran the autodiscover active sync test and here are the results:

Attempting the Autodiscover and Exchange ActiveSync test (if requested).
  Testing of Autodiscover for Exchange ActiveSync failed.
   Test Steps
   Attempting each method of contacting the Autodiscover service.
  The Autodiscover service couldn't be contacted successfully by any method.
   Test Steps
   Attempting to test potential Autodiscover URL https://domain.com/AutoDiscover/AutoDiscover.xml
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name aasdcs.org in DNS.
  The host name couldn't be resolved.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host aasdcs.org couldn't be resolved in DNS Exception details:
Message: The requested name is valid, but no data of the requested type was found
Type: System.Net.Sockets.SocketException
Stack trace:
at System.Net.Dns.GetAddrInfo(String name)
at System.Net.Dns.InternalGetHostByName(String hostName, Boolean includeIPv6)
at System.Net.Dns.GetHostAddresses(String hostNameOrAddress)
at Microsoft.Exchange.Tools.ExRca.Tests.ResolveHostTest.PerformTestReally()
.
 
 
 
 Attempting to test potential Autodiscover URL https://autodiscover.domain.com/AutoDiscover/AutoDiscover.xml
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.XX.XX
 Testing TCP port 443 on host autodiscover.aasdcs.org to ensure it's listening and open.
  The port was opened successfully.
 Testing the SSL certificate to make sure it's valid.
  The SSL certificate failed one or more certificate validation checks.
   Test Steps
   Validating the certificate name.
  Certificate name validation failed.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host name autodiscover.aasdcs.org doesn't match any name found on the server certificate CN=remote.aasdcs.org, OU=Domain Control Validated, O=remote.aasdcs.org.
 
 
 
 
 
 Attempting to contact the Autodiscover service using the HTTP redirect method.
  The attempt to contact Autodiscover using the HTTP Redirect method failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.X.XX
 
 Testing TCP port 80 on host autodiscover.domain.com to ensure it's listening and open.
  The port was opened successfully.
 ExRCA is checking the host autodiscover.domain.com for an HTTP redirect to the Autodiscover service.
  ExRCA failed to get an HTTP redirect response for Autodiscover.
   Additional Details
  A Web exception occurred because an HTTP 404 - NotFound response was received from IIS7.
 
 
 
 Attempting to contact the Autodiscover service using the DNS SRV redirect method.
  ExRCA failed to contact the Autodiscover service using the DNS SRV redirect method.
   Test Steps
   Attempting to locate SRV record _autodiscover._tcp.domain.com in DNS.
  The Autodiscover SRV record wasn't found in DNS.
   Tell me more about this issue and how to resolve it
 
 I changed my domain info to show:  domain.com.

Hope this provides a little more info.  
 
 
0
Do email signature updates give you a headache?

Do you feel like all of your time is spent managing email signatures? Too busy to visit every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34139859
Are you forwarding port 80/443 to the new exchange 2007 server?
0
 

Author Comment

by:isilva
ID: 34139955
MegaNuk - Yes.
0
 

Author Comment

by:isilva
ID: 34140190
Actuall no, I configured a virtual server.  I think it might have something to do with IIS.  It might be that the default sites are not set for remote.domain.com, could that be it?  Trying to test now.  
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34143113
You can test autodiscover internally by holding down the CTRL key and then right clicking on the outlook icon in the bottom right hand side of your screen and selecting "Test Autoconfiguration" then select only the autodiscover options and enter credentials.
0
 

Accepted Solution

by:
isilva earned 0 total points
ID: 34149805
Hello - Thank you for your responses.  I was able to figure out the issue.  The issue was the SSL.  when adding the A record to point to the (subdomain) autodiscover.domain.com, Outlook could not verify the domain name because it was not included in the cert
A work around for single domain certs is to create a SRV recordand have it point to exchange.domain.com on port 443.  This resolved the issue, when connecting internally and helped resolve OWA site not being up.  

Right now, seems like OAB /OOF is not working properly, so trying to figure that out.

Thank you for all for taking the time to read/comment on this post.  

0
 

Author Closing Comment

by:isilva
ID: 34182476
Adding SRV record allowed users using Outlook locally to authenticate without a user name and password.  This also stopped the security warning when opening outlook (users outside the network).
0
 
LVL 1

Expert Comment

by:jjoz
ID: 34979529
ok, many thanks for your clarification so I'll try to create the following records to match whatever I've got in my SAN certificate:

1. ExCAS01.domain.com - Exchange CAS A Record
2. Autodiscover.domain.com - Autodiscover CNAME to the CAS Server above
3. _autodiscover._tcp.domain.com - SRV type record

only number two (Autodiscover.domain.com) that is listed in my SAN certificate, do I need to create SAN entry for my ExCAS01.domain.com as well ?

I just want to make Outlook Anywhere working with external user with Outlook 2007 SP2
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
"Migrate" an SMTP relay receive connector to a new server using info from an old server.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now