Solved

Autodiscover

Posted on 2010-11-15
13
2,438 Views
Last Modified: 2012-08-13
Hello,

Just installed an SBS2008/Exchange 2007.  Autodiscover test (testexchangeconnectivity.com) continues to fail.  Outlook connected (interntally) conitnues to get popup to enter user name and password.  
Autodiscover.domain.com has been added (host) to point to the public (static) IP address and have also opened up the ports on the router.  

I have installed a basic (single) SSL cert from Godaddy and installed with no issues.  

Issues:  
*Autodiscover test fails (testexchagenconnectivity.com)

*Outlook continues to prompt for user name and password when connecting on the local network.
Note:  if you close the login prompt, exchange remains connected to exchange.

Receive (security alert) - Information you exchange with this site cannot be viewed or changed by others........
(two green checks for - This security cetificate is trusted.....-The security certificate is valid.
One red X on - The name on the security certificate is invalid or does not match the name of the site

0
Comment
Question by:isilva
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
  • 2
  • +2
13 Comments
 
LVL 5

Expert Comment

by:mittermueller
ID: 34138629
Your certificate does not include the autodiscover hostname...
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34138652
Mittermuller is right, your cert doesn't include the autodiscover.yourdomain.com subject

Other than that ensure you install at least E2k7 SP2 (SP3 is out) as that resolves several password prompt issues
0
Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

 

Author Comment

by:isilva
ID: 34138772
MitterMueller - Does that mean I have to purchase another cert?  Should I have purchased a multiple domain cert?  

0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34138965
the certificate needs to to have multiple hostnames in it (not domains). So the certificate will respond to all hostnames of that server (e.g. msdc01, msdc01.mydomain.local, msdc01.dyndns.org, autodiscover.mydomain.local,
mydomain.local, etc.).

Maybe you can get Godaddy to setup a new one will ALL names you need (aliases for your hostname).
0
 

Author Comment

by:isilva
ID: 34139156
Hello,

I ran the autodiscover active sync test and here are the results:

Attempting the Autodiscover and Exchange ActiveSync test (if requested).
  Testing of Autodiscover for Exchange ActiveSync failed.
   Test Steps
   Attempting each method of contacting the Autodiscover service.
  The Autodiscover service couldn't be contacted successfully by any method.
   Test Steps
   Attempting to test potential Autodiscover URL https://domain.com/AutoDiscover/AutoDiscover.xml 
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name aasdcs.org in DNS.
  The host name couldn't be resolved.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host aasdcs.org couldn't be resolved in DNS Exception details:
Message: The requested name is valid, but no data of the requested type was found
Type: System.Net.Sockets.SocketException
Stack trace:
at System.Net.Dns.GetAddrInfo(String name)
at System.Net.Dns.InternalGetHostByName(String hostName, Boolean includeIPv6)
at System.Net.Dns.GetHostAddresses(String hostNameOrAddress)
at Microsoft.Exchange.Tools.ExRca.Tests.ResolveHostTest.PerformTestReally()
.
 
 
 
 Attempting to test potential Autodiscover URL https://autodiscover.domain.com/AutoDiscover/AutoDiscover.xml 
  Testing of this potential Autodiscover URL failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.XX.XX
 Testing TCP port 443 on host autodiscover.aasdcs.org to ensure it's listening and open.
  The port was opened successfully.
 Testing the SSL certificate to make sure it's valid.
  The SSL certificate failed one or more certificate validation checks.
   Test Steps
   Validating the certificate name.
  Certificate name validation failed.
   Tell me more about this issue and how to resolve it
   Additional Details
  Host name autodiscover.aasdcs.org doesn't match any name found on the server certificate CN=remote.aasdcs.org, OU=Domain Control Validated, O=remote.aasdcs.org.
 
 
 
 
 
 Attempting to contact the Autodiscover service using the HTTP redirect method.
  The attempt to contact Autodiscover using the HTTP Redirect method failed.
   Test Steps
   Attempting to resolve the host name autodiscover.domain.com in DNS.
  The host name resolved successfully.
   Additional Details
  IP addresses returned: 68.XX.X.XX
 
 Testing TCP port 80 on host autodiscover.domain.com to ensure it's listening and open.
  The port was opened successfully.
 ExRCA is checking the host autodiscover.domain.com for an HTTP redirect to the Autodiscover service.
  ExRCA failed to get an HTTP redirect response for Autodiscover.
   Additional Details
  A Web exception occurred because an HTTP 404 - NotFound response was received from IIS7.
 
 
 
 Attempting to contact the Autodiscover service using the DNS SRV redirect method.
  ExRCA failed to contact the Autodiscover service using the DNS SRV redirect method.
   Test Steps
   Attempting to locate SRV record _autodiscover._tcp.domain.com in DNS.
  The Autodiscover SRV record wasn't found in DNS.
   Tell me more about this issue and how to resolve it
 
 I changed my domain info to show:  domain.com.

Hope this provides a little more info.  
 
 
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34139859
Are you forwarding port 80/443 to the new exchange 2007 server?
0
 

Author Comment

by:isilva
ID: 34139955
MegaNuk - Yes.
0
 

Author Comment

by:isilva
ID: 34140190
Actuall no, I configured a virtual server.  I think it might have something to do with IIS.  It might be that the default sites are not set for remote.domain.com, could that be it?  Trying to test now.  
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 34143113
You can test autodiscover internally by holding down the CTRL key and then right clicking on the outlook icon in the bottom right hand side of your screen and selecting "Test Autoconfiguration" then select only the autodiscover options and enter credentials.
0
 

Accepted Solution

by:
isilva earned 0 total points
ID: 34149805
Hello - Thank you for your responses.  I was able to figure out the issue.  The issue was the SSL.  when adding the A record to point to the (subdomain) autodiscover.domain.com, Outlook could not verify the domain name because it was not included in the cert
A work around for single domain certs is to create a SRV recordand have it point to exchange.domain.com on port 443.  This resolved the issue, when connecting internally and helped resolve OWA site not being up.  

Right now, seems like OAB /OOF is not working properly, so trying to figure that out.

Thank you for all for taking the time to read/comment on this post.  

0
 

Author Closing Comment

by:isilva
ID: 34182476
Adding SRV record allowed users using Outlook locally to authenticate without a user name and password.  This also stopped the security warning when opening outlook (users outside the network).
0
 
LVL 1

Expert Comment

by:jjoz
ID: 34979529
ok, many thanks for your clarification so I'll try to create the following records to match whatever I've got in my SAN certificate:

1. ExCAS01.domain.com - Exchange CAS A Record
2. Autodiscover.domain.com - Autodiscover CNAME to the CAS Server above
3. _autodiscover._tcp.domain.com - SRV type record

only number two (Autodiscover.domain.com) that is listed in my SAN certificate, do I need to create SAN entry for my ExCAS01.domain.com as well ?

I just want to make Outlook Anywhere working with external user with Outlook 2007 SP2
0

Featured Post

Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question