Link to home
Start Free TrialLog in
Avatar of ALAA_ELMAHDY
ALAA_ELMAHDY

asked on

newly installed computers can't trust the certificate of exchange server

Dear All,

i have a public certificate from entrust and it works perfectly from out side the company but from the inside i configured the owa to be windows integrated and basic authintication and all the others like it but i am recieving a certificate ,this only happened with my local servers names.

i opened mmc- certificates - computer

and i found it unable to trust the entrust

i tried to trace the server and i didn't find any backet going to the internet

how can i know what to tell the network team to allow for the entrust to work
Avatar of craig_j_Lawrence
craig_j_Lawrence
Flag of Australia image

Hi,

Did you add the local server names to the Subject Alternate Name (SAN) list when the certificate was created?

for a client computer to "accept" a certificate, the host name you are entering in the browser must match one of the names associated with the certificate.

As Craig says you either need to change the cert subject

OR

Add an internal DNS entry for whatever name is on your cert to resolve to the internal IP address of your web server.
Avatar of ALAA_ELMAHDY
ALAA_ELMAHDY

ASKER

both of them are existing

the names are very well in the certificate it self (SAN one)

and it was working perfectly and still working on the server zone but i don't know what happened.

this message disappears when i trust the entrust certificate chain so i think it's a matter of the clients can't check the issuer of the certificate but i don't know what to do then.

the certificate is working from the internet perfectly and the servers that appear on the message are the client access servers.
and there is a dns record for what ever names in the certificate.
Can you post the cert error message? Modify the domain name in MSPaint if you want.
Also, where are you receiving the cert warning? Outlook or OWA on these new machines?
I am recieving this message on the new Pc's

i had called microsoft support and they transfer the issue from exchange to windows team we reached that the windows is able to download the entrust certificate from the windows update site but not able to inject it to the local pc's certificates.
So you are going to have to install the cert manually then? Surely Entrust will have something to say about this? Have you tried installing IE 9 or the latest Root Certificate update from Windows Update?
how can i install the latest Root Certificate update from Windows Update
IE --> tools --> safety --> windows update
It should be listed as one of the optional updates
THIS IS WINDOWS 7 AND it's fully updated
Have you spoken to your cert provider to see if they have any solution? You may need a new intermediate cert from them to resolve this.
i have downloaded the certificate from windows update and checked for the update and discovered that the last update is 2009 means nothing new and also when i installed the certificate it works like sharm.
but i want to get it working on all pc's
ASKER CERTIFIED SOLUTION
Avatar of craig_j_Lawrence
craig_j_Lawrence
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
sorry for not closing the Question due to limited connectivity.

Finally microsoft announced that there was there an error in the windows update package which the windows 7 uses to update the trusted CA's list.

and this was fixed and republished by the windows Update team.

thanks
Alaa Elahdy
Avatar of Glen Knight
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.