Solved

Invalid SSL certificate

Posted on 2011-03-07
7
748 Views
Last Modified: 2012-05-11
I installed a UCC certificate from GoDaddy on my Exchange 2010. After I installed it on the Exchange sever  our 2007 Outlook users get this error when they open Outllook:
 "The name of the security certificate is invalid or does not match the name of the site"

I googled the error and tried to follow the suggestions but was not sure of the steps in some of the links. I am new to Exchange 2010 and command line. I am trying to find a link that is not so cryptic
0
Comment
Question by:InSearchOf
  • 3
  • 2
  • 2
7 Comments
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 35066817
What names do you have on your cert? Which one is it saying doesn't match the certificate? Change the internal URLs to point at a name on your cert that resolves to the internal IP of your CAS server.
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 250 total points
ID: 35066946
The names you should have on your UCC Certificate are as follows:

mail.domain.com (or whatever you want to use)
autodiscover.domain.com
internalservername.internaldomain.local
internalservername

If you don't have those names in your certificate, please re-key the certificate and include them, then your error should go away.

Alan
0
 

Author Comment

by:InSearchOf
ID: 35068612
Yes I have to change the internal URLs according to the info I have found researching the error I am just not quite clear on how to do it being that I am new to Exchange 2010 and powershell.

Those are the names I have on my certificate. If I run the " Get-ExchangeCertificate" command I only see IP and WS as the only service assciated with the thumb print. When I installed the cert according to the instructions provided me by GoDaddy I did associate IIS, SMTP and a couple of other services as well. Did I execute  the wrong command or miss something?
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 35068636
If you purchased a GoDaddy SSL Certificate you should not have to change the internal URL's.

Please advise the name of the site from the error that you are seeing or post a screen-shot of the error.

Thanks

Alan
0
 

Author Comment

by:InSearchOf
ID: 35070688
Ok. Waiting for a user to send me a screenshot of the error. So far no errors. I did a restart of the Transport service as well as an IISRESET and so far no complaints.
0
 
LVL 31

Assisted Solution

by:MegaNuk3
MegaNuk3 earned 250 total points
ID: 35072047
Also have a look at
Get-clientaccessServer | fl Identity, autodiscoverInternalUri
Change that to a name on your cert that resolves internally to the internal IP address of your CAS server (or amend internal DNS so the cert name resolves to the CAS internal IP address)
0
 

Author Comment

by:InSearchOf
ID: 35072664
Ok. Thanks for all the help.
0

Featured Post

Do email signature updates give you a headache?

Constantly trying to correctly format email signatures? Spending all of your time at every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

Join & Write a Comment

Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now