Solved

Invalid SSL certificate

Posted on 2011-03-07
7
781 Views
Last Modified: 2012-05-11
I installed a UCC certificate from GoDaddy on my Exchange 2010. After I installed it on the Exchange sever  our 2007 Outlook users get this error when they open Outllook:
 "The name of the security certificate is invalid or does not match the name of the site"

I googled the error and tried to follow the suggestions but was not sure of the steps in some of the links. I am new to Exchange 2010 and command line. I am trying to find a link that is not so cryptic
0
Comment
Question by:InSearchOf
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 35066817
What names do you have on your cert? Which one is it saying doesn't match the certificate? Change the internal URLs to point at a name on your cert that resolves to the internal IP of your CAS server.
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 250 total points
ID: 35066946
The names you should have on your UCC Certificate are as follows:

mail.domain.com (or whatever you want to use)
autodiscover.domain.com
internalservername.internaldomain.local
internalservername

If you don't have those names in your certificate, please re-key the certificate and include them, then your error should go away.

Alan
0
 

Author Comment

by:InSearchOf
ID: 35068612
Yes I have to change the internal URLs according to the info I have found researching the error I am just not quite clear on how to do it being that I am new to Exchange 2010 and powershell.

Those are the names I have on my certificate. If I run the " Get-ExchangeCertificate" command I only see IP and WS as the only service assciated with the thumb print. When I installed the cert according to the instructions provided me by GoDaddy I did associate IIS, SMTP and a couple of other services as well. Did I execute  the wrong command or miss something?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 35068636
If you purchased a GoDaddy SSL Certificate you should not have to change the internal URL's.

Please advise the name of the site from the error that you are seeing or post a screen-shot of the error.

Thanks

Alan
0
 

Author Comment

by:InSearchOf
ID: 35070688
Ok. Waiting for a user to send me a screenshot of the error. So far no errors. I did a restart of the Transport service as well as an IISRESET and so far no complaints.
0
 
LVL 31

Assisted Solution

by:MegaNuk3
MegaNuk3 earned 250 total points
ID: 35072047
Also have a look at
Get-clientaccessServer | fl Identity, autodiscoverInternalUri
Change that to a name on your cert that resolves internally to the internal IP address of your CAS server (or amend internal DNS so the cert name resolves to the CAS internal IP address)
0
 

Author Comment

by:InSearchOf
ID: 35072664
Ok. Thanks for all the help.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question