Exchange 2007 SP3 Outlook Anywhere problems and wildcard certificate

Posted on 2011-03-09
Last Modified: 2012-05-11
my config is 2 CAS servers loadbalanced under pointing to hardware loadbalancer IP address. Also points to the same ip address. SSL certificate used for Exchange is issued for * and have SAN *,
Doing Test-OutlookWebServices I receive:
Id      : 1003
Type    : Information
Message : About to test AutoDiscover with the e-mail address

Id      : 1007
Type    : Information
Message : Testing server with the published name &

Id      : 1019
Type    : Information
Message : Found a valid AutoDiscover service connection point. The AutoDiscover URL on this object is

Id      : 1006
Type    : Information
Message : The Autodiscover service was contacted at

Id      : 1016
Type    : Success
Message : [EXCH]-Successfully contacted the AS service at The elapsed time was 171 milliseconds.

Id      : 1015
Type    : Success
Message : [EXCH]-Successfully contacted the OAB service at The elapsed time was 0 milliseconds.

Id      : 1014
Type    : Success
Message : [EXCH]-Successfully contacted the UM service at The elapsed time was 15 milliseconds.

Id      : 1016
Type    : Success
Message : [EXPR]-Successfully contacted the AS service at The elapsed time was 109 milliseconds.

Id      : 1015
Type    : Success
Message : [EXPR]-Successfully contacted the OAB service at The elapsed time was 0 milliseconds.

Id      : 1014
Type    : Information
Message : [EXPR]-The UM is not configured for this user.

Id      : 1017
Type    : Success
Message : [EXPR]-Successfully contacted the RPC/HTTP service at The elapsed time was 187 milliseconds.

Id      : 1006
Type    : Success
Message : The Autodiscover service was tested successfully.

For domain-joined clients everything works perfectly but when I try to configure Outlook 2010 on machine outside the domain with dns configured to resolve and autodiscover properly configure Outlook to use Rpc over HTTP, profile is created but after this I receive instant prompt for login and cannot open mailbox. Is this a problem with my wildcard certificate or should I try toggling authorization setting on IIS.
To answer question why internal and external url is the same - I publish exchange only in WAN (no access from internet, so also is not usable for me) and unfortunately out AD domain is the same as smtp domain so for easier config I made just one url - maybe this is wrong.
Question by:Matt72127
  • 2

Accepted Solution

praveenkumare_sp earned 250 total points
ID: 35088249
i think i know whats  the issue

please see think link

When, if and how do you modify Outlook Providers?

go to the place where the article talks about the below command
Set-OutlookProvider EXPR -CertPrincipalName msstd:*

Expert Comment

ID: 35088305
the reason this happens is
the certificate issued to name is *
but ur outlook anywhere url will be

there is a mismatch in the URLS thats the reason why this is happening


Author Closing Comment

ID: 35126815
Thanks a lot, this is really helpfull

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question