Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange 2007 SP3 Outlook Anywhere problems and wildcard certificate

Posted on 2011-03-09
3
Medium Priority
?
946 Views
Last Modified: 2012-05-11
Hello,
my config is 2 CAS servers loadbalanced under webmail.domain.com pointing to hardware loadbalancer IP address. Also autodiscover.domain.com points to the same ip address. SSL certificate used for Exchange is issued for *.domain.com and have SAN *.domain.com, domain.com.
Doing Test-OutlookWebServices I receive:
Id      : 1003
Type    : Information
Message : About to test AutoDiscover with the e-mail address Administrator@domain.com.

Id      : 1007
Type    : Information
Message : Testing server CAS1.domain.com with the published name https://webmail.domain.com/ews/exchange.asmx & https://webmail.domain.com/EWS/Exchange.asmx.

Id      : 1019
Type    : Information
Message : Found a valid AutoDiscover service connection point. The AutoDiscover URL on this object is https://webmail.domain.com/autodiscover/autodiscover.xml.

Id      : 1006
Type    : Information
Message : The Autodiscover service was contacted at https://webmail.domain.com/autodiscover/autodiscover.xml.

Id      : 1016
Type    : Success
Message : [EXCH]-Successfully contacted the AS service at https://webmail.domain.com/ews/exchange.asmx. The elapsed time was 171 milliseconds.

Id      : 1015
Type    : Success
Message : [EXCH]-Successfully contacted the OAB service at https://webmail.domain.com/ews/exchange.asmx. The elapsed time was 0 milliseconds.

Id      : 1014
Type    : Success
Message : [EXCH]-Successfully contacted the UM service at https://cas1.domain.com/UnifiedMessaging/Service.asmx. The elapsed time was 15 milliseconds.

Id      : 1016
Type    : Success
Message : [EXPR]-Successfully contacted the AS service at https://webmail.domain.com/EWS/Exchange.asmx. The elapsed time was 109 milliseconds.

Id      : 1015
Type    : Success
Message : [EXPR]-Successfully contacted the OAB service at https://webmail.domain.com/EWS/Exchange.asmx. The elapsed time was 0 milliseconds.

Id      : 1014
Type    : Information
Message : [EXPR]-The UM is not configured for this user.

Id      : 1017
Type    : Success
Message : [EXPR]-Successfully contacted the RPC/HTTP service at https://webmail.domain.com/Rpc. The elapsed time was 187 milliseconds.

Id      : 1006
Type    : Success
Message : The Autodiscover service was tested successfully.

For domain-joined clients everything works perfectly but when I try to configure Outlook 2010 on machine outside the domain with dns configured to resolve webmail.domain.com and autodiscover.domain.com autodiscover properly configure Outlook to use Rpc over HTTP, profile is created but after this I receive instant prompt for login and cannot open mailbox. Is this a problem with my wildcard certificate or should I try toggling authorization setting on IIS.
To answer question why internal and external url is the same - I publish exchange only in WAN (no access from internet, so also www.testexchangeconnectivity.com is not usable for me) and unfortunately out AD domain is the same as smtp domain so for easier config I made just one url - maybe this is wrong.
0
Comment
Question by:Matt72127
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 8

Accepted Solution

by:
praveenkumare_sp earned 1000 total points
ID: 35088249
i think i know whats  the issue

please see think link

When, if and how do you modify Outlook Providers?
http://msexchangeteam.com/archive/2008/09/29/449921.aspx

go to the place where the article talks about the below command
Set-OutlookProvider EXPR -CertPrincipalName msstd:*.fouthcoffee.com
0
 
LVL 8

Expert Comment

by:praveenkumare_sp
ID: 35088305
the reason this happens is
the certificate issued to name is *.domain.com
but ur outlook anywhere url will be webmail.domain.com


there is a mismatch in the URLS thats the reason why this is happening

0
 

Author Closing Comment

by:Matt72127
ID: 35126815
Thanks a lot, this is really helpfull
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
Are you an Exchange administrator employed with an organization? And, have you encountered a corrupt Exchange database due to which you are not able to open its EDB file. This article will explain all the steps to repair corrupt Exchange database.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question