?
Solved

Exchange certificate with an invalid internal domain

Posted on 2011-03-21
3
Medium Priority
?
625 Views
Last Modified: 2012-06-01
I just upgraded Exchange 2003 to 2010. I wanted to get a real certificate for this client. The problem is their internal domain is a vaild Internet domain name ending in .com that is owned by someone else

I can't use that domain name in a certificate.

I know I can get a certificate with just the external domain but I want to elimintate the certificate error that pops up in Outlook on the internal network

How can I get around this problem?.
0
Comment
Question by:ajdratch
3 Comments
 
LVL 5

Expert Comment

by:wynandkunkel
ID: 35182560
I have not implemented it myself but can imagine the following:

-Install a CA on one of the DC's in the domain (Backup of thei machine becomes (EXTREMELY!!!!) important.
-issue a certificate (with the .com domain) on the internal CA
-publish/install that internal domain cert on the internal network to all machines using GPO mechanism.

Assuming that the external domain cert has already bee issued, this way the machines should trust the (internal) CA when on the LAN and also trust the (external) CA when roaming.

Best of luck!
0
 
LVL 7

Expert Comment

by:TheTull
ID: 35182653
If all you want to really accomplish is to eliminate the certificate error notification then your clients just need to trust the CA root certificate.  I see no reason why not to just use a self-signed certificate on the internal LAN, and then have your clients import the root certificate into the trusted root certificate authorities.  
0
 
LVL 1

Accepted Solution

by:
satshah earned 2000 total points
ID: 35182839
Create an internal certificate for your domain and modify the URL in the exchange management shell.

http://support.microsoft.com/kb/940726


To resolve this issue, modify the URLs for the appropriate Exchange 2007 components. To do this, follow these steps:
Start the Exchange Management Shell.
Modify the Autodiscover URL in the Service Connection Point. The Service Connection Point is stored in the Active Directory directory service. To modify this URL, type the following command, and then press ENTER:
Set-ClientAccessServer -Identity CAS_Server_Name -AutodiscoverServiceInternalUri https://mail.contoso.com/autodiscover/autodiscover.xml
Modify the InternalUrl attribute of the EWS. To do this, type the following command, and then press ENTER:
Set-WebServicesVirtualDirectory -Identity "CAS_Server_Name\EWS (Default Web Site)" -InternalUrl https://mail.contoso.com/ews/exchange.asmx
Modify the InternalUrl attribute for Web-based Offline Address Book distribution. To do this, type the following command, and then press ENTER:
Set-OABVirtualDirectory -Identity "CAS_Server_name\oab (Default Web Site)" -InternalUrl https://mail.contoso.com/oab
Modify the InternalUrl attribute of the UM Web service. To do this, type the following command, and then press ENTER:
Set-UMVirtualDirectory -Identity "CAS_Server_Name\unifiedmessaging (Default Web Site)" -InternalUrl https://mail.contoso.com/unifiedmessaging/service.asmx
Note This command is required only in an Exchange 2007 environment. This command no longer exists in an Exchange 2010 environment. Instead, the WebServices URL is used for this purpose.
Open IIS Manager.
Expand the local computer, and then expand Application Pools.
Right-click MSExchangeAutodiscoverAppPool, and then click Recycle.

0

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange administrators are always vigilant about Exchange crashes and disasters that are possible any time. It is quite essential to identify the symptoms of a possible Exchange issue and be prepared with a proper recovery plan. There are multiple…
Upgrading from older Exchange server to the latest Exchange server can be tiresome, error-prone and risky, without being a seasoned exchange server administrators. It can become even problematic if you're an organization that runs on tight timeline…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…
Suggested Courses

616 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question