Solved

Exchange certificate with an invalid internal domain

Posted on 2011-03-21
3
569 Views
Last Modified: 2012-06-01
I just upgraded Exchange 2003 to 2010. I wanted to get a real certificate for this client. The problem is their internal domain is a vaild Internet domain name ending in .com that is owned by someone else

I can't use that domain name in a certificate.

I know I can get a certificate with just the external domain but I want to elimintate the certificate error that pops up in Outlook on the internal network

How can I get around this problem?.
0
Comment
Question by:ajdratch
3 Comments
 
LVL 5

Expert Comment

by:wynandkunkel
ID: 35182560
I have not implemented it myself but can imagine the following:

-Install a CA on one of the DC's in the domain (Backup of thei machine becomes (EXTREMELY!!!!) important.
-issue a certificate (with the .com domain) on the internal CA
-publish/install that internal domain cert on the internal network to all machines using GPO mechanism.

Assuming that the external domain cert has already bee issued, this way the machines should trust the (internal) CA when on the LAN and also trust the (external) CA when roaming.

Best of luck!
0
 
LVL 7

Expert Comment

by:TheTull
ID: 35182653
If all you want to really accomplish is to eliminate the certificate error notification then your clients just need to trust the CA root certificate.  I see no reason why not to just use a self-signed certificate on the internal LAN, and then have your clients import the root certificate into the trusted root certificate authorities.  
0
 
LVL 1

Accepted Solution

by:
satshah earned 500 total points
ID: 35182839
Create an internal certificate for your domain and modify the URL in the exchange management shell.

http://support.microsoft.com/kb/940726


To resolve this issue, modify the URLs for the appropriate Exchange 2007 components. To do this, follow these steps:
Start the Exchange Management Shell.
Modify the Autodiscover URL in the Service Connection Point. The Service Connection Point is stored in the Active Directory directory service. To modify this URL, type the following command, and then press ENTER:
Set-ClientAccessServer -Identity CAS_Server_Name -AutodiscoverServiceInternalUri https://mail.contoso.com/autodiscover/autodiscover.xml
Modify the InternalUrl attribute of the EWS. To do this, type the following command, and then press ENTER:
Set-WebServicesVirtualDirectory -Identity "CAS_Server_Name\EWS (Default Web Site)" -InternalUrl https://mail.contoso.com/ews/exchange.asmx
Modify the InternalUrl attribute for Web-based Offline Address Book distribution. To do this, type the following command, and then press ENTER:
Set-OABVirtualDirectory -Identity "CAS_Server_name\oab (Default Web Site)" -InternalUrl https://mail.contoso.com/oab
Modify the InternalUrl attribute of the UM Web service. To do this, type the following command, and then press ENTER:
Set-UMVirtualDirectory -Identity "CAS_Server_Name\unifiedmessaging (Default Web Site)" -InternalUrl https://mail.contoso.com/unifiedmessaging/service.asmx
Note This command is required only in an Exchange 2007 environment. This command no longer exists in an Exchange 2010 environment. Instead, the WebServices URL is used for this purpose.
Open IIS Manager.
Expand the local computer, and then expand Application Pools.
Right-click MSExchangeAutodiscoverAppPool, and then click Recycle.

0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now