• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1654
  • Last Modified:

publish OWA trought TMG Certificate key is incorrect

hi all ,
i running into a small problm

i have Exchange 2010 in place , i ve installed a CA on it and create new certificate , assign the IIS service to it .and export it as pfx with password  .
i ve installed the certificate on TMG certificate store ,but when i use the wizard to creat the port listner for OWA it shows me the certificate as Invalide  with remark , the key type is incorrect !

what are the "correct type " for the key to be valide for publishing owa ?
0
Osmoze
Asked:
Osmoze
  • 9
  • 8
2 Solutions
 
mattconroyCommented:
Create a SAN cert using the CA for the Exchange Server. Create the exchange cert from the Exchange Server, and submit it to the CA. We will Call the CA Server DC1.

Next, install the root CA of Server DC1 in the Trusted Root CA(for computer not user) on the TMG.
0
 
OsmozeAuthor Commented:
Hi , actually i solved it by recreating a new certificate request ( vias Exchange management console )
submit the request code to the CA and got the new certificate and complete the pending request on Exchange EMC .and transfer services to it .

Export it , as pfx with the password  .and installe it on TMG in the personnal and trusted certificate store .

now all working well .OWA is published .

now my i am in Outlook anywhere , i ve done the same steps ( new certificate for it and smpt ,pop imap as services ) seconde port with the new certificate assigner ,etc .
but still outlook cannot connect to the server !

any help to configure it the correct way ?
0
 
mattconroyCommented:
For rpc over https to work you will need to install the root certificate of the CA in the TMG trusted root ca.
0
Restore individual SQL databases with ease

Veeam Explorer for Microsoft SQL Server delivers an easy-to-use, wizard-driven interface for restoring your databases from a backup. No expert SQL background required. Web interface provides a complete view of all available SQL databases to simplify the recovery of lost database

 
OsmozeAuthor Commented:

Already Done  i followed this step by step but still outlook cannot access exchange

http://exchangemaster.wordpress.com/2010/04/11/publish-exchange-2010-with-tmg-cont/
0
 
mattconroyCommented:
Are the ports open for rpc?
0
 
OsmozeAuthor Commented:
wich ports ? ave set up a rule in TMG to publish outlook anywhere using the exchange web client publishing wizard , i think this is enough  to open necessary ports
0
 
mattconroyCommented:
Can you get to https://yourtmgaddress/rpc/to proxy.all?

You should get a blank page with no errors.
0
 
OsmozeAuthor Commented:
Yep i got the blank page .and the test rule on TMG is showing that the configuration is OK . but i dont where i missing somthing ,
i configured Outlook as follow :
new profile :Internet Mail
choose http with the user credential and the TMG IP where i published OA .when i open outlook , it told me cannot connecto to the server ...

am i missing somthing ?  i know it's so close !!
0
 
mattconroyCommented:
Is outlook anywhere enabled on the Exchange Server?
0
 
OsmozeAuthor Commented:
Yep it"s enabled !!
should i use https://TMGIP/rpc when configiuring server url in outlook ?  or without /rpc/ ?
0
 
mattconroyCommented:
Without
0
 
OsmozeAuthor Commented:
Ok  here's some pic from my configuration ,

any ideas ?
test-rule.png
outlook-profile.PNG
send-recive.PNG
0
 
mattconroyCommented:
What do you get if you run the www.rests change inns ticket.com for outlook anywhere?
0
 
OsmozeAuthor Commented:
Sorry , i dont understant ? running what (url is not clear ) ? and from where i have to test ?
0
 
mattconroyCommented:
Testexchangeconnectivity.com
0
 
OsmozeAuthor Commented:
ah ok
it wont work , because we are not publishing outlook anywhere over Internet , but for our agency that have a VPN site to site trought a nother Firewall in front of TMG , they re not domain member , but the IT stuff want to give them acces to Outlook .

so Testexchangeconnectivity.com will not work !
0
 
OsmozeAuthor Commented:
it solved the problme for the CA , but still  have issue with outlook anyhere , i ll open another post for it .
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

  • 9
  • 8
Tackle projects and never again get stuck behind a technical roadblock.
Join Now