Exchange 2010 Single Cert conflicts with host and autodiscover

Posted on 2011-05-06
Last Modified: 2012-05-11
We have two 2010 servers. is the internal CAS/DB server; is a CAS server that faces the internet.  EXCHANGE has a self-signed cert as; EXCHANGEFE has regular SSL cert named  

When Outlook profiles are configured, they typically show connection to EXCHANGE and use the self-signed cert with no issue.  

The last few days, there have been instances where users open Outlook and are prompted with a EXCHANGEFE --AND-- AUTODISCOVER cert mis-match because that server only has cert installed.

How can I force all internal users to only go to EXCHANGE CAS server so that the ExchangeFE does not show EXCHANGEFE and AUTODISCOVER cert errors?

Autodiscover is not available via internet.  We have it internal, but I am OK with turning it OFF and requiring manual Outlook profile configuration.
Question by:tcloud
    LVL 4

    Expert Comment

    You can user same cert for OWA as well as for Autodiscover but make sure you have same subject name for both for eg; OWA URL : and AutoDiscover URl :

    If you are using Third party certificate then it will work from internet as well.

    Author Comment

    So I need to set the AutoDiscover URI manually, if so ,where?

    How do I keep clients from going to  They should go to EXCHANGE or use the OWA cert on the ExchangeFE server.
    LVL 4

    Accepted Solution

    Use Same Cert Across organisation.Follow below mentioned article;

    Author Closing Comment

    You were absolutely right, one of my servers still had the listed when it should have been the for which I have a cert.  THANKS!

    Featured Post

    Free book by J.Peter Bruzzese, Microsoft MVP

    Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

    Join & Write a Comment

    Learn more about how the humble email signature can be used as more than just an electronic business card. When used correctly, a signature can easily be tailored for different purposes by different departments within an organization.
    Find out how to use dynamic social media in email signatures with this top 10 DOs & DON’Ts.
    In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
    The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

    730 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now