Solved

Error SSL certificat prompt in Outlook - Exchange 2010

Posted on 2011-09-19
8
357 Views
Last Modified: 2012-05-12
Hello everyone,

I encountered a problem with SSL certificat.

I've just bought a SAN SSL certificate to protect all my external domain.
But I have now a prompt in my local domain on Outlook saying my certificate is note valide for this URL.
My Outlook client in local are connected to the Exchange server (srv-exchange.masociete.net).
Does I abligatory need to add the name of my Exchange server in the SAN ssl certificate or is there a workeround to use the generated certificate just for OWA, ActiveSync and Outlook Anywhere connection ?

Thanks in advance for your answers.

Damien
0
Comment
Question by:dbrenot
  • 5
  • 2
8 Comments
 
LVL 25

Expert Comment

by:-MAS
ID: 36559412
you should have these names in your certificate
1. mail.external-domain-name.com
2.autodiscover.domain.com
3.exch-servername.domain.com

Please check this
http://exchangeserverpro.com/configure-an-ssl-certificate-for-exchange-server-2010
http://technet.microsoft.com/en-us/library/dd351044.aspx
0
 

Author Comment

by:dbrenot
ID: 36559426
thanks but the problem is my internal domain name was created with windows NT 4 and is like masociete.net and I've not bought the domain masociete.net.

Could I change the internal URL used by Outlook client to connect to Exchange ?
0
 

Author Comment

by:dbrenot
ID: 36559463
Could I use the command line get-clientaccessserver | fl *uri* and set-clientaccessserver -AutoDiscoverServiceInternalUri to change the URL to point to the URL in my certificate ?

0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 25

Accepted Solution

by:
-MAS earned 500 total points
ID: 36559557
Here is the full commands

[PS] C:\Documents and Settings\Administrator.UICDOMAIN>Get-clientAccessServer | fl Name,AutoDiscoverServiceInternalUri

Name                           : HUB1
AutoDiscoverServiceInternalUri : https://hub1.domain.com/Autodiscover/Autodiscover.xml
Set-ClientAccessServer -Identity hub1 -AutoDiscoverServiceInternalUri "https://mail.domain.com/autodiscover/autodiscover.xml"
================================================================================

[PS] C:\Documents and Settings\Administrator.UICDOMAIN>Get-AutodiscoverVirtualDirectory | fl Name,internalurl,externalurl

Name        : Autodiscover (Default Web Site)
InternalUrl :
ExternalUrl :

================================================================================
Offline Address Book

[PS] C:\Documents and Settings\Administrator.UICDOMAIN>Get-OabVirtualDirectory |  fl Server,Name,internalurl,externalurl

Server      : HUB1
Name        : OAB (Default Web Site)
InternalUrl : http://hub1.domain.com/OAB ExternalUrl :

Set-OabVirtualDirectory -Identity "hub1\oab (default web site)" -InternalUrl https://mail.domain.com/oab -ExternalUrl https://mail.domain.com/oab
================================================================================

[PS] C:\Documents and Settings\Administrator.UICDOMAIN>Get-UMVirtualDirectory | fl Name,Server,Internalurl,externalurl

Name        : UnifiedMessaging (Default Web Site)
Server      : HUB1
InternalUrl : https://hub1.domain.com/UnifiedMessaging/Service.asmx
ExternalUrl :

set-UMVirtualDirectory -Identity "hub1\UnifiedMessaging (Default Web Site)" -InternalUrl https://mail.domain.com/UnifiedMessaging/Service.asmx -ExternalUrl https://mail.domain.com/UnifiedMessaging/Service.asmx

============================================================================================
EWS:
[PS] C:\Documents and Settings\Administrator.UICDOMAIN>Get-WebServicesVirtualDir
ectory | fl name,internalurl,externalurl

Name        : EWS (Default Web Site)
InternalUrl : https://hub1.domain.com/EWS/Exchange.asmx
ExternalUrl :

set-WebservicesVirtualDirectory -Identity "hub1\EWS (default web site)" -InternalUrl https://mail.domain.com/EWS/Exchange.asmx -ExternalUrl https://mail.domain.com/EWS/Exchange.asmx

===============================================================================

0
 
LVL 14

Expert Comment

by:setasoujiro
ID: 36559561
you can do this from the EMC, give exchange 2007/2010.
You should indeed set your internal URLS to the same as the External, and have all the right internal dns records to resolve these.
0
 
LVL 25

Expert Comment

by:-MAS
ID: 36559579

Change domain.com it to your external domain name.
0
 
LVL 25

Expert Comment

by:-MAS
ID: 36559589
you make both internal and external the same
0
 
LVL 25

Expert Comment

by:-MAS
ID: 36559608
Apart from that Why you keep windows NT,
Install windows2003/2008 server and promote it a domain controller and transfer all  FSMO roles.

Then change the DNS IP in the exchange server and restart and run command  'setup.com /prepareAD'

Cheers
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question