Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Exchange 2010 SP2 - SSL Certificate Problem

Posted on 2012-03-20
7
Medium Priority
?
863 Views
Last Modified: 2012-03-23
We have just completed a migration from Exchange 2003 to Exchange 2010.  The server is an on-premise single server solution with a mix of Outlook 2003 & Outlook 2010 clients.  The server name is exchange.companyname.local and we have installed a GoDaddy SSL certificate in the name of office.companyname.co.uk which is the external name, this is assigned in IIS and currently works with Outlook We App with no problems.  The problem we are experiencing is that on the Outlook 2010 clients an SSL error keeps being displayed saying 'The name on the certificate does not match the server'.  I'm guessing there’s some additional configuration required somewhere since we installed the GoDaddy certificate.  Help would be very much appreciated. Thanks in advance.
0
Comment
Question by:jambomambo
  • 3
  • 2
6 Comments
 
LVL 28

Expert Comment

by:MAS
ID: 37741688
1.Make sure 'exchange.companyname.local' and 'office.companyname.co.uk' is added in the certificate

2. Enable IIS services for the certificate installed

3. Configure autodiscover in the server. post the output of the below command
    Get-AutodiscoverVirtualDirectory | fl Name,internalurl,externalurl
0
 
LVL 28

Expert Comment

by:MAS
ID: 37741716
Type 'Get-Exchangecertificate' and get the thumbprint and enable IIS service using the below command

Enable-ExchangeCertificate -Thumbprint 5113ae0233a72fccb75b1d0198628675333d010e -Services IIS
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 37741744
If you bought a single name SSL certificate - you should have bought a SAN / UCC SSL certificate (multi name) and should include the following names in the certificate if you want to lose the errors:

office.companyname.co.uk
autodiscover.companyname.co.uk
exchange.companyname.local
exchange

You should also add an Autodiscover A record in your Domains DNS Records (not internally) and point it to the Public IP Address of your Exchange Server.

If you have all the above names - the errors should go away.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 28

Expert Comment

by:MAS
ID: 37741857
As suggested by Alanhardisty
please add autodiscover.companyname.co.uk  also
I forgot to mention about autodiscover in my post
0
 

Author Comment

by:jambomambo
ID: 37742728
Thanks very much for your comments guys.  I am just in the process of obtaining another certificate from GoDaddy, it looks like they have a UCC option recommended for Exchange.  Hopefully this will sort it. I will let you know...
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 2000 total points
ID: 37742741
It should do.  Use the New Certificate Wizard to generate the Request in the Exchange Management console> Server Config> New Certificate Wizard.
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange sat down with resident SQL expert, Jim Horn, for an in-depth look into the makings of a successful career in SQL.
Eseutil Hard Recovery is part of exchange tool and ensures Exchange mailbox data recovery when mailbox gets corrupt due to some problem on Exchange server.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…
Suggested Courses

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question