Solved

Exchange 2010 Autodiscover cerfication error

Posted on 2012-04-05
3
518 Views
Last Modified: 2012-04-13
Hello!
I have a problem with my Exchange 2010 server.
When users connect while on the domain they get the autodiscover uri from AD and that works great.
However, when connected outsite the domain - they get a certification error stating "The name on the security certification is invalid or does not match the name of the site."

I have been googling this for a while now and tryed all kinds of soloutions with no success.
I have;
Point DNS from autodiscover.domain.com TO mail.domain.com
My autodiscover Url is set to https://mail.domain.com/autodiscover/autodiscover.xml

The problem is, the cert is for mail.domain.com and this does not match with autodiscover.domain.com !

This is from testexchangeconnectivity.com

Attempting to test potential Autodiscover URL https://autodiscover.domain.com/AutoDiscover/AutoDiscover.xml
 	Testing of this potential Autodiscover URL failed.
 	
	Test Steps
 	
	Attempting to resolve the host name autodiscover.domain.com in DNS.
 	The host name resolved successfully.
 	
	Additional Details
	Testing TCP port 443 on host autodiscover.domain.com to ensure it's listening and open.
 	The port was opened successfully.
	Testing the SSL certificate to make sure it's valid.
 	The SSL certificate failed one or more certificate validation checks.
 	
	Test Steps
 	
	ExRCA is attempting to obtain the SSL certificate from remote server autodiscover.domain.com on port 443.
 	ExRCA successfully obtained the remote SSL certificate.
 	
	Additional Details
	Validating the certificate name.
 	Certificate name validation failed.
 	 Tell me more about this issue and how to resolve it
 	
	Additional Details

Open in new window


Please, anyone who could assist me?
0
Comment
Question by:tigerffs
3 Comments
 
LVL 58

Accepted Solution

by:
tigermatt earned 500 total points
ID: 37810730
>> My autodiscover Url is set to https://mail.domain.com/autodiscover/autodiscover.xml

I presume you are referring to the autodiscover URL you have set in your Service Connection Point (SCP) for internal purposes? (Set using Set-ClientAccessServer -AutodiscoverServiceInternalUri)

If so, the SCP is valid only for domain-joined machines. If you are connecting externally or from a non-domain machine, the value stored in Active Directory is not available to those computers. In these cases, Outlook automatically infers the URL, trying https://<smtp-domain>/Autodiscover/Autodiscover.xml and then https://autodiscover.<smtp-domain>/Autodiscover/Autodiscover.xml. <smtp-domain> is the part of the @ in the email address Outlook is supplied with.

In this case, the process will fail because your SSL certificate does not mention autodiscover.domain.com as a valid DNS name.

How to resolve the problem?

Purchase a Unified Communications certificate from somewhere like GoDaddy which lists the autodiscover domain in addition to the mail domain. This is the standard practice.
Remove your autodiscover.domain.com record from external DNS and instead use the SRV connection point method to direct Autodiscover to the mail.domain.com record: http://support.microsoft.com/kb/940881 - this method does require your public DNS provider to support SRV records. Many do not.
Use a wildcard certificate - not something I would recommend. I have had issues with wildcard certificates, and they are generally a lot more costly than a multi-name SAN/UC certificate anyway

-Matt
0
 
LVL 6

Expert Comment

by:emadallan
ID: 37812031
generate a new cert request from exchange 2010 and include all your FQDN, then purshace UCC   cert from a public CA.
continue your pending request in exchange 2010 console.
0
 
LVL 3

Author Closing Comment

by:tigerffs
ID: 37841787
I did the SRV though our DNS supplier and got it working, thank you for your assistance.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Large Outlook files lead to various unwanted errors and corruption issues. Furthermore, large outlook files can also make Outlook take longer to start-up, search, navigate, and shut-down. So, In this article, i will discuss a method to make your Out…
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question