Solved

Exchange 2010 OWA, Activesync

Posted on 2012-04-10
10
728 Views
Last Modified: 2012-04-15
Yesterday I created a self-signed certificate using my Exchange Server. I was able to install and then deleted the old expired cert and two certs with no services assigned. Outlook clients are no longer getting "expired cert" message but OWA and Activesync have quit working. Also, now I can't get to cert web enrollment site. Please help!
0
Comment
Question by:DL197
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 3
10 Comments
 
LVL 7

Assisted Solution

by:raeldri
raeldri earned 250 total points
ID: 37827572
have you enabled the certifcate?

Get-Exchangecerticate | FL
Enable-ExchangeCertificate -thumbprint (pastethumbprint) -services IIS

Open in new window

0
 

Author Comment

by:DL197
ID: 37827661
[PS] C:\Windows\system32>Enable-ExchangeCertificate -thumbprint (71917B6EB8DBDA82FB367C201DE523D5191030DC) -services IIS

Bad numeric constant: 71917.
At line:1 char:46
+ Enable-ExchangeCertificate -thumbprint (71917 <<<< B6EB8DBDA82FB367C201DE523D5191030DC) -services IIS
    + CategoryInfo          : ParserError: (71917:String) [], ParentContainsErrorRecordException
    + FullyQualifiedErrorId : BadNumericConstant
0
 

Author Comment

by:DL197
ID: 37827687
[PS] C:\Windows\system32>Get-ExchangeCertificate | FL


AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule,
                     ule}
CertificateDomains : {belton.local, mail.belton.local, mail.beltontexas.g
                     autodiscover.belton.local, autodiscover.ci.belton.tx
                     .beltontexas.gov, beltonpd.local, beltontexas.gov, c
                     s.gov}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : C=US, S=TX, L=Belton, O=City of Belton, OU=Belton, C
NotAfter           : 4/9/2013 5:11:18 PM
NotBefore          : 4/9/2012 4:51:18 PM
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 4657376577E2329B437E7251904AD6D7
Services           : None
Status             : Valid
Subject            : C=US, S=TX, L=Belton, O=City of Belton, OU=Belton, C
Thumbprint         : 704B3ADA43B4FA89B254AD06F6280A0A6D12FB62

AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule,
                     ule, System.Security.AccessControl.CryptoKeyAccessRu
CertificateDomains : {belton-CITY-EX2-CA}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=belton-CITY-EX2-CA, DC=belton, DC=local
NotAfter           : 4/9/2017 3:46:37 PM
NotBefore          : 4/9/2012 3:36:38 PM
PublicKeySize      : 2048
RootCAType         : Registry
SerialNumber       : 2708CB79F0F7909648B3C2D3A7EDBB31
Services           : IMAP, IIS, SMTP
Status             : Valid
Subject            : CN=belton-CITY-EX2-CA, DC=belton, DC=local
Thumbprint         : 71917B6EB8DBDA82FB367C201DE523D5191030DC
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 7

Expert Comment

by:raeldri
ID: 37827696
remove the brackets from the thumb print sorry
0
 

Author Comment

by:DL197
ID: 37827719
Command completed successfully. OWA site still doesn't come up. Neither HTTP or HTTPS...... Restarted IIS, no luck.
0
 
LVL 7

Expert Comment

by:raeldri
ID: 37827776
What shows in the IIS access logs?
0
 

Author Comment

by:DL197
ID: 37827789
Where do I find those?
0
 

Author Comment

by:DL197
ID: 37827816
Found them @ c:\windows\system32\errorlogs\httperr. They are really long, not sure what I am looking for. See a lot of "Timer_ConnectionIdle" and "2012-04-10 13:51:20 ::1%0 49496 ::1%0 80 HTTP/1.1 POST /powershell?serializationLevel=Full;PSVersion=2.0 - 1 Connection_Dropped MSExchangePowerShellAppPool
2012-04-10 13:51:20 ::1%0 42795 ::1%0 80 HTTP/1.1 POST /PowerShell?serializationLevel=Full;clientApplication=EMC;PSVersion=2.0 - 1 Connection_Dropped MSExchangePowerShellAppPool
2012-04-10 13:51:20 ::1%0 42810 ::1%0 80 HTTP/1.1 POST /PowerShell?clientApplication=EMC;PSVersion=2.0 - 1 Connection_Dropped MSExchangePowerShellAppPool
2012-04-10 13:51:20 ::1%0 42805 ::1%0 80 HTTP/1.1 POST /PowerShell?serializationLevel=Full;clientApplication=EMC;PSVersion=2.0 - 1 Connection_Dropped MSExchangePowerShellAppPool
2012-04-10 13:51:20 ::1%0 42801 ::1%0 80 HTTP/1.1 POST /PowerShell?serializationLevel=Full;clientApplication=EMC;PSVersion=2.0 - 1 Connection_Dropped MSExchangePowerShellAppPool"
0
 

Accepted Solution

by:
DL197 earned 0 total points
ID: 37829386
I set certsrv folder to http access. I was then able to generate second cert which solved my problem. Evidently, first cert was corrupt as I generated second exactly the same.
0
 

Author Closing Comment

by:DL197
ID: 37848007
It was the method used to solve the problem.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
This is a fairly complicated script that will install the required prerequisites to install SCCM 2012 R2 on a server.  It was designed under the functional model in order to compartmentalize each step required, reducing the overall complexity.  The …
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question