Solved

Expired / Invalid exchange certificates

Posted on 2012-04-11
7
540 Views
Last Modified: 2012-06-27
checking on one of our sbs servers (sbs 2008, exchange 2007), I can see some invalid certificates, they are also out of date.

How can I find out their use?

they are self signed, and i always seem to run into issues renewing them. what is the correct way of renewing them?
0
Comment
Question by:Neal58
  • 4
  • 2
7 Comments
 
LVL 7

Assisted Solution

by:Abbas Haidar
Abbas Haidar earned 167 total points
ID: 37833185
Step 1 - run the domain name wizard and the process of doing that it builds the self signed cert.

Step 2, http://blogs.technet.com/b/sbs/archive/2008/09/30/how-do-i-distribute-the-sbs-2008-self-signed-ssl-certificate-to-my-users.aspx The process works like that

To put it in your Forefront, export out the self signed cert and then place it in the publishing rule.  I'm not as familar about forefront as ISA so i'm guessing a bit there.

Holler if that doesn't help.
http://social.technet.microsoft.com/Forums/en-US/smallbusinessserver/thread/6ba91ebb-dffa-4211-b193-30d9f7a32949/
0
 
LVL 17

Assisted Solution

by:WORKS2011
WORKS2011 earned 333 total points
ID: 37833245
try these commands:

1. to get the thumbprint type: Get-ExchangeCertificate -domain "servername" | fl
2. thumbprint in step 1 enter in step 3.
3. type: Get-ExchangeCertificate -thumbprint "2FB28F5075EFE9B30A8F8458DED0A137629F62D7" | New-ExchangeCertificate
4. you'll confirm "overwrite existing default SMTP certificate, take the new thumbprint and enter in step 5
5. Enable-ExchangeCertificate -thumbprint "FB5AECA6B39816F 02B3245BD1D953934HD8H730F" -services IIS
0
 
LVL 4

Author Comment

by:Neal58
ID: 37833613
absi81 - i get this error when running the internet address management wizard:

Description:
  Stopped working

Problem signature:
  Problem Event Name:      CLR20r3
  Problem Signature 01:      dpcw.exe
  Problem Signature 02:      6.0.5601.8524
  Problem Signature 03:      4bb3c519
  Problem Signature 04:      mscorlib
  Problem Signature 05:      2.0.0.0
  Problem Signature 06:      4e154615
  Problem Signature 07:      20c7
  Problem Signature 08:      143
  Problem Signature 09:      N3CTRYE2KN3C34SGL4ZQYRBFTE4M13NB
  OS Version:      6.0.6002.2.2.0.305.9
  Locale ID:      2057

Read our privacy statement:
  http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409


WORKS2011 - normally that is how i would do it, but last time i did that on this server i mucked all the certificates up . . .
0
Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

 
LVL 17

Expert Comment

by:WORKS2011
ID: 37834009
what happens when you run the "Fix My Network" wizard?
0
 
LVL 17

Expert Comment

by:WORKS2011
ID: 37834038
The Domain Purchase and Configuration Wizard (dpcw.exe) can crash if DNS is having problems run dcdiag /test:dns and report the results.
0
 
LVL 4

Author Comment

by:Neal58
ID: 37836439
Fix My Network wizard:

Could not configure the router
DNS is using a DNS Forwarder
Exchange SMTP connectors are invalid
A networking component is not configured properly. (Component ID 3)
A networking component is not configured properly. (Component ID 4)

(havent clicked to fix these yet)

dcdiag /test:dns:


Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SERVER
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SERVER
      Starting test: Connectivity
         ......................... SERVER passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVER

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SERVER passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : domain

   Running enterprise tests on : domain.local
      Starting test: DNS
         Test results for domain controllers:

            DC: SERVER.domain.local
            Domain: domain.local


               TEST: Basic (Basc)
                  Warning: The AAAA record for this DC was not found

               TEST: Dynamic update (Dyn)
                  Warning: Failed to add the test record _dcdiag_test_record in
zone domain.local

               TEST: Records registration (RReg)
                  Network Adapter
                  [00000006] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Clien
t):

                     Warning:
                     Missing AAAA record at DNS server 192.168.0.200:
                     SERVER.domain.local

                     Warning:
                     Missing AAAA record at DNS server 192.168.0.200:
                     gc._msdcs.domain.local

               Warning: Record Registrations not found in some network adapters

               SERVER                    PASS WARN PASS PASS WARN WARN n/a
         ......................... domain.local passed test DNS
0
 
LVL 17

Accepted Solution

by:
WORKS2011 earned 333 total points
ID: 37837178
DNS is ok, looking at the receive connector errors I've seen where it can be a bug, check the link below (scroll to the bottom - I pasted below) explains in more detail.

Follow this link.

It seems that "Exchange SMTP connectors are invalid" message is a bug in "Fix my network" wizard. I have spend some hours in investigating the problem and noticed that the only way to avoid that stupid message is to do the following steps:
1. open exchange console
2. go to server configuration->hub transport.
3. remove all receive connectors except "Default [servername]" ( if you miss that you must create it yourself, search the web how to do it)
4. run "Fix my network" wizard again
5. when you see "Exchange SMTP connectors are invalid", allow the wizard to repair/reconfigure connectors.
6. the wizard should now succesfuly recreate missing connectors
At this moment you should have 3 connectors (if you have Internet Domain Name connected) or 2 connectors if without domain. The fix wizard should not report any invalid connectors from now.
But when you modify in any way any connector, then our message will apear again. Undoing your changes will not help (this is the bug in wizard), you will see our unwanted message until you allow the wizard to recreate connectors as described above.
Pay attention that the "Fix my network" wizard has the log file at C:\Program Files\Windows Small Business Server\Logs\fncw.log. Look this file, mayby you will see why your connetors are invalid.
I hope this help with your strugle with "Fix my network" wizard.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now