Link to home
Start Free TrialLog in
Avatar of fstinc
fstinc

asked on

ssl certificate for exchange

i ordered, paid, and installed (followed step by step instructions) a SSL certificate for exchange 2010. When I try to install outlook 2010 - i get an error message saying "the name of the security certificate is invalid or does not match the name of the site."

what should i do? this is the reason i bought the SSL to avoid the annoying pop ups

screen shot attached.
cert.PNG
Avatar of Anuroopsundd
Anuroopsundd
Flag of India image

If you click on the view certificate is it the right certificate what you configured?
Avatar of fstinc
fstinc

ASKER

yes.
Avatar of Kent Dyer
is this a "site-wide" cert?  Or is this specific to a server?  Reading: exchange.fst.lan really sounds like an "internal" behind-the-scenes lan or server name.  However, are you really dealing with a server name cert, or an Exchange server cert?  In other words, if your e-mail address is jdoe@company.com, shouldn't the cert be exchange.company.com and not exchange.fst.lan?  Look at your existing cert and check it's detail either in Internet Explorer on your Exchange server or through the MMC Snapin for certs - most likely the old one is a trusted cert..  You can download it and view it locally or get the details from your server.  I know there used to be the old tool certutil that may help too.  You may need to go back to the vendor have them re-generate the cert for you depending on your findings.

HTH,

Kent
Avatar of fstinc

ASKER

yes, exchange.fst.lan is the fqdn of my local server.
Is the cert exactly the same as your old one?  Did you switch vendors?

Kent
Avatar of fstinc

ASKER

I had a self assigned which i deleted. Amd imported new
please take a look at this tool to help generate the proper command for a CSR.

When you created your SSL did you put multiple names, or did you only put the exchange.fst.lan name?  in the above page, the extra names would go in the Subject Alternative Names area.

You want an SSL with the multiple names (a UCC/SAN type of SSL certificate) to make things easier for yourself.
Avatar of fstinc

ASKER

yes, i included exchange.fst.lan as part of the ssl cert.

when i setup outlook (internally/externally) the domain is always exchange.fst.lan.  I found that externally outlook/configuration works just fine. But connected to the internal network is when i get that error message - assuming because exchange.fst.lan is the local server so it can't process the SSL?

what's the workaround here?
Is the new cert assigned for services, like IIS?

Did you restart Exchange transport service after importing the cert?
ASKER CERTIFIED SOLUTION
Avatar of Jim Millard
Jim Millard
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial