Link to home
Start Free TrialLog in
Avatar of betobarajas
betobarajas

asked on

Active Sync connectivity error

I have been trying to get Active Sync setup to use with HTC Android smartphones but cant seem to get it configured right.  I am using an ssl key from godaddy and added the keys to IIS7 and to the intermediate certificate authority.  The firewall is set to allow port 443 and AV is currently disabled.  This is on MS Exchange 2010 on a WS 2008 R2.  

ExRCA is testing Exchange ActiveSync.
       The Exchange ActiveSync test failed.
       
      Test Steps
       
      Attempting the Autodiscover and Exchange ActiveSync test (if requested).
       Testing of Autodiscover for Exchange ActiveSync failed.
       
      Test Steps
       
      Attempting each method of contacting the Autodiscover service.
       The Autodiscover service couldn't be contacted successfully by any method.
       
      Test Steps
       
      Attempting to test potential Autodiscover URL https://cocopah-casino.com/AutoDiscover/AutoDiscover.xml
       Testing of this potential Autodiscover URL failed.
       
      Test Steps
       
      Attempting to resolve the host name cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
      Testing TCP port 443 on host cocopah-casino.com to ensure it's listening and open.
       The port was opened successfully.
      Testing the SSL certificate to make sure it's valid.
       The SSL certificate failed one or more certificate validation checks.
       
      Test Steps
       
      ExRCA is attempting to obtain the SSL certificate from remote server cocopah-casino.com on port 443.
       ExRCA wasn't able to obtain the remote SSL certificate.
       
      Additional Details
       The certificate couldn't be validated because SSL negotiation wasn't successful. This could have occurred as a result of a network error or because of a problem with the certificate installation.
      Attempting to test potential Autodiscover URL https://autodiscover.cocopah-casino.com/AutoDiscover/AutoDiscover.xml
       Testing of this potential Autodiscover URL failed.
       
      Test Steps
       
      Attempting to resolve the host name autodiscover.cocopah-casino.com in DNS.
       The host name couldn't be resolved.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       Host autodiscover.cocopah-casino.com couldn't be resolved in DNS InfoDomainNonexistent.
      Attempting to contact the Autodiscover service using the HTTP redirect method.
       The attempt to contact Autodiscover using the HTTP Redirect method failed.
       
      Test Steps
       
      Attempting to resolve the host name autodiscover.cocopah-casino.com in DNS.
       The host name couldn't be resolved.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       Host autodiscover.cocopah-casino.com couldn't be resolved in DNS InfoDomainNonexistent.
      Attempting to contact the Autodiscover service using the DNS SRV redirect method.
       ExRCA failed to contact the Autodiscover service using the DNS SRV redirect method.
       
      Test Steps
       
      Attempting to locate SRV record _autodiscover._tcp.cocopah-casino.com in DNS.
       The Autodiscover SRV record wasn't found in DNS.
        Tell me more about this issue and how to resolve it

Help Please.
SOLUTION
Avatar of ash007
ash007
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of betobarajas
betobarajas

ASKER

Thanks!  I just added the A record and SRV record on the Godaddy domain dns zones, and this is now the new log:

ExRCA is testing Exchange ActiveSync.
       The Exchange ActiveSync test failed.
       
      Test Steps
       
      Attempting the Autodiscover and Exchange ActiveSync test (if requested).
       Testing of Autodiscover for Exchange ActiveSync failed.
       
      Test Steps
       
      Attempting each method of contacting the Autodiscover service.
       The Autodiscover service couldn't be contacted successfully by any method.
       
      Test Steps
       
      Attempting to test potential Autodiscover URL https://cocopah-casino.com/AutoDiscover/AutoDiscover.xml
       Testing of this potential Autodiscover URL failed.
       
      Test Steps
       
      Attempting to resolve the host name cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 208.109.181.129
      Testing TCP port 443 on host cocopah-casino.com to ensure it's listening and open.
       The port was opened successfully.
      Testing the SSL certificate to make sure it's valid.
       The SSL certificate failed one or more certificate validation checks.
       
      Test Steps
       
      ExRCA is attempting to obtain the SSL certificate from remote server cocopah-casino.com on port 443.
       ExRCA wasn't able to obtain the remote SSL certificate.
       
      Additional Details
       The certificate couldn't be validated because SSL negotiation wasn't successful. This could have occurred as a result of a network error or because of a problem with the certificate installation.
      Attempting to test potential Autodiscover URL https://autodiscover.cocopah-casino.com/AutoDiscover/AutoDiscover.xml
       Testing of this potential Autodiscover URL failed.
       
      Test Steps
       
      Attempting to resolve the host name autodiscover.cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 66.62.42.230
      Testing TCP port 443 on host autodiscover.cocopah-casino.com to ensure it's listening and open.
       The specified port is either blocked, not listening, or not producing the expected response.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       A network error occurred while communicating with the remote host.
      Attempting to contact the Autodiscover service using the HTTP redirect method.
       The attempt to contact Autodiscover using the HTTP Redirect method failed.
       
      Test Steps
       
      Attempting to resolve the host name autodiscover.cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 66.62.42.230
      Testing TCP port 80 on host autodiscover.cocopah-casino.com to ensure it's listening and open.
       The specified port is either blocked, not listening, or not producing the expected response.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       A network error occurred while communicating with the remote host.
      Attempting to contact the Autodiscover service using the DNS SRV redirect method.
       ExRCA failed to contact the Autodiscover service using the DNS SRV redirect method.
       
      Test Steps
       
      Attempting to locate SRV record _autodiscover._tcp.cocopah-casino.com in DNS.
       The Autodiscover SRV record was successfully retrieved from DNS.
       
      Additional Details
       The Service Location (SRV) record lookup returned host mail.cocopah-casino.com.
      Attempting to test potential Autodiscover URL https://mail.cocopah-casino.com/Autodiscover/Autodiscover.xml
       Testing of this potential Autodiscover URL failed.
       
      Test Steps
       
      Attempting to resolve the host name mail.cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 66.62.42.230
      Testing TCP port 443 on host mail.cocopah-casino.com to ensure it's listening and open.
       The specified port is either blocked, not listening, or not producing the expected response.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       A network error occurred while communicating with the remote host.
SOLUTION
Avatar of Chris
Chris
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
On our Cisco firewall we have access rules setup to permit http and https to 66.62.42.230.  I run port query on localhost and port 80 and and 443 are listening but when running port query on mail.cocopah-casino.com  the port is filtered.  This definitely tells me it is a firewall problem but I am unsure why that is.  SMTP traffic works fine and the access rule is setup just the same.  All roles are installed on same server 66.62.42.230. When I browse to the external active sync website the connection times out, when browse the internal active sync website I get the following error:

Server Error in '/Microsoft-Server-ActiveSync' Application.
Configuration Error
Description: An error occurred during the processing of a configuration file required to service this request. Please review the specific error details below and modify your configuration file appropriately.

Parser Error Message: Could not load file or assembly 'Microsoft.Exchange.Security, Version=14.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35' or one of its dependencies. Failed to grant permission to execute. (Exception from HRESULT: 0x80131418)

Source Error:


[No relevant source lines]


Source File: web.config    Line: 1509

On IIS the connection times out for mail.cocopah-casino.com on the bindings for port 80 and 443.

The connection has timed out
     
     
     
     
     
       
       
          The server at mail.cocopah-casino.com is taking too long to respond.
       

       
       

  The site could be temporarily unavailable or too busy. Try again in a few
    moments.
  If you are unable to load any pages, check your computer's network
    connection.
  If your computer or network is protected by a firewall or proxy, make sure
    that Firefox is permitted to access the Web.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Without using autodisover I get the following log.  

ExRCA is testing Exchange ActiveSync.
       The Exchange ActiveSync test failed.
       
      Test Steps
       
      Attempting to resolve the host name mail.cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 66.62.42.230
      Testing TCP port 443 on host mail.cocopah-casino.com to ensure it's listening and open.
       The port was opened successfully.
      Testing the SSL certificate to make sure it's valid.
       The certificate passed all validation requirements.
       
      Test Steps
       
      ExRCA is attempting to obtain the SSL certificate from remote server mail.cocopah-casino.com on port 443.
       ExRCA successfully obtained the remote SSL certificate.
       
      Additional Details
       Remote Certificate Subject: CN=mail.cocopah-casino.com, OU=Domain Control Validated, O=mail.cocopah-casino.com, Issuer: SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US.
      Validating the certificate name.
       The certificate name was validated successfully.
       
      Additional Details
       Host name mail.cocopah-casino.com was found in the Certificate Subject Common name.
      Validating certificate trust for Windows Mobile devices.
       The certificate is trusted and all certificates are present in the chain.
       
      Test Steps
       
      ExRCA is attempting to build certificate chains for certificate CN=mail.cocopah-casino.com, OU=Domain Control Validated, O=mail.cocopah-casino.com.
       One or more certificate chains were constructed successfully.
       
      Additional Details
       A total of 2 chains were built. The highest quality chain ends in root certificate OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US.
      Analyzing the certificate chains for compatability problems with Windows Phone devices.
       Potential compatibility problems were identified with some versions of Windows Phone.
        Tell me more about this issue and how to resolve it
       
      Additional Details
      ExRCA is analyzing intermediate certificates that were sent down by the remote server.
       All intermediate certificates are present and valid.
       
      Additional Details
      Testing the certificate date to confirm the certificate is valid.
       Date validation passed. The certificate hasn't expired.
       
      Additional Details
       The certificate is valid. NotBefore = 5/25/2012 4:50:09 AM, NotAfter = 5/2/2013 8:59:29 PM
      Checking the IIS configuration for client certificate authentication.
       Client certificate authentication wasn't detected.
       
      Additional Details
       Accept/Require Client Certificates isn't configured.
      Testing HTTP Authentication Methods for URL https://mail.cocopah-casino.com/Microsoft-Server-ActiveSync/.
       The HTTP authentication test failed.
       
      Additional Details
       An HTTP 500 response was returned from Unknown.

The smartphone device gives error "Authentication failed.  Please verify username adn or password.
with the NAT fixed and the SSL checks being completed you can cross the firewall out
but if you are getting those kind of errors its the exchange server thats having issues.

You need to check the config of the activesync urls and the other bits to make sure they are configured correctly

have a quick run through Exchange Best Practise analyser

you should also check the permissions on the Exchange Virtual directories to make sure they are set correctly

what service packs do you have on?
I reset the virtual directories in MS Exchange and deleted them in IIS7.  I had a feeling that IIS7 was corrupted so I uninstalled the webserver role and installed it back again.  We were constantly getting a kerberos authentication error when opening the EMC.  That error would usually clear with a restart but now its not.  

The following error occurred while attempting to connect to the specified Exchange server 'cocopah-mail.cocopahcasino.local':

The attempt to connect to http://cocopah-mail.cocopahcasino.local/PowerShell using "Kerberos" authentication failed: Connecting to remote server failed with the following error message : The WinRM client sent a request to an HTTP server and got a response saying the requested HTTP URL was not available. This is usually returned by a HTTP server that does not support the WS-Management protocol. For more information, see the about_Remote_Troubleshooting Help topic.

When I open the shell I get this error:

VERBOSE: Connecting to COCOPAH-MAIL.cocopahcasino.local
[cocopah-mail.cocopahcasino.local] Connecting to remote server failed with the following error message : The WinRM clie
nt sent a request to an HTTP server and got a response saying the requested HTTP URL was not available. This is usually
 returned by a HTTP server that does not support the WS-Management protocol. For more information, see the about_Remote
_Troubleshooting Help topic.
    + CategoryInfo          : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [], PSRemotingTransportExc
   eption
    + FullyQualifiedErrorId : PSSessionOpenFailed

I need to clear this error before I can continue ActiveSync troubleshooting, I'll be researching the root cause.
here is a technet blog detailing some EMC issues
have a look a little bit down the page and the same error is detailed there with a fix

http://blogs.technet.com/b/exchange/archive/2010/02/04/3409289.aspx
The above suggestion did not work.  This is an error on the event log, I am researching.

The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (http://+:80/wsman/) in HTTP.SYS.

 No remote requests will be serviced on that URL.

 User Action
 Please use "netsh http" to check if ACL for URL (http://+:80/wsman/) is set to Network Service.

 Additional Data
 The error code received from HTTP.sys is 5: %%5
have you checked the bindings on the websites - it sounds like they might be wrong
that and make sure the winmanagement service is set to the right account
These are the bindings:  User generated imageThe Win-management service is set to Network Service and running.
I installed MS exchange on a different server and where it asks you to select a server to connect for remote powershell I selected the original server and received this error:

---------------------------
Microsoft Exchange
---------------------------
The attempt to connect to http://cocopah-mail.cocopahcasino.local/PowerShell using "Kerberos" authentication failed: Connecting to remote server failed with the following error message : <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
 For more information, see the about_Remote_Troubleshooting Help topic.

---------------------------
OK  
---------------------------


I only installed the mailbox role on the new server and it connects just fine to that one.  Is there a way to move the mailboxes from the original database to the now new mailbox database?

I tried looking for the local move request but it only seems to be available for moving mailboxes from the new mailbox database into the original database.

We are planning on reinstalling the OS on the original exchange server.
Nevermind after clearing the previous local move request the option to use the local move request is now available.  I already moved a test mailbox successfully. I'm burning too much time figuring this problem, we will move the mailbox to the new server and reinstall the OS on the failed mail server and start fresh with all installs.  I will update, hopefully Active-sync works after all this.  Thanks.
How can you delete a corrupted unused mailbox store?  Since we reinstalled the OS, the old mailbox store is still showing up in the new exchange server and causing errors.
When trying to create a new mailbox on the new database store, this error comes up.  I think its because its still seeing the corrupted mailbox and not letting me do anything till I fix that.  
Error:
>You must provide a value for this property.
>Click here for help... http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.141).aspx?v=14.1.355.1&t=exchgf1&e=ms.exch.err.ExF0DCB8
>
>Exchange Management Shell command attempted:
>Enable-Mailbox -Identity 'cocopahcasino.local/Cocopah Users/Christian Meza' -Alias 'cmeza'
>
>Elapsed Time: 00:00:00

User generated image
Exchange local move request of all mailboxes went fine and I created new connectors for the Hub transport role and deleted the old ones.  Exchange is currently functional but I cannot create new mailboxes.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The only mailbox showing up is the currently working mailbox.  I had previously seen that I needed to delete that container through ADSI edit and did it but its still showing up on EMC.  I just finished uninstalling the secondary mailbox role that was installed as backup and that one removed just fine.  I couldn't do this with the old server because it was failing when trying to remove roles.
Fixed!  

For reference the containers where under Configuartion

CN = Microsoft Exchange
CN = Cocopah Casino
CN = Administrative Group
CN = Database
CN = Mailbox Database

I deleted the corrupted mailbox and corrupted public folder and I am now able to create new mailboxes.  Finally can move back to setting up Active Sync.  Thanks.
ExRCA is testing Exchange ActiveSync.
       Exchange ActiveSync was tested successfully.
       
      Test Steps
       
      Attempting to resolve the host name mail.cocopah-casino.com in DNS.
       The host name resolved successfully.
       
      Additional Details
       IP addresses returned: 66.62.42.230
      Testing TCP port 443 on host mail.cocopah-casino.com to ensure it's listening and open.
       The port was opened successfully.
      Testing the SSL certificate to make sure it's valid.
       The certificate passed all validation requirements.
       
      Test Steps
       
      ExRCA is attempting to obtain the SSL certificate from remote server mail.cocopah-casino.com on port 443.
       ExRCA successfully obtained the remote SSL certificate.
       
      Additional Details
      Validating the certificate name.
       The certificate name was validated successfully.
       
      Additional Details
       Host name mail.cocopah-casino.com was found in the Certificate Subject Common name.
      Validating certificate trust for Windows Mobile devices.
       The certificate is trusted and all certificates are present in the chain.
       
      Test Steps
       
      ExRCA is attempting to build certificate chains for certificate CN=mail.cocopah-casino.com, OU=Domain Control Validated, O=mail.cocopah-casino.com.
       One or more certificate chains were constructed successfully.
       
      Additional Details
      Analyzing the certificate chains for compatability problems with Windows Phone devices.
       Potential compatibility problems were identified with some versions of Windows Phone.
        Tell me more about this issue and how to resolve it
       
      Additional Details
      ExRCA is analyzing intermediate certificates that were sent down by the remote server.
       All intermediate certificates are present and valid.
       
      Additional Details
      Testing the certificate date to confirm the certificate is valid.
       Date validation passed. The certificate hasn't expired.
       
      Additional Details
       The certificate is valid. NotBefore = 6/3/2012 10:27:38 PM, NotAfter = 5/2/2013 8:59:29 PM
      Checking the IIS configuration for client certificate authentication.
       Client certificate authentication wasn't detected.
       
      Additional Details
      Testing HTTP Authentication Methods for URL https://mail.cocopah-casino.com/Microsoft-Server-ActiveSync/.
       The HTTP authentication methods are correct.
       
      Additional Details
      An ActiveSync session is being attempted with the server.
       Testing of an Exchange ActiveSync session completed successfully.
       
      Test Steps
       
      Attempting to send the OPTIONS command to the server.
       The OPTIONS response was successfully received and is valid.
       
      Additional Details
      Attempting the FolderSync command on the Exchange ActiveSync session.
       The FolderSync command completed successfully.
       
      Additional Details
      Attempting the initial sync to the Inbox folder. This initial sync won't return any data.
       The Sync command completed successfully.
       
      Additional Details
      Attempting to test the GetItemEstimate command for the Inbox folder.
       ExRCA successfully received the GetItemEstimate response from the server.
       
      Additional Details
      Attempting to test synchronization of the Inbox folder.
       The Sync command completed successfully.
       
      Additional Details

I have already Sync the first HTC Android phone successfully.  Thank you!
Thanks