SSL Certificate Issue

Posted on 2012-08-25
Last Modified: 2012-08-25
Renewed an SSL Cert from GoDaddy and got it installed on the single SBS 2008 server.  Internal & OWA is working fine but a domain added laptop is getting the following prompt:

There is a problem with the proxy server's certificate.  The name on the security certificate is invalid or does not match the name on target

Outlook is unable to connect the proxy server.  (Error Code 10)

Aside from that; the iphone isn't getting email either BUT:

1.  If I add a Self Assigned CERT the Iphone gets email but then the Outlook 2010 client who is currently offsite gets the Self Assigned CERT but it doesn't match the name.
2.  If I remove the CERT nothing works obviously.

What I am trying to do is get the CA CERT from GoDaddy to be assigned to site and possibly even RPC over HTTP so this will be resolved.

I'm sure I'm missing something pretty obvious.

Please advise and thanks!
Question by:BGTSLLC
    LVL 4

    Author Comment

    I ran this:

    [PS] C:\Windows\System32>get-clientaccessserver -identity “servername” |fl

    Name                           : servername
    OutlookAnywhereEnabled         : True
    AutoDiscoverServiceCN          : servername
    AutoDiscoverServiceClassName   : ms-Exchange-AutoDiscover-Service
    AutoDiscoverServiceInternalUri :
    AutoDiscoverServiceGuid        : 77378f46-2c66-4aa9-a6a6-3e7a48b19596
    AutoDiscoverSiteScope          : {Default-First-Site-Name}
    IsValid                        : True
    OriginatingServer              : XXXXFP01.domainname.local
    ExchangeVersion                : 0.1 (8.0.535.0)
    DistinguishedName              : CN=XXXXFP01,CN=Servers,CN=Exchange Administrat
                                     ive Group (FYDIBOHF23SPDLT),CN=Administrative
                                     Groups,CN=First Organization,CN=Microsoft Exch
    Identity                       :XXXXFP01
    Guid                           : 4cc6d9a5-f28b-42ee-97d9-8f96a8634876
    ObjectCategory                 : domainname.local/Configuration/Schema/ms-Exch-Exch
    ObjectClass                    : {top, server, msExchExchangeServer}
    WhenChanged                    : 8/25/2012 9:37:36 AM
    WhenCreated                    : 7/30/2010 9:49:45 AM

    Based on this article:

    This is because i’m connecting to services using the NetBIOS name of mbx1 which does not match the name on the certificate. If i run Get-ClientAccessServer -Identity mbx1 | FL i’ll see that the AutoDiscoverServiceInternalUri says https://MBX1/Autodiscover/Autodiscover.xml, this does not match the certificate. I can also check the other services and see that i get the same results for OAB, EWS, Outlook Anywhere (OA) and Exchange Active Sync (EAS). So i need to update all theses internal url’s to match the name on the cert.

    •Set-ClientAccessServer -Identity "mbx1" –AutodiscoverServiceInternalURI https://nlb.nwtraders.msft/autodiscover/autodiscover.xml


    •Set-WebServicesVirtualDirectory -Identity "mbx1\EWS (Default Web Site)" –InternalUrl  https://nlb.nwtraders.msft/EWS/Exchange.asmx

    •Set-OABVirtualDirectory -Identity “mbx1\OAB (Default Web Site)” -InternalURL https://nlb.nwtraders.msft/OAB

    •Enable-OutlookAnywhere -Server mbx1 -ExternalHostname “nlb.nwtraders.msft” -ClientAuthenticationMethod “NTLM”

    •Set-ActiveSyncVirtualDirectory -Identity “mbx1\Microsoft-Server-ActiveSync (Default Web Site)” -InternalURL https://nlb.nwtraders.msft/Microsoft-Server-Activesync

    Not sure if I am headed in the right direction.
    LVL 4

    Accepted Solution

    Ok so I deleted and re added the certificate, used DigiCerts utility and it worked for the domain laptop currently offsite.  Now I just need to confirm that iphones are picking up and this is done.
    LVL 4

    Author Comment

    Woohoo - got it all fixed!

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Suggested Solutions

    Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
    Set OWA language and time zone in Exchange for individuals, all users or per database.
    This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now