ActiveSync works internally, but not externally.

Hello Friends,

ActiveSync, which works internally, but not externally.

We are using exchange 2010 SP2 and Exchange Certificate is our internal root CA.

When I have test the Activesync using https://www.testexchangeconnectivity.com , getting error: " 

Testing the SSL certificate to make sure it's valid.
The SSL certificate failed one or more certificate validation checks.
Validating certificate trust for Windows Mobile devices.
Certificate trust validation failed.
Test Steps
ExRCA is attempting to build certificate chains for certificate CN=mob.domain.com.
A certificate chain couldn't be constructed for the certificate."

Please advice me to resolve/ work activesync from externally aswell.
 






Additional Details

The certificate chain couldn't be built. You may be missing required intermediate certificates.
LVL 3
binumicrosoftAsked:
Who is Participating?
 
Alan HardistyConnect With a Mentor Co-OwnerCommented:
To make Activesync work externally, buy a 3rd party SSL certificate with at least the following names included in the cert:

autodiscover.yourdomain.com
mail.yourdomain.com (or whatever you prefer to use)

Then when it is installed and enabled, Activesync should work.
0
 
binumicrosoftAuthor Commented:
So you mean we can not use internal CA for activeSync from externally? or any other option to use internal as well?
0
 
Alan HardistyCo-OwnerCommented:
The name on the certificate must be resolvable externally to the Public IP Address of your server.  Does it?

If it doesn't I would suggest buying one that does and then it will work happily.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
matykeCommented:
You can use internal CA for ActiveSync certificate, but you need to allow not trusted certificates in activesync configuration on your mobile devices.

Do you have any other errors when checking with https://www.testexchangeconnectivity.com/
?
Try to enable "Ignore Trust for SSL" when checking ActiveSync.

Martin
0
 
binumicrosoftAuthor Commented:
We have installed 3rd party Exchange Certificate and the problem got resolved.

Thanks everyone!!
0
 
Alan HardistyCo-OwnerCommented:
Excellent - don't forget to close the question down selecting the comment or comments that helped you solve the question.

Alan
0
All Courses

From novice to tech pro — start learning today.