?
Solved

ActiveSync works internally, but not externally.

Posted on 2012-12-20
8
Medium Priority
?
1,147 Views
Last Modified: 2013-02-03
Hello Friends,

ActiveSync, which works internally, but not externally.

We are using exchange 2010 SP2 and Exchange Certificate is our internal root CA.

When I have test the Activesync using https://www.testexchangeconnectivity.com , getting error: " 

Testing the SSL certificate to make sure it's valid.
The SSL certificate failed one or more certificate validation checks.
Validating certificate trust for Windows Mobile devices.
Certificate trust validation failed.
Test Steps
ExRCA is attempting to build certificate chains for certificate CN=mob.domain.com.
A certificate chain couldn't be constructed for the certificate."

Please advice me to resolve/ work activesync from externally aswell.
 






Additional Details

The certificate chain couldn't be built. You may be missing required intermediate certificates.
0
Comment
Question by:binumicrosoft
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
8 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 38711120
To make Activesync work externally, buy a 3rd party SSL certificate with at least the following names included in the cert:

autodiscover.yourdomain.com
mail.yourdomain.com (or whatever you prefer to use)

Then when it is installed and enabled, Activesync should work.
0
 
LVL 3

Author Comment

by:binumicrosoft
ID: 38711248
So you mean we can not use internal CA for activeSync from externally? or any other option to use internal as well?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 38711462
The name on the certificate must be resolvable externally to the Public IP Address of your server.  Does it?

If it doesn't I would suggest buying one that does and then it will work happily.
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 
LVL 2

Expert Comment

by:matyke
ID: 38717197
You can use internal CA for ActiveSync certificate, but you need to allow not trusted certificates in activesync configuration on your mobile devices.

Do you have any other errors when checking with https://www.testexchangeconnectivity.com/
?
Try to enable "Ignore Trust for SSL" when checking ActiveSync.

Martin
0
 
LVL 3

Author Comment

by:binumicrosoft
ID: 38722098
We have installed 3rd party Exchange Certificate and the problem got resolved.

Thanks everyone!!
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 38722236
Excellent - don't forget to close the question down selecting the comment or comments that helped you solve the question.

Alan
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Suggested Courses
Course of the Month8 days, 6 hours left to enroll

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question