Solved

Outlook 2010 Client display certificate warning for www certificate

Posted on 2013-01-29
5
531 Views
Last Modified: 2013-03-07
I do not understand why outlook keeps bothering our users regarding a SSL certificate that is in no way related to outlook, exchange or even webmail.

We have our SSL certificate with multiple names setup properly for mail.****.org but when some users start outlook, they get a warning regarding www.****.org. our website is totally unrelated to outlook, why is outlook looking to connect to www? I have checked the autodiscover and DNS and there is nothing on the mail side that points to www...

We are running Exchange 2010 SP1 CU8
Clients are 2010
Exchange is internal with a 1 to 1 NAT through the firewall
Our http website (www) is hosted outside with it's own certificate

Thanks
0
Comment
5 Comments
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38831324
Are you using single name certificate or SAN certificate ?
run test-outlookwebservices | fl and check if it reports any errors.

Verify your configuration is optimal as suggested by Sembee in his below article.
http://exchange.sembee.info/2007/install/singlenamessl.asp
0
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 500 total points
ID: 38832760
if you are "lucky" you have a catch-all record which resolves to your website.

try resolving i-do-not-exists.domain.com and if you get an IP back you know this is the case.

Try adding autodiscover.domain.com (or a SVC record which points to mail.domain.com) to solve this issue.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38835123
It is autodiscover doing its thing.
You need to see what Autodiscover is doing. It may well be that you ahve the wildcard in place, or that the URL you have configured for Autodiscover isn't correct or doesn't resolve to the correct place.
Very common problem.

get-clientaccessserver | select Identity, AutodiscoverServiceInternalURI

Check that the URL in there resolves to your Exchange server. If not, then you need to correct things.

Simon.
0
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38904943
run test-outlookwebservices | fl command on exchange powershell and check if it reports any errors. if yes, then we need to fix those errors first. If possible post the results here.
0
 

Author Comment

by:Information Technology
ID: 38962028
I think the issue is solved. Issue was DNS related and there was no host name for auto discover internally so by default the *.<domain> goes to the same IP as the main www site... After adding a host name entry for autodiscover internally and pointing it to the exchange server it worked. It's strange cause the srv entries were there and working but I guess the outlook client check the hostname first and uses that maybe first...
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange - Retention Policy 4 33
Exhange 2010 10 34
problem with default throttling policy 2 21
How to restrict users sending out emails to all 1 17
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
This video discusses moving either the default database or any database to a new volume.

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question