Solved

Outlook 2010 Client display certificate warning for www certificate

Posted on 2013-01-29
5
530 Views
Last Modified: 2013-03-07
I do not understand why outlook keeps bothering our users regarding a SSL certificate that is in no way related to outlook, exchange or even webmail.

We have our SSL certificate with multiple names setup properly for mail.****.org but when some users start outlook, they get a warning regarding www.****.org. our website is totally unrelated to outlook, why is outlook looking to connect to www? I have checked the autodiscover and DNS and there is nothing on the mail side that points to www...

We are running Exchange 2010 SP1 CU8
Clients are 2010
Exchange is internal with a 1 to 1 NAT through the firewall
Our http website (www) is hosted outside with it's own certificate

Thanks
0
Comment
5 Comments
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38831324
Are you using single name certificate or SAN certificate ?
run test-outlookwebservices | fl and check if it reports any errors.

Verify your configuration is optimal as suggested by Sembee in his below article.
http://exchange.sembee.info/2007/install/singlenamessl.asp
0
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 500 total points
ID: 38832760
if you are "lucky" you have a catch-all record which resolves to your website.

try resolving i-do-not-exists.domain.com and if you get an IP back you know this is the case.

Try adding autodiscover.domain.com (or a SVC record which points to mail.domain.com) to solve this issue.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38835123
It is autodiscover doing its thing.
You need to see what Autodiscover is doing. It may well be that you ahve the wildcard in place, or that the URL you have configured for Autodiscover isn't correct or doesn't resolve to the correct place.
Very common problem.

get-clientaccessserver | select Identity, AutodiscoverServiceInternalURI

Check that the URL in there resolves to your Exchange server. If not, then you need to correct things.

Simon.
0
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38904943
run test-outlookwebservices | fl command on exchange powershell and check if it reports any errors. if yes, then we need to fix those errors first. If possible post the results here.
0
 

Author Comment

by:Information Technology
ID: 38962028
I think the issue is solved. Issue was DNS related and there was no host name for auto discover internally so by default the *.<domain> goes to the same IP as the main www site... After adding a host name entry for autodiscover internally and pointing it to the exchange server it worked. It's strange cause the srv entries were there and working but I guess the outlook client check the hostname first and uses that maybe first...
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
Find out what you should include to make the best professional email signature for your organization.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now