?
Solved

Outlook 2010 Client display certificate warning for www certificate

Posted on 2013-01-29
5
Medium Priority
?
542 Views
Last Modified: 2013-03-07
I do not understand why outlook keeps bothering our users regarding a SSL certificate that is in no way related to outlook, exchange or even webmail.

We have our SSL certificate with multiple names setup properly for mail.****.org but when some users start outlook, they get a warning regarding www.****.org. our website is totally unrelated to outlook, why is outlook looking to connect to www? I have checked the autodiscover and DNS and there is nothing on the mail side that points to www...

We are running Exchange 2010 SP1 CU8
Clients are 2010
Exchange is internal with a 1 to 1 NAT through the firewall
Our http website (www) is hosted outside with it's own certificate

Thanks
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38831324
Are you using single name certificate or SAN certificate ?
run test-outlookwebservices | fl and check if it reports any errors.

Verify your configuration is optimal as suggested by Sembee in his below article.
http://exchange.sembee.info/2007/install/singlenamessl.asp
0
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 2000 total points
ID: 38832760
if you are "lucky" you have a catch-all record which resolves to your website.

try resolving i-do-not-exists.domain.com and if you get an IP back you know this is the case.

Try adding autodiscover.domain.com (or a SVC record which points to mail.domain.com) to solve this issue.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38835123
It is autodiscover doing its thing.
You need to see what Autodiscover is doing. It may well be that you ahve the wildcard in place, or that the URL you have configured for Autodiscover isn't correct or doesn't resolve to the correct place.
Very common problem.

get-clientaccessserver | select Identity, AutodiscoverServiceInternalURI

Check that the URL in there resolves to your Exchange server. If not, then you need to correct things.

Simon.
0
 
LVL 8

Expert Comment

by:vSolutionsIT
ID: 38904943
run test-outlookwebservices | fl command on exchange powershell and check if it reports any errors. if yes, then we need to fix those errors first. If possible post the results here.
0
 

Author Comment

by:Information Technology
ID: 38962028
I think the issue is solved. Issue was DNS related and there was no host name for auto discover internally so by default the *.<domain> goes to the same IP as the main www site... After adding a host name entry for autodiscover internally and pointing it to the exchange server it worked. It's strange cause the srv entries were there and working but I guess the outlook client check the hostname first and uses that maybe first...
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
This video discusses moving either the default database or any database to a new volume.
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question