Link to home
Create AccountLog in
Exchange

Exchange

--

Questions

--

Followers

Top Experts

Avatar of lpadmin1
lpadmin1

The certificate status could not be determined because the revocation check failed.
Went through the whole process with godaddy on the phone.  Everything went smoothly until the last step where the cert was supposed to become active.  Then we got the error as listed in the title of this question.

Any help would be greatly appreciated as godaddy was unable to help past this point.

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Manpreet SIngh KhatraManpreet SIngh Khatra🇮🇳

How many certificates do you have in Exchange as of now ?
Get-ExchangeCertificate

- Rancy

One of my dear friends wrote this solution, take a look

http://msexchangeguru.com/2012/11/12/certificate-revocation/

Regards,
Exchange_Geek

Avatar of lpadmin1lpadmin1

ASKER

I am going to try these steps on Monday.

Rancy -

I have a 5 slot cert on our old exchange server that is coexistance, and this cert is going to be going on the new exchange server as the last step before we bring down the old server and make this one live / transfer the mailboxes over.

There are no other certs on the new one right now we are just trying to install the first one.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Actually after ru nning the command on my new server exchange 2010 it shows 3 thumbprints.  

the first one ........ as service and my domain, and OU=Domain Control Validated
the second one IP..S. as service and CN=computername of server
the third one IP.WS.  CN=computername of server

check details of these certificates

1) Expiry date
2) Services associated with.

Regards,
Exchange_Geek

The problem cert expires 4/4/18
The one below it expires 4/1/18
The bottom one expires 3/18/18

The problem one is the only one I knew of  / purchased.  Not sure if the others are there by default?

I am not sure how to tell what services are associated with each cert.
certfail.jpg

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Get-ExchangeCertificate | FL

- Rancy

thank you Rancy,

so, run the cmdlet and let us know the output

Regards,
Exchange_Geek

see screenshot
User generated image

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


As seen the 3rd one is the one with all services assigned to it .... did someone after the second add IIS and Enable again ?

- Rancy

After installing Exchange 2010 on a fresh install of 2008 R2, I got the mailflow working correctly making sure I can do the following:

Move a test mailbox over to 2010 from 2007.
Create a new mailbox on 2010.
Send / receive mail from a 2007 mailbox to a 2010 mailbox.
Send / receive mail externally to / from exchange 2010 mailbox.

After all that was tested working, I called Godaddy to get a new cert for the ex 2010 server so I could get webmail working etc and shut down the 2007 server.

Went through all the steps with godaddy and when importing the problem cert I got this error.

That was pretty much how everything went down.

Thre is currently a godaddy issued cert on the 2007 server still live that is associated with some of the fqdn's that the new one is trying to use.

Here is what I'd do.

Call up GoDaddy again, get the cert re-issued that was given last time.

Remove all the certs.

Ensure you run the above cmdlet again and shouldn't get a response.

Next, then work on importing the cert and see if it goes thru.

Regards,
Exchange_Geek

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Ok, so I should remove all 3 of those certs on the 2010 server, run the cmdlet and make sure none are displaying anymore, go through the steps with goddaddy again to get my cert and try importing it again.

Are any of the certs that I have now a type of default cert or are all 3 of them associated with what I did with godaddy?

the last one seems the one that's related to all four services.

Regards,
Exchange_Geek

Look if your going to get a new one with all those service yes you can but if you can atleast remove the first 2 ...

- Rancy

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


It appears the bottom 2 certs were self generated / self signed by the exchange server..

You're right, but the cert given by GoDaddy wasn't assigned to any services.

Regards,
Exchange_Geek

When I go through this godaddy process again after deleting all 3 certs, will it automatically register those 4 services i need to the new cert?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Yes sir.

Regards,
Exchange_Geek

I am hopefully finding time to try this today.  Ill keep you updated.

User generated image
After removing one of the self generated cert and the failed public cert from godaddy the last self generated one cannot be deleted.  

User generated image
I was told by godaddy that our server is checking a bad / cached revocation list somehow and thinks that this new cert i am trying to activate is not valid.  

I really hope we can get this resolved soon, I have already tried some things i found regarding proxies but we dont go through a proxy..  Any help appreciated.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


User generated image
I was able to force the new cert to take over the services, allowing me to remove the remaining exchange generated cert.  However it still fails revocation.

Just updating you guys.  Still trying to get the revocation to pass while waiting for your input.

Try running the IISRESET once to check if that helps

- Rancy

OK I just ran it, do I have to do something to refresh the status once this completes or should it automaticcally just show that it worked?  Because when it completed nothing happened after refreshing the view.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


User generated image
I get this error when trying to load the snapin for certificate authority on my domain controller..

could this be related to the problem?

Check if services are running and Remote registry and CA server is contactable

- Rancy

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


The DC wasnt a CA server is what I found.  I just installed the services on it and I guess will retry this cert again..  Do I have to generate a new request and go through all those steps or can i somehow just make this one that failed work?

Try with this if it was generated fine it should work fine as well .... if not we can try that other option later

- Rancy

What steps do I need to take to try and reuse this cert?  All I see is renew cert which doesnt work because it says name exists, or New Exch Cert which makes me generate a new request, and Import Cert..

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Try to Import the One you have or try it from the Exchange shell with the Enable-ExchangeCertificate command

- Rancy

I already tried it at the shell and it went through OK but it still shows the same error in the console.  Does this mean I have to redo everything :\

What if you do a Get-Exchange certificate ?
Is it possible to restart the server ?

- Rancy

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Get-ExchangeCertificate results in

Services: IP.WS.    Subject:  CN=domain.com, OU=Domain Control Validated

I can reboot it because it is not our functioning mailserver at this time.  Rebooting now

After reboot it still shows the error..  What I dont understand is this:

I downloaded the digicert utility and ran a revocation test, and it passed.  It only fails from the management console..

Why?

User generated image

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Question:  

We dont use any kind of proxy with our exchange server, but everywhere i look it mentions setting your proxy for revocation to complete..  Is this something I have to do, and are they using proxy in different context from a type of web gateway / redirection?

ASKER CERTIFIED SOLUTION
Avatar of costanoscostanos🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

That absolutely worked.  Thank you very much!
Exchange

Exchange

--

Questions

--

Followers

Top Experts

Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.