Solved

Exchange TLS certificate expired

Posted on 2013-05-16
11
1,061 Views
Last Modified: 2013-09-12
Hi Experts,

I have an issue where a security certificate expired the other day on our SBS server and i continually get this message in my event logs. I have followed the Microsoft article to renew the certificate with the same thumb print but the error still occurs.

I also have tried server restarts, importing the new certificate into the trusted certificate list but still the error appears.

It is an SBS 2008 server, please see below for full error message.

Source: MSExchangeTransport
Category: TransportService
Event ID: 12016
User (If Applicable): N/A
Computer: ExchangeServer.Domain.Local
Event Description: There is no valid SMTP Transport Layer Security (TLS) certificate for the FQDN of remote.domain.com.au. The existing certificate for that FQDN has expired. The continued use of that FQDN will cause mail flow problems. A new certificate that contains the FQDN of remote.domain.com.au should be installed on this server as soon as possible. You can create a new certificate by using the New-ExchangeCertificate task.
Event Log Name: Application
Event Log Type: error


Look forward to reading your comments
0
Comment
Question by:isdd2000
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 25

Expert Comment

by:Tony1044
Comment Utility
0
 
LVL 4

Expert Comment

by:iammorrison
Comment Utility
The main question is who is the CA? Is it self signed, internal CA or external CA?
0
 

Author Comment

by:isdd2000
Comment Utility
Hi tony,
Yes I have tried importing the certificate into the sbs console.

Hi Jammorrison,
It's self assigned
0
 
LVL 4

Expert Comment

by:iammorrison
Comment Utility
Do any of the certs that you have tried show up in either the excahnge console or in shell? And if they do show up, is it stating that there is no private key associated?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
Comment Utility
As this is SBS, if you don't want to use a commercial certificate, then just run the Configure my Internet Name wizard in the console. That will generate a new certificate.

Simon.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:isdd2000
Comment Utility
Will try that Sembee2
0
 

Author Comment

by:isdd2000
Comment Utility
Hi guys,

Sorry I know this has been a long standing issue.

Sembee2: I cant find configure my internet name in the console.

Jammorrison: where is it in the console?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
Comment Utility
it is called setup your internet address, and is on the Network, Connectivity section.
Running fix my network should also resolve the issue.

Simon.
0
 

Author Comment

by:isdd2000
Comment Utility
Hi Simon,

Will this effect our current configuration?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
Comment Utility
Shouldn't do. Just make sure that the settings are the same as what you have now.
Fix my network shouldn't change anything, but it depends what that tool finds.

Simon.
0
 

Author Closing Comment

by:isdd2000
Comment Utility
Fix my network did not resolve this issue, re running setup internet address did after a server restart
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
how to add IIS SMTP to handle application/Scanner relays into office 365.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now