Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 305
  • Last Modified:

Outlook for remote users - Name on security certificate is invalid

Some of our remote users see a security alert pop up when they use Outlook 2007 and connect to our Exchange server over the internet.  Our Exchange 2007 server uses a self-signed certificate and this has been working great for many years.  We just need to import the certificate in IE and that's it.

The certificate information shows it is issued to *.ssldomain.com / Trustwave and I don't know where that comes from.  Our own certificates show up just fine under the Trusted Rood Certification Authorities in IE and everything else works just fine.

We tried to install this problem certificate, shows it installed fine but the message returns the next time Outlook is opened.  Outlook can sync just fine with our Exchange server but the security alert is annoying.  Remote computer is Windows 7 with IE10.
outlook1.jpg
outlook2.jpg
outlook3.jpg
0
rwottowa
Asked:
rwottowa
  • 3
  • 2
1 Solution
 
Adam BrownSr Solutions ArchitectCommented:
Check to see what server your autodiscover.magnetics.com DNS record is pointing to. It looks like it's currently pointing to your web hosting server, which is probably being run by SSLDomain.com. If you're using a hosted Exchange solution, you'll want to talk to your hosting provider to get a better certificate assigned.

That said, if you use a self-signed certificate with Exchange, you're going to have some issues with it for a while. Spend a little money getting a valid 3rd Party SSL SAN cert and you'll have fewer headaches to deal with (like making people install the certificate).
0
 
rwottowaAuthor Commented:
As far as i know, we don't have anything set up for autodiscover.magnetics.com, only a host record for mailserv.magnetics.com.

Should we have a host record set up for autodiscover as well and point to our Exchange server, same as mailserv?

Either way, I think switching to a third party ssl is a good idea.  Any suggestions for providers are welcome as well.
0
 
Adam BrownSr Solutions ArchitectCommented:
Here, I wrote a blog on how Autodiscover works and some tricks you can use to get it working right: http://acbrownit.wordpress.com/2012/12/20/internal-dns-and-exchange-autodiscover/

Autodiscover uses a predictable pattern for finding the right spot for where to look for configuration info. it starts looking at https://domain.com/autodiscover/autodiscover.xml and then moves on to other records. The blog post has more details.
0
 
rwottowaAuthor Commented:
I tried with adding autodiscover as a host record on our ISP.  It is seeing mailserv.magnetics.com as the name on the certificate now but still shows up every time Outlook is started.  When it is installed, it shows it was successful but still shows up again the next time.
0
 
rwottowaAuthor Commented:
Installing a 3rd party SSL certificate is the best way to go forward.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now