Solved

Exchange certificate and webpage certificate conflict

Posted on 2013-06-13
8
190 Views
Last Modified: 2013-06-17
Hello guys,
I have a correct certificate to my exchange server that works perfectly when connecting to /owa etc.
The problem is that when I try to use auto-discover in outlook, it tries domain.com first instead of mail.domain where the correct cert. is.
The domain.com uses another cert. to our secure webpage.
Is it possible to fix it, without adding the auto-discover entries in the other cert.
Thanks
0
Comment
Question by:macxpres
  • 4
  • 4
8 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39244548
Internally it shouldn't be trying to connect to the root of the domain. It should go straight to the value configured within Exchange.

Externally it isn't possible to stop it trying to use the root of the domain, as that is a preconfigured value. Furthermore, mail.example.com isn't one of the names that it tries. Therefore you either need to ensure that you have autodiscover.example.com in the SSL certificate, or configure SRV records. http://semb.ee/srv
You will have to ensure that autodiscover.example.com doesn't resolve, so no wildcard entries in the DNS. It will still try and use it, but will time out.

Simon.
0
 

Author Comment

by:macxpres
ID: 39244572
I already have a srv-record that points to the mail server: mail.domain.com
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39244714
Does Autodiscover resolve?

Simon.
0
 

Author Comment

by:macxpres
ID: 39244744
Yes:
_autodiscover._tcp.domain.com resolves to mail.domain.com.
0
Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39244995
That wasn't what I meant.
Does autodiscover.example.com resolve anywhere?

Simon.
0
 

Author Comment

by:macxpres
ID: 39246792
Yes, it resolves to the exchange servers external IP.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39248370
That will be part of the problem.
If you are using SRV records and do not have autodiscover.example.com in the SSL certificate then you must ensure that autodiscover.example.com does not resolve anywhere. That will usually mean removing the entry from DNS and any wilkdcard in the DNS being removed as well.

Simon.
0
 

Author Closing Comment

by:macxpres
ID: 39252362
Thanks for all your help
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now