Solved

Cannot set out of office. Auto-discover test fails. Outlook / Exchange 2010

Posted on 2013-06-17
14
41 Views
Last Modified: 2015-06-23
Hello,

Any help greatly received.

There appears to be alot of information available out there, although no clear and concise explanation of the problem at hand.

Existing and new users are unable to set the out of office within Outlook 2010 in an Exchange 2010 environment. (SBS2011)

The autodiscover internal and external url settings are https://mail.domain.com/autodiscover/autodiscover.xml with a valid SSL certificate installed.

An A record exists within DNS so that mail.domain.com resolves internally to the Exchange server.  The EWS address is also https://mail.domain.com/EWS/Exchange.asmx

Running a test autoconfiguration results with the following:  

attempting url  https://mail.domain.com/autodiscover/autodiscover.xml found through scp
autodiscover to https://mail.domain.com/autodiscover/autodiscover.xml starting
autodiscover to https://mail.domain.com/autodiscover/autodiscover.xml failed (ox800c8203)
etc etc

Local autodiscover for domain.com starting
Local autodiscover for domain.com failed (ox8004010f)

Thank you
0
Comment
Question by:utilize
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 5
14 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39253750
As this is SBS, did you setup the server using the wizards?
Do you have a trusted SSL certificate on the server? If so, does the name match what you have configured Exchange to use?
The error code you have posted is usually a DNS error, so I would check name resolution is correct.  You shouldn't have any external DNS servers in the network configuration of the workstations or server - if you need to use an external DNS server then it should be set as a forwarder in the DNS server applet.

Simon.
0
 

Author Comment

by:utilize
ID: 39253764
Hello Simon,

Indeed, wizards were used. The SSL certificate does match the configured name for Exchange and the URLs.

No external DNS servers are used.

Thank you,
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39253784
Is the certificate trusted?
If you browse to the URL mentioned for Autdiscover do you get a certificate prompt? You should just get an authentication prompt (Which will never work without error, which is to be expected).

Does the SBS server host any other web sites, except for the defaults of course.

Simon
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:utilize
ID: 39255382
the certificate is trusted, it's from a trusted external CA.

no certificate prompt, just the authentication.

SBS doesn't host any sites other than the defaults
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39256089
Lets go back to basics - in IIS Manager, look at the SSL certificate configuration and ensure that Client Certificates is set to IGNORE, not ACCEPT.
After changing it, run IISRESET and test again.

Simon.
0
 

Author Comment

by:utilize
ID: 39256126
Thanks Simon. Client Certificates are already set to Ignore on SSL.

Here are the settings:

Autodiscover:
Require SSL - NO
Client Cert - Ignore

EWS:
Require SSL - NO
Client Cert - Ignore

OAB:
Require SSL - NO
Client Cert - Ignore

RPC:
Require SSL - YES
Client Cert - Ignore
0
 

Author Comment

by:utilize
ID: 39256238
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39257059
In that case it is either a DNS configuration error or something is wrong with the SSL certificate. The error code you are getting is a cannot connect, and is usually one of those two items.

You need to check the DNS again, ensure that the client resolves it correctly.
Then you will need to speak to your SSL provider and ask about rekeying the certificate. They shoudl do that free of charge.

Simon.
0
 

Author Comment

by:utilize
ID: 39258543
thank you - i will try the rekey. I'm pretty confident that DNS is okay.
0
 

Author Comment

by:utilize
ID: 39258721
okay - the certificate has been reissued but the problem persists.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39264638
I haven't really got anything else to suggest.
This fails for a small number of reasons, and while you are confident you have DNS correct, I have to suspect that either that is the problem, or the host names aren't configured correctly.

You can try re-running the wizards in SBS again, which should correct things. Ensure that the clients are using ONLY the SBS Server for DNS, no external servers.

Simon.
0
 

Accepted Solution

by:
utilize earned 0 total points
ID: 39514325
this ended up being a problem with a stale DNS entry on a PC which wouldn't clear. A rebuild of the OS fixed the issue.
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 40845714
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question