Solved

Exchange 2013 Auto Discover SSL annoyance

Posted on 2013-11-10
4
336 Views
Last Modified: 2013-11-17
We have recently purchased a GeoTrust EV SSL certificate to prevent those annoying SSL warnings when you start outlook 2013.

The errors seem to have some almost completely, however...

The certificate has been issued for an FQDN, e.g. "exchange.domain.com".
Our internal domain (AD)/hostname for that server is "exchange2013.company.corp"

Most of the errors seem fixed, I even ran some scripts to update autodiscover issues.
http://jaworskiblog.com/2013/04/13/setting-internal-and-external-urls-in-exchange-2013/

But, when outlook starts, it still asks to accept a certificate for "exchange2013.company.corp" and not the correct URL "exchange.domain.com"
Mind you, under outlook settings, I have changed the msstd to exchange.domain.com

It seems the configuration on the server still has a reference to "autodiscover.company.corp" (complains about this too) and "exchange2013.company.corp". I tried browsing using ADSIedit, but can't find it...

Anyone, any idea?
0
Comment
Question by:redworks
  • 2
4 Comments
 
LVL 18

Expert Comment

by:Peter Hutchison
Comment Utility
Your certificate will require multiple alternate names so it should include external, internal names and the Autodiscover name as well included in the same certificate.

http://exchangeserverpro.com/exchange-server-2013-ssl-certificates/

The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default).
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
Comment Utility
@ cmsxpjh

"The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default). "

This is incorrect information, as is this:

"Your certificate will require multiple alternate names so it should include external, internal names"

The settings you have applied are blank by default and should be left blank. They have nothing to do with Autodiscover and are not the cause of this problem.
Internal names are not possible on SSL certificates which are valid after November 2014. Therefore there is no requirement to include them.

The error is probably from Autodiscover which is set on the Client Access Server properties.

get-clientaccessserver | select identity, AutodiscoverServiceInternalURI

The host name listed should be one that matches your trusted certificate.

Simon.
0
 

Accepted Solution

by:
redworks earned 0 total points
Comment Utility
Turns out there were some old, self signed certificates, bound to the SMTP.
When I removed those, reapplied EV certificate to SMTP (seemed to be have done already, but appearantly not fully). Then it stopped complaining.
0
 

Author Closing Comment

by:redworks
Comment Utility
this is the solution
0

Featured Post

Wish Marketing would stop bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now