Solved

Exchange 2013 Auto Discover SSL annoyance

Posted on 2013-11-10
4
338 Views
Last Modified: 2013-11-17
We have recently purchased a GeoTrust EV SSL certificate to prevent those annoying SSL warnings when you start outlook 2013.

The errors seem to have some almost completely, however...

The certificate has been issued for an FQDN, e.g. "exchange.domain.com".
Our internal domain (AD)/hostname for that server is "exchange2013.company.corp"

Most of the errors seem fixed, I even ran some scripts to update autodiscover issues.
http://jaworskiblog.com/2013/04/13/setting-internal-and-external-urls-in-exchange-2013/

But, when outlook starts, it still asks to accept a certificate for "exchange2013.company.corp" and not the correct URL "exchange.domain.com"
Mind you, under outlook settings, I have changed the msstd to exchange.domain.com

It seems the configuration on the server still has a reference to "autodiscover.company.corp" (complains about this too) and "exchange2013.company.corp". I tried browsing using ADSIedit, but can't find it...

Anyone, any idea?
0
Comment
Question by:redworks
  • 2
4 Comments
 
LVL 19

Expert Comment

by:Peter Hutchison
ID: 39636824
Your certificate will require multiple alternate names so it should include external, internal names and the Autodiscover name as well included in the same certificate.

http://exchangeserverpro.com/exchange-server-2013-ssl-certificates/

The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default).
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39638121
@ cmsxpjh

"The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default). "

This is incorrect information, as is this:

"Your certificate will require multiple alternate names so it should include external, internal names"

The settings you have applied are blank by default and should be left blank. They have nothing to do with Autodiscover and are not the cause of this problem.
Internal names are not possible on SSL certificates which are valid after November 2014. Therefore there is no requirement to include them.

The error is probably from Autodiscover which is set on the Client Access Server properties.

get-clientaccessserver | select identity, AutodiscoverServiceInternalURI

The host name listed should be one that matches your trusted certificate.

Simon.
0
 

Accepted Solution

by:
redworks earned 0 total points
ID: 39641607
Turns out there were some old, self signed certificates, bound to the SMTP.
When I removed those, reapplied EV certificate to SMTP (seemed to be have done already, but appearantly not fully). Then it stopped complaining.
0
 

Author Closing Comment

by:redworks
ID: 39654297
this is the solution
0

Featured Post

Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now