Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange 2013 Auto Discover SSL annoyance

Posted on 2013-11-10
4
Medium Priority
?
356 Views
Last Modified: 2013-11-17
We have recently purchased a GeoTrust EV SSL certificate to prevent those annoying SSL warnings when you start outlook 2013.

The errors seem to have some almost completely, however...

The certificate has been issued for an FQDN, e.g. "exchange.domain.com".
Our internal domain (AD)/hostname for that server is "exchange2013.company.corp"

Most of the errors seem fixed, I even ran some scripts to update autodiscover issues.
http://jaworskiblog.com/2013/04/13/setting-internal-and-external-urls-in-exchange-2013/

But, when outlook starts, it still asks to accept a certificate for "exchange2013.company.corp" and not the correct URL "exchange.domain.com"
Mind you, under outlook settings, I have changed the msstd to exchange.domain.com

It seems the configuration on the server still has a reference to "autodiscover.company.corp" (complains about this too) and "exchange2013.company.corp". I tried browsing using ADSIedit, but can't find it...

Anyone, any idea?
0
Comment
Question by:redworks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 20

Expert Comment

by:Peter Hutchison
ID: 39636824
Your certificate will require multiple alternate names so it should include external, internal names and the Autodiscover name as well included in the same certificate.

http://exchangeserverpro.com/exchange-server-2013-ssl-certificates/

The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default).
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39638121
@ cmsxpjh

"The autodiscover name is for Outlook, Outlook Anywhere and ActiveSync web services.
Configuration for this is via the Get-AutoDiscoverVirtualDirectory and Set-AutoDiscoverVirtualDirectory for the InternalUrl and ExternalUrl attributes (empty by default). "

This is incorrect information, as is this:

"Your certificate will require multiple alternate names so it should include external, internal names"

The settings you have applied are blank by default and should be left blank. They have nothing to do with Autodiscover and are not the cause of this problem.
Internal names are not possible on SSL certificates which are valid after November 2014. Therefore there is no requirement to include them.

The error is probably from Autodiscover which is set on the Client Access Server properties.

get-clientaccessserver | select identity, AutodiscoverServiceInternalURI

The host name listed should be one that matches your trusted certificate.

Simon.
0
 

Accepted Solution

by:
redworks earned 0 total points
ID: 39641607
Turns out there were some old, self signed certificates, bound to the SMTP.
When I removed those, reapplied EV certificate to SMTP (seemed to be have done already, but appearantly not fully). Then it stopped complaining.
0
 

Author Closing Comment

by:redworks
ID: 39654297
this is the solution
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

660 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question