?
Solved

Autodiscover Exchange 2013 -- Turn off Connect to proxy servers that have this principal name in their certificate

Posted on 2013-11-11
5
Medium Priority
?
3,099 Views
Last Modified: 2013-11-14
Hi,

I am having issues with Exchange Server 2013. Autodiscover is checking the box (Only Connect To Proxy Servers That Have This Principal Name In Their Certificate). How can i disable this.

I have tried:
Set-OutlookProvider EXPR -CertPrincipalName none

but did not work.
0
Comment
Question by:harbz96
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 14

Expert Comment

by:Radweld
ID: 39641343
You have to specify a principle name otherwise how with the cert work?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39644516
What is the objective with wanting to disable the function?
If your SSL certificate is for host.example.com then fine. If it is for *.example.com then you can have problems, but usually only with Windows XP clients.

Outline the original issue, not what you believe is the fix.

Simon.
0
 

Author Comment

by:harbz96
ID: 39646125
Hi Simon.

Our certificate is for exchange.domain.com

But our proxy address is mail.domain.local

And it's looking for proxy address in certificate
0
 
LVL 14

Expert Comment

by:Radweld
ID: 39647304
Your certificate must have exchange.domain.com listed as a subject alternative name (SAN) entry or be the principle name (the default name) if the default is something else but contains the san entry you can Set-OutlookProvider EXPR -CertPrincipalName exchange.domain.com
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 39647314
You need to reconfigure Exchange to use your public name everywhere. That includes changing the internal and external host name for OWA, ActiveSync, Outlook Anywhere etc. Use a split DNS system to ensure the name resolution goes the correct place.

There should be no reason to change the OutlookProvider value if you configure the host name in Outlook Anywhere correctly.

Internal server names are not allowed on SSL certificates that expire past November 2014, so the switch to split DNS using the external name needs to happen at some point, you may as well do so for a new implementation.

Simon.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
We aren’t perfect, just like everyone else.  Check out the email errors our community caught and learn the top errors every email marketer should avoid.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses
Course of the Month11 days, 9 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question