Solved

Exchange 2010 Cert error

Posted on 2013-11-22
9
63 Views
Last Modified: 2015-06-20
Hi all,

I am looking to see if someone can link me to a workaround for issuing a new cert that includes SAN to resolve my issues on a network I inherited.

Currently - I just resolved the Free/Busy, OOF issues internally by adjusting all my internal URL's.  I have a single issue cert. that includes only webmail.domain.ca.  It has no SAN.

I know the proper resolution is to issue a multi-cert (can't recall the actual name for that right now) that includes autodiscover.domain.ca and localservername.domain.local.

Is there a workaround to Exchange 2010 that can let me prevent the Outlook pop up with security alert "servername.domain.local" and 'The name on the security certificate is invalid or does not match the name of the site'.

Thanks!
0
Comment
Question by:browningit
9 Comments
 
LVL 12

Accepted Solution

by:
Julian123 earned 250 total points
ID: 39669629
Yes, user set-clientaccessserver -autodiscoverinternalserviceuri to https://webmail.domain.ca/autodiscover/autodiscover.xml. This article has more detail: http://www.shudnow.net/2013/07/26/outlook-certificate-error-and-autodiscover-domain-com-not-working/

You will also want to do this for the other URLs Exchange uses as described here: http://www.bing.com/search?q=exchange+2010+web+serivices+urls&src=IE-TopResult&FORM=IE11TR&conversationid=.

I recommend setting the internal and external urls to use the FQDN that's on your certificate. You should make sure that that FQDN is reachable by both users inside the firewall and outside.
0
 
LVL 2

Author Comment

by:browningit
ID: 39669656
Thanks for the reply Julian.

However, it was set to the webmail.domain.ca previously, and would not resolve/time out looking for it hence my change to the internally resolve-able FQDN.

I am looking over your article now.  I can always hit the URL externally on all /ews /autodiscover /owa etc., but internally was the issue and my 'forced hand' at changing all the URL's to reflect FQDN to make sure that my users could hit the OOF buttons and so on to make it work.
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 250 total points
ID: 39669759
You need a split DNS so the external host name resolves internally.
http://semb.ee/splitdns

Then you can configure everything to use the external host name internally.

Simon.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 2

Author Comment

by:browningit
ID: 39669793
Looks like a reasonable solution sembee, I'll hammer that out after hours today and see what happens.  

Thanks!
0
 
LVL 12

Expert Comment

by:Julian123
ID: 39670074
Agreed, the urls mentioned in the article I sent above must be reachable internally and proper DNS configuration will enable that..
0
 
LVL 2

Author Comment

by:browningit
ID: 39673547
Simon,

I just flipped all the records for internal URL's back to webmail, and configured the internal DNS server ( hosted on another virtual server internally ) as suggested.  I am essentially back at square one.  I have an SRV record, and the new zone for webmail.domain.ca pointing to my internal IP for the Exchange server.  Doesn't fly.  No OOF, no Free/Busy.
0
 
LVL 2

Author Comment

by:browningit
ID: 39673601
Tentatively, I appear to have resolved it through catching a typo, and making some other network changes.  More testing and an update on the matter tomorrow.

As far as my message about DNS testing not working, it could be related to a record I am unable to clear linking to the previous and dead DNS server.
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40841367
I've requested that this question be closed as follows:

Accepted answer: 500 points for Simon Butler (Sembee)'s comment #a39669759

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2016 OWA 3 47
Save Exchange PowerShell Command 12 29
Using an iCal Calendar Subscription in Outlook 4 28
Autodiscover is not working for one user 1 28
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
In this step by step procedure, you will come to know the details of creating an Outlook meeting in 2007, 2010, 2013 & 2016.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
how to add IIS SMTP to handle application/Scanner relays into office 365.

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question