Solved

Problem with site security certificate in Exchange 2010

Posted on 2013-12-25
7
238 Views
Last Modified: 2014-01-09
We have security certificate from trusted authority but now we are getting below error of certificate.

"The name on security certificate is invalid or does not mach the name of the site"

This error pops up frequently in outlook. Kindly assist for the same.
Cert-Error.jpg
0
Comment
Question by:sanjayambre
7 Comments
 
LVL 10

Expert Comment

by:Korbus
ID: 39739248
Can I assume you have a different internal (e.g. exchserv.lanname.local)and external (e.g. mail.domainname.com) server name for your exchange server?   Is that internal name on the certificate?

If this is your issue (answered yes & no above): here is a workaround - you can create a LOCAL dns entry on network to point the external name to your internal exchange server IP address.  (note this will NOT match what the internet says for the giving domain name- which will specify your WAN IP.)  You can then configure outlook using the external name and it will find the server and match the cert.
0
 
LVL 19

Expert Comment

by:Patricksr1972
ID: 39739282
Hi,

For this setup you need à SAN certificate (Subject Alternative Name) which contains your internal domain and your external domain.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 39739500
Patrick, after 2015, internal names can no longer be used on SAN certificates.

So you are better off setting your Internal URLs to match your External URLs and then using split brain DNS, where you have a non-authoritative copy of your external DNS namespace on your internal DNS servers.
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:sanjayambre
ID: 39739692
Yes. we have different internal (e.g. exchserv.lanname.local)and external (e.g. mail.domainname.com) server name for exchange server. Error pops-up is related with internal server name.
0
 
LVL 8

Accepted Solution

by:
vSolutionsIT earned 300 total points
ID: 39739778
use your external domain name mentioned in the certificate and configure your exchange services as mentioned in below articles then check if you are still facing this issue.

http://www.msexchange.org/articles-tutorials/exchange-server-2007/management-administration/configuring-exchange-server-2007-web-services-urls.html

http://exchange.sembee.info/2007/install/singlenamessl.asp
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 39740567
Yep, just make your internal URLs match your external URLs in Exchange and use split brain DNS to create those external records to map to internal IPs.
0
 
LVL 10

Expert Comment

by:Korbus
ID: 39741248
That's called "split-brain DNS"? LOL, love it!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question