Solved

Exchange 2010 issues after migration from SBS 2003

Posted on 2014-01-31
6
266 Views
Last Modified: 2014-11-12
Hi
Have installed Exchange 2010 on Server 2008R2 and migrated users mailboxes from SBS 2003 which is still co-existing on the network.

I have 2 issues:

1. Although owa works from the internet, iphones won't connect and application log shows Event id 1033 MSExchange Activesync "The setting ExternalProxy in the web.config file was not valid. The previous value was null and has been changed to ."

2. When opening Outlook on the Client machines, a security alert is seen. "The name on the security certificate is invalid or does not match the name of the site". The certificate is for xyz.externaldomain.com however the exchange server is ex2010.intdomain.local

Any help appreciated

Thanks

Julian
0
Comment
Question by:J-B
  • 2
  • 2
  • 2
6 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39825414
Do you have a trusted SSL certificate on the server?
If so, have you changed all URLs within Exchange to match the name on the trusted SSL certificate?

http://semb.ee/hostnames

On the ActiveSync error, that is unusual. Has any attempt been made to customise the ActiveSync configuration in any way?

Have you installed Exchange 2010 SP3 plus the latest rollup?

Simon.
0
 

Author Comment

by:J-B
ID: 39826341
Yes I have a trusted cert on the server from RapidSSL for new.domain.co.uk

I have made all the URL's internally on exchange match the name of the trusted SSL cert

Exchange 2010 SP3 is installed but no rollup packages.


This is the only error message I am getting when running the Microsoft Remote Connectivity Analyser using the Activesync option

"Analyzing the certificate chains for compatibility problems with Windows Phone devices.
       Potential compatibility problems were identified with some versions of Windows Phone.
        Tell me more about this issue and how to resolve it
       
      Additional Details
       
The certificate is only trusted on Windows Mobile 6.0 and later versions. Devices running Windows Mobile 5.0 and 5.0 with the Messaging and Security Feature Pack won't be able to sync. Root = CN=GeoTrust Global CA, O=GeoTrust Inc., C=US.
Elapsed Time: 4 ms. "

OWA access is working fine, and the iPhone will now accept and validate the settings when the account is entered however with a series of ticks, however when I check for mail i am getting the error "The connection to the server failed".

The only port I have open is 443

Julian
0
 

Author Comment

by:J-B
ID: 39826464
Right, I have it working :) But only with a newly created account.

So I guess its a permission / Active directory issue on the accounts that were moved over from SBS 2003
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39826495
Check that permission inheritance is enabled on the accounts that were moved from SBS 2003.

Simon.
0
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 500 total points
ID: 39834635
Follow this article to reapply the appropriate permissions to migrated accounts:
http://technet.microsoft.com/en-us/library/gg615504.aspx

(FYI, this is a step in the migration process, but is often missed)

Jeff
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 39834640
For the certificate issue, follow the solution referenced here:
http://www.experts-exchange.com/Q_27417843.html
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Configuring DNS Round Robin in Windows DNS server ? 8 63
Customising IE behaviour on certain pages 2 55
exchange 13 16
exchange, office 365 13 21
Find out what you should include to make the best professional email signature for your organization.
In-place Upgrading Dirsync to Azure AD Connect
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question