Exchange Certificate update failure

Posted on 2014-02-03
Last Modified: 2014-02-10
I have an SBS 2011 Standard server with Exchange 2010.

The business recently changed it's name/domain. As a result I have changed the email domain in exchange. Exchange is being used for internal send/receive mail only, no remote access.

After completing the process, everything looks and is operating appropriately, with the exception of the certificate being updated in some fashion.

Users are using outlook 2010, as they also have some pop3 emails configured. Upon launching outlook, they immediately get a certificate warning that pops up twice. They can say yes to proceed and function normally.

The certificate warning is attached below. It references the email domain name at the top, but when I open the certificate, it appears to be for the new email domain name.

I have run the internet setup wizard multiple time, as well as the fix my network wizard without success. Is there another manual means of updating/correcting this issue?
Question by:tjwo94
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Author Comment

ID: 39830984
Additional information:

When I run an autodiscover test from an outlook client I notice these things are still referencing the old domain:

Exchange RPC
Availability URL service
Unified Message Service URL

Exchange HTTP
Availability URL service
Unified Message Service URL
Certificate Principle Name
LVL 12

Expert Comment

by:David Paris Vicente
ID: 39831194
If you are just using for internal purposes the Exchange organization, you can generate a new certificate with your internal CA, if you have one.

The SAN certificate name is probably wrong you have to generate a new SAN certificate with the correct domain .

Please take a look here:Create a New Exchange Certificate to see how you accomplish that.

LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 500 total points
ID: 39831263
After you have installed your cert did you change your Exchange Virtual directories to reflect your new domain name on the cert? Also if you users mailboxes that reside on the old exchange server your certificate will need to have the following...


You will then need to install the cert on the new Exchange server, export it and import it on any other CAS servers in your environment, including your old Exchange server.

If you do not have your old Exchange server in play then you probably just need to modify your virtual directories in the ECP or using powershell.

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Author Comment

ID: 39831435

I have not updated exchange virtual directories, and can't say that I know how. There is only one exchange server which is what I have updated.

Accepted Solution

tjwo94 earned 0 total points
ID: 39831469

Looks like you pointed me in the right direction. While determining how to update virtual directories, I came upon this:

Ran through the steps, and now my test outlook client isn't popping up cert errors. I'll check regular users tomorrow and update.
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39832125
Your mistake was making the changes in Exchange directly.
If you had ran the wizards in SBS Console it would have changed the domain for you AND generated an SSL certificate that was suitable for the task. SBS should not be managed in the same way as the full product, as you will never make all of the changes the wizards make (I read somewhere it was over 200).


Author Comment

ID: 39832151
I re ran the wizards first Simon. First the internet setup wizard to change the email domain, then a fix network wizard ti hopefully clean up any lose ends. The certificate was created, however the wizard failed to apply all the changes necessary to other exchange components in order for everything to work properly. The url I posted shows the pieces the wizard failed to complete, otherwise the wizard did a great job.

Author Closing Comment

ID: 39846821
What I found did the trick, no more cert errors. Thank for getting me looking in the right place.

Featured Post

Free Webinar: AWS Backup & DR

Join our upcoming webinar with experts from AWS, CloudBerry Lab, and the Town of Edgartown IT to discuss best practices for simplifying online backup management and cutting costs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Powershell Command for Distribution Lists 2 33
exchange 7 20
find the Exchange server name that Outlook is connected to. 6 25
office 365 5 17
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question