Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How to stop certificate errors on new Exchange 2013 CAS server running in 2010 environment.

Posted on 2014-09-05
6
451 Views
Last Modified: 2014-09-15
We are in the process of migrating all of our servers away from exchange 2010 and onto exchange 2013 with the long term view of migrating mailboxes to exchange online in a hybrid environment. I began by introducing the Exchange 2013 server with the CAS and Mailbox role. We use round robin DNS for our CAS with the internal URL matching the external webmail address so I ran the set-clientaccessserver -identity -servername - autodiscoverserviceinternalUri https://domain.org/autodiscover/autodiscover.xml and then began migrating mailboxes across for testing.

All email come through and send ok however I receive certificate errors stating that the server name does not match the certificate. Can anyone help me?

I am not sure what the next step to take is.
0
Comment
Question by:MSSC_support
  • 3
  • 3
6 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40306103
You need to ensure that you have a certificate on the new server and all of the URLs are correct. Adjusting just the Autodiscover one is NOT enough.
Pointing the URLs at the Exchange 2010 server isn't going to work either.
You need a URL for Exchange 2010 and a URL for exchange 2013.

Simon.
0
 

Author Comment

by:MSSC_support
ID: 40306123
Hi Simon,

Apologies if I am a little slow in understanding what you are saying. I have a URL for the new and old server. The new 2013 server has the certificate too that was used on 2010. This will eventually replace the 2010 server. The entry is also in DNS so that the certificate error doesn't get thrown but it still does.

Have I missed anything here?

Thanks
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40306162
You cannot use the same URL for both servers.

The only time you could use the same URL is if you were doing a big bang, where everyone is being migrated in a very short space of time.

At the very least, you need to have the current URL going to Exchange 2013, with a legacy URL on the older server. Exchange will proxy some web based traffic, but others it will redirect.

Simon.
0
Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

 

Author Comment

by:MSSC_support
ID: 40306179
Also, should I point the autodiscover for all the exchange 2010 servers to the new exchange 2013 cas server as currently the old 2010 environment I have left as is and only ammended autodiscover for the new exchange CAS server.

Is the 2013 cas server role backward compatible? Can I just point all the mailboxes to that CAS server instead?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40307422
Point all of your current URLs at the Exchange 2013 server and configure a new legacy URL for the Exchange 2010 server, with the exception of the Autodiscover URL.

With regards to mailboxes though, don't change that. The behaviour changes between the Exchange versions. On Exchange 2013 all connection is through Outlook Anywhere and each user will have a unique endpoint in their client. Therefore let Outlook/Exchange redirect the traffic for you when you move the mailbox to the Exchange 2013 platform.

OWA doesn't proxy, it only redirects, so you will need to have two URLs available.

I suggest that you read the co-existence documentation on TechNet. A migration of this kind needs to be planned due to the architecture changes. You cannot really make the changes on the fly.

Simon.
0
 

Author Closing Comment

by:MSSC_support
ID: 40323332
Managed to get it working by removing the round robin DNS for the old cas servers and adding the new CAS server in there and also by configuring outlook anywhere with the external url.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question