Exchange 2010 changed transport server cert, now edge sync fails

Posted on 2014-09-08
Last Modified: 2014-09-08
I replaced my main exchange server's certificate and now the edgesync fails.

When I do a "Start-EdgeSynchroinzation" on the hub transport server I get:

Result: CouldNotConnect
Type: Recipients
Result: CouldNotConnect
Type: Configuration

and the "Test-EdgeSynchronization" command Returns this:

SyncStatus: Failed
UtcNow : [a few seconds ago]
FailureDetail: EdgeSync service cannot connect to this subscription because of error "No EdgeSync credentials were found for Edge Transport server. Remove the Edge subscription and re-subscribe to the Edge Transport server."
CredentialRecords: Number of credentials 0
CookieRecords: Number of cookies 0

Just to be clear it was the cert on the hub transport that was replaced, not the cert on the edge server.

I've removed the edge subscription from the hub transport server using EMC then went to the edge server and ran:

New-EdgeSubscription -FileName C:\Users\Administrator\Desktop\edge-subcription.xml

Then copied the file to the hub transport server and used "New Edge Subscription" in the EMC to re-add the subscription. After adding the subscription the EMC shows the EXCH2-EDGE subscription as valid under the "Is Valid" column.

However when I run the Start-EdgeSynchronization or Test-EdgeSynchronization commands (on the hub transport server) in the EMS I get the results I posted above. Given that it was the Hub transport that had it's cert replaced, it's likely that the edge server can't authenticate against the hub transport and not the other way around. Does anyone have any idea how I can fix this?
Question by:jdhwpgmbca
  • 3
  • 2
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40310671
What did you replace the certificate with?
A trusted certificate or self signed?

In most instances, you now need two certificates on Exchange.
- A trusted certificate for web services etc.
- A self signed certificate as the default SMTP certificate for internal traffic.

Therefore the easiest fix is to run


on the Hub transport server, no further attributes required. When prompted to replace the default SMTP certificate say Yes. Then test again.


Author Comment

ID: 40310699
A trusted cert from comodo. I just paid $600 for it, so I'm reluctant to run new-exchangecertificate on the hub transport. That would generate a new key which would need to be re-signed by the CA. Besides, I'm not convinced that doing that is any different from generating a request and having it signed by a CA then importing the cert (in EMC). It's not that the advice isn't appreciated - but I don't want to lose my new certificate.

Author Comment

ID: 40310749
I think it's likely that changing the web server certificate on the hub transport is what broke the trust between the servers. In order to re-establish the trust I have to get the edge server to refetch the ldap information containing the hub transport certificate into it's AD-LDS. I just don't know how to do this.
LVL 63

Accepted Solution

Simon Butler (Sembee) earned 500 total points
ID: 40310841
$600 for an SSL certificate? You can get ones suitable for Exchange for less than $70/year!
Anyway, I am not proposing replacing your trusted certificate, this is an additional SSL certificate for SMTP traffic only. New-Exchangecertificate on its own creates a new self signed certificate, which Exchange trusts.

Exchange wants to communicate with the server over SMTP using its real FQDN. However with SSL certificates that expire after November 2015 you cannot put internal names on the certificates, so you need to use a combination of trusted certificates and a self signed certificate.


Author Comment

ID: 40311018
There's a bunch of Subject-Alt-Names, they say that's why it's so expensive, but I think it's a rip-off. Anyway that's off topic.

Thanks for the tip about needing two certificates, that's what did it. I generated a new cert on the hub transport using New-ExchangeCertificate. It asked me if I wanted to replace another certificate and identified the certificate as something that expired yesterday (it also showed the certs fingerprint). This was obviously not my commercial cert so I just answered yes to the prompt. After this I needed to do a "Start-EdgeSynchronization -ForceFullSync" on the hub transport. This sent the certificate to the edge server. And after this everything worked fine.


Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question