Solved

Exchange 2013 Security Certificate

Posted on 2014-10-29
3
132 Views
Last Modified: 2014-11-03
I am testing a new deployment of Exchange 2013.  I have a new domain name purchased, and licensed from godaddy, have already made all of the DNS forwarding changes and MX pointers.  I have email working on the server. Our domain is set as l*********p.net . This is our external, public domain.  Our internal, private domain is just set as *example.com.  This was setup before I ever even came on board years ago.

I have purchased a multi domain security certificate for our public domain, but this is where the issue comes into play.  When I enable that certificate, I can access our Exchange server from the web-portal both internally and externally just fine, everything works as it is supposed to, EXCEPT for Outlook. If I try and add the Exchange account to Outlook (2013) it gives error codes that the Security Certificate does not match, as it is looking at the local name of the Exchange Server itself (dc4.example.com).  The issue here is that I cannot purchase the *example.com domain as it is owned by someone else.  This has not been an issue in the past, since we never needed to have a public facing domain before.  Well, since we don't 'technically' own the rights to the public *example.com domain, I cannot get a third party certified certificate with that domain name in it. I can create a self-certified certificate through Exchange, that includes the domain, but then every web browser throws up security warnings every time you try to connect both internally and externally.

What is the best practice here to make both ends meet?
0
Comment
Question by:Brendon Gaige
  • 2
3 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 500 total points
ID: 40411183
All you need to do here is to set autodiscover internaluri to match your external url.

Here is a really simple step by step on how to get this working (Step 7):
http://www.mustbegeek.com/configure-external-and-internal-url-in-exchange-2013/
0
 

Assisted Solution

by:Brendon Gaige
Brendon Gaige earned 0 total points
ID: 40411277
Thank you, actually the step I was missing was step 6, in changing the Outlook Anywhere address, it was still pointed at the servers local domain name, instead of the public address (which I already have SNAMES for in our DNS).  Now it is working like a champ once I reset the certificates.  Thank you very much for that link!
0
 

Author Closing Comment

by:Brendon Gaige
ID: 40419019
Actual suggestion was not where the issue was occurring, but provided link did involve the correction necessary to fix the issue.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now