Link to home
Start Free TrialLog in
Avatar of Luis Mendoza
Luis Mendoza

asked on

Why can't I receive email after renewing my MS Exchange 2007 server SSL certificate?

We renewed the SSL Certificate on our MS Exchange Server 2007.  Users using MS Exchange with MS Outlook 2007/2010 kept working fine.  Users using MS Outlook 2007/2010 with POP3 stopped receiving email.

We were forced to renew the certificate with new hash strength, from SHA1 to SHA2.

1.  We checked our firewall.  No changes made.

The only change was to replace the SSL certificate on the email server.  We verified that POP was assigned as a service to the certificate thumbprint.

Any thoughts?  SHA2 issue???

Luis Mendoza
(Net Admin)
Avatar of Sudeep Sharma
Sudeep Sharma
Flag of India image

Which client are you using for POP3 download?

Did you tried Microsoft Remote Connectivity Analyzer for POP3 emails, is that reporting it fine?

Remote Connectivity Analyzer
https://testconnectivity.microsoft.com/

Thanks,
Sudeep
Could be an schannel version issue - what OS are you running outlook on?
Avatar of Luis Mendoza
Luis Mendoza

ASKER

Sudeep,
  We are using MS Outlook 2007/2010 to download email.  We use webmail as well which works fine.  We are trying the analyzer now.

Any other ideas are welcome.  thanks,

Luis
Dave,
  We are running MS Windows 7 32/64 bit, Pro and Ultimate.

thanks
Luis
That should be fine then. Win7/8 Schannel supports the newer protocol suites.
I would normally try wireshark next - capture an attempted login and see if there are any issues setting up TLS.
Give a other email client like Thuderbird a try if that connects, so that we know that the issue is related to Outlook and not Exchange.

Thanks,
Sudeep
1.  Will try Wireshark and see what it can tell us

2.  Will look into Thunderbird as well


thanks!
Luis
By the way we are getting a general error on MS Outlook but here it is:

"Task "username" - Receiving' reported error (0x800CCC0F) : 'The connection to the server was interrupted.  If this problem continues, contact your server administrator or Internet service provider (ISP).'
ASKER CERTIFIED SOLUTION
Avatar of Luis Mendoza
Luis Mendoza

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
No objections
This resolved not being able to pass standard POP email, however did not allow us to pass encrypted email.  I am posting a separate question for that issue.