Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Exchange 2010 SSL not being accepted by Outlook on our Server 2003 RD hosts. But does on Server 2008 R2 hosts.

Posted on 2015-01-19
14
102 Views
Last Modified: 2015-02-10
We have an issue on our Server 2003 Remote Desktop hosts. All users are prompted with an error about not being able to load the SSL.

ssl1
Users on our Server 2008 R2 Remote Desktop Hosts do not see this error & the SSL loads correctly.
Both host OS versions are running Office 2010 & they connect to the same Exchange 2010 Server.

Every user on the Server 2003 farm is prompted with this error every time they load Outlook.

We did recently renew our Exchange SSL in December, this seems to be when the issue first occurred.
I am guessing either the certificate file is corrupted or the renewal/new download is no longer compatible with either Server 2003 or IE8.

Any help would be greatly appreciated.
0
Comment
Question by:Howzatt
  • 5
  • 4
  • 2
  • +2
14 Comments
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 222 total points
ID: 40559085
when last did you update the root certificates on the server 2003 machines?
Update your root certificates and ensure that the 2K3 machines have the intermediate certificates from your certificate provider

http://support.microsoft.com/kb/931125
0
 
LVL 17

Assisted Solution

by:Gaurav Singh
Gaurav Singh earned 110 total points
ID: 40559140
please check the connectivity on below URL:

https://testconnectivity.microsoft.com/
0
 

Author Comment

by:Howzatt
ID: 40559176
info on updating the root certificates seems a bit sketchy for Server 2003.
The MS update for it has been pulled and all the documentation about it talk about Windows XP.

I'm pretty sure this is the issue though as our Server 2008 R2 hosts are unaffected. Apparently the root certificates update automatically in 2008 R2.

Just struggling to find the clear instructions for users who did not previously download the Windows update fix for this.
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 
LVL 17

Assisted Solution

by:Gaurav Singh
Gaurav Singh earned 110 total points
ID: 40559177
Hi which CA's Certificate you are using?
0
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 222 total points
ID: 40559181
you can get the intermediate certificates from the Certificate Authority
0
 

Author Comment

by:Howzatt
ID: 40559483
CA I thought was Go Daddy. But it is saying it's Starfield now? Did they change their name?
0
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 222 total points
ID: 40559487
starfield is godaddy
0
 

Author Comment

by:Howzatt
ID: 40559549
I don't understand what it is that I need to get from them?
0
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 222 total points
ID: 40559607
Intermediate Certificates if your certificate was from starfield get the starfield intermediate ones
https://certs.godaddy.com/repository
0
 

Author Comment

by:Howzatt
ID: 40559629
And I install on the Server 2003 Remote Desktop hosts?
If so, tried that and it didn't help.
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 112 total points
ID: 40560202
If you haven't updated the root certificates, then you will probably need to download and install BOTH the root and the intermediate certificates from the GoDaddy/Starfield repository. Ensure that you install them in the Computer context in Certificates Manager and not Personal.

Simon.
0
 

Author Comment

by:Howzatt
ID: 40565897
How do you do it from the computer context?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 112 total points
ID: 40566177
When you run MMC, and choose certificates, you get a prompt. One of those is Computer.

Simon.
0
 
LVL 5

Assisted Solution

by:R. Toby Richards
R. Toby Richards earned 56 total points
ID: 40570801
I had a similar issue trying to set TLS in group policy. My problem was that 2003 can't install a version of IE that understands newer SSL/TLS protocols. I was able to get around the group policy by futzing with administrative templates. Unfortunately, your issue may be more difficult to resolve. Are you sure you are using SSL, not TLS?
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question