Link to home
Start Free TrialLog in
Avatar of Ajoy Rajan
Ajoy RajanFlag for Australia

asked on

Exchange Internal Certificate error

Hi Guys,

We are having a small issue, where internally on the network, when we open outlook, it gives a certificate error. We select yes and all works, but it is annoying.

All the internal URL' s are correct and working. Can someone help to resolve the certificate error?

Regards,

Ajoy
Avatar of RantCan
RantCan
Flag of United States of America image

Your SAN certificate does not match where your mail comes from. You are signing, for example:

yourdomain.com (for exchange) with a self-signed certificate (for mailserver01.domain.local).

Install a signing certificate for your mail domain (yourdomain.com) on your exchange server and assign services to it, (SMTP, CAS, etc.)
Avatar of Ajoy Rajan

ASKER

We have our domain.com certificate installed and working fine externally. Internally, also it has been assigned the required services.

Please find the attachment for ref.
Capture.JPG
Set up an internal DNS zone to match the name of your server: Mail.yourdomain.com and set the A record to the internal IP of your mail server. This creates a split brain DNS and should solve the internal resolution issue.
Hi RantCan,

We cannot have the domain.com.au setup internally, as the people who work on the website, get affected. Their access to our website stops internally and they need to work on this. Is it possible to use a different certificate internally and mail.domain.com.au certificate externally?

Regards,

Ajoy
ASKER CERTIFIED SOLUTION
Avatar of RantCan
RantCan
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial