Solved

Exchange 2013 - Certificate Errors

Posted on 2016-09-30
9
51 Views
Last Modified: 2016-10-03
I have server 2012 R2 installed with Hyper-V; one VM "2012 R2" with essential experience as the DC; one VM with Exchange 2013.
Mail is working well with OWA and Outlook.  But I have two issues:

On outlook, after connecting, we get a certificate error "The name on the security certificate is invalid or does not match the name of the site" on all clients (except one).
    What do I need to check, verify etc. ?

I cannot get "Anywhere Access" to complete on the DC server.  I am trying to use the SSL certificate issued for the Exchange which it accepts.
    Should the intermediate certificate be installed on this server ?
    Is it correct to use this SSL certificate on the DC server ?
0
Comment
Question by:Eur0star1
  • 4
  • 4
9 Comments
 
LVL 25

Expert Comment

by:-MAS
ID: 41823868
Hi,
Please check my article
https://www.experts-exchange.com/articles/13676/Out-Of-office-not-working.html

Please let me know if it doesnt help.
0
 
LVL 29

Expert Comment

by:ScottCha
ID: 41824133
Use this to look at the specifics on your certificates.

Get-ExchangeCertificate | fl

Did you get your cert from a CA like Godaddy?

Make sure it hasn't expired.
0
 

Author Comment

by:Eur0star1
ID: 41824850
Spent some time this morning cross checking all settings using -MAS-'s article as guidance.

Current situation:  The SSL certificate is from Godaddy and has over 18 months to run.  It is assigned to services IMAP, POP, SMTP and IIS and the hosts   remote.   autodiscover.    mail.   and  servername.   are assigned.

We get certificate errors on all  'Outlook 2013'  clients  but,  the  'Outlook 2016'  client works correctly.

We also get a certificate error on using the ECP interface.

Hope the  'Outlook 2016'  gives you a clue !

Regards
Brian
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 25

Expert Comment

by:-MAS
ID: 41824951
Please post the error.
0
 

Author Comment

by:Eur0star1
ID: 41825304
It's the Certificate Security Warning

"The name of the security certificate is invalid or does not match the name of the site"

displayed about 2 minutes after opening Outlook
0
 
LVL 25

Expert Comment

by:-MAS
ID: 41825340
Please post the output of these commands
Get-clientAccessServer | fl Name,AutoDiscoverServiceInternalUri

Open in new window

Get-ExchangeCertificate | fl Issuer,CertificateDomains,services

Open in new window

0
 

Author Comment

by:Eur0star1
ID: 41825947
Sorry about delay;  long weekend !

As requested:

Get-clientAccessServer
Name                                                : SIKORSKY
AutoDiscoverServiceInternalUri   : https://mail.reprotec-ltd.co.uk/autodiscover/autodiscover.xml

Get-ExchangeCertificate
Issuer                        : CN=Go Daddy Secure Certificate Authority - G2,
                                     OU=http://certs.godaddy.com/repository/,
                                     O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US
CertificateDomains : {remote.reprotec-ltd.co.uk,  www.remote.reprotec-ltd.co.uk,
                                      mail.reprotec-ltd.co.uk, sikorsky.reprotec-ltd.co.uk,
                                      autodiscover.reprotec-ltd.co.uk}
Services                     : IMAP, POP, IIS, SMTP

Issuer                         : CN=sikorsky.reprotec-ltd.co.uk
CertificateDomains : {sikorsky.reprotec-ltd.co.uk, autodiscover.reprotec-ltd.co.uk,
                                      remote.reprotec-ltd.co.uk,  mail.reprotec-ltd.co.uk}
Services                     : IMAP, POP, SMTP

Issuer                         : CN=sikorsky.reprotec.local
CertificateDomains : {sikorsky.reprotec.local}
Services                     : SMTP

Issuer                        : CN=sikorsky.reprotec.local
CertificateDomains : {sikorsky.reprotec.local}
Services                     : None

Issuer                        : CN=Microsoft Exchange Server Auth Certificate
CertificateDomains : {}
Services                     : SMTP

Issuer                         : CN=Sikorsky
CertificateDomains : {Sikorsky, Sikorsky.REPROTEC.local}
Services                     : IIS, SMTP

Issuer                         : CN=WMSvc-SIKORSKY
CertificateDomains : {WMSvc-SIKORSKY}
Services                     : None

Regards
Brian
0
 
LVL 25

Accepted Solution

by:
-MAS earned 500 total points
ID: 41826190
Your config seems fine.
Please try to create a new outlook profile and let me know.

Thanks
MAS
0
 

Author Closing Comment

by:Eur0star1
ID: 41826321
After checking various settings -MAS- the long standing issue was resolved after rebuilding the profiles.

Thanks

Brian
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
OfficeMate Freezes on login or does not load after login credentials are input.
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question