Solved

Exchange 2013 - Certificate Errors

Posted on 2016-09-30
9
41 Views
Last Modified: 2016-10-03
I have server 2012 R2 installed with Hyper-V; one VM "2012 R2" with essential experience as the DC; one VM with Exchange 2013.
Mail is working well with OWA and Outlook.  But I have two issues:

On outlook, after connecting, we get a certificate error "The name on the security certificate is invalid or does not match the name of the site" on all clients (except one).
    What do I need to check, verify etc. ?

I cannot get "Anywhere Access" to complete on the DC server.  I am trying to use the SSL certificate issued for the Exchange which it accepts.
    Should the intermediate certificate be installed on this server ?
    Is it correct to use this SSL certificate on the DC server ?
0
Comment
Question by:Eur0star1
  • 4
  • 4
9 Comments
 
LVL 24

Expert Comment

by:-MAS
ID: 41823868
Hi,
Please check my article
https://www.experts-exchange.com/articles/13676/Out-Of-office-not-working.html

Please let me know if it doesnt help.
0
 
LVL 29

Expert Comment

by:ScottCha
ID: 41824133
Use this to look at the specifics on your certificates.

Get-ExchangeCertificate | fl

Did you get your cert from a CA like Godaddy?

Make sure it hasn't expired.
0
 

Author Comment

by:Eur0star1
ID: 41824850
Spent some time this morning cross checking all settings using -MAS-'s article as guidance.

Current situation:  The SSL certificate is from Godaddy and has over 18 months to run.  It is assigned to services IMAP, POP, SMTP and IIS and the hosts   remote.   autodiscover.    mail.   and  servername.   are assigned.

We get certificate errors on all  'Outlook 2013'  clients  but,  the  'Outlook 2016'  client works correctly.

We also get a certificate error on using the ECP interface.

Hope the  'Outlook 2016'  gives you a clue !

Regards
Brian
0
 
LVL 24

Expert Comment

by:-MAS
ID: 41824951
Please post the error.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:Eur0star1
ID: 41825304
It's the Certificate Security Warning

"The name of the security certificate is invalid or does not match the name of the site"

displayed about 2 minutes after opening Outlook
0
 
LVL 24

Expert Comment

by:-MAS
ID: 41825340
Please post the output of these commands
Get-clientAccessServer | fl Name,AutoDiscoverServiceInternalUri

Open in new window

Get-ExchangeCertificate | fl Issuer,CertificateDomains,services

Open in new window

0
 

Author Comment

by:Eur0star1
ID: 41825947
Sorry about delay;  long weekend !

As requested:

Get-clientAccessServer
Name                                                : SIKORSKY
AutoDiscoverServiceInternalUri   : https://mail.reprotec-ltd.co.uk/autodiscover/autodiscover.xml

Get-ExchangeCertificate
Issuer                        : CN=Go Daddy Secure Certificate Authority - G2,
                                     OU=http://certs.godaddy.com/repository/,
                                     O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US
CertificateDomains : {remote.reprotec-ltd.co.uk,  www.remote.reprotec-ltd.co.uk,
                                      mail.reprotec-ltd.co.uk, sikorsky.reprotec-ltd.co.uk,
                                      autodiscover.reprotec-ltd.co.uk}
Services                     : IMAP, POP, IIS, SMTP

Issuer                         : CN=sikorsky.reprotec-ltd.co.uk
CertificateDomains : {sikorsky.reprotec-ltd.co.uk, autodiscover.reprotec-ltd.co.uk,
                                      remote.reprotec-ltd.co.uk,  mail.reprotec-ltd.co.uk}
Services                     : IMAP, POP, SMTP

Issuer                         : CN=sikorsky.reprotec.local
CertificateDomains : {sikorsky.reprotec.local}
Services                     : SMTP

Issuer                        : CN=sikorsky.reprotec.local
CertificateDomains : {sikorsky.reprotec.local}
Services                     : None

Issuer                        : CN=Microsoft Exchange Server Auth Certificate
CertificateDomains : {}
Services                     : SMTP

Issuer                         : CN=Sikorsky
CertificateDomains : {Sikorsky, Sikorsky.REPROTEC.local}
Services                     : IIS, SMTP

Issuer                         : CN=WMSvc-SIKORSKY
CertificateDomains : {WMSvc-SIKORSKY}
Services                     : None

Regards
Brian
0
 
LVL 24

Accepted Solution

by:
-MAS earned 500 total points
ID: 41826190
Your config seems fine.
Please try to create a new outlook profile and let me know.

Thanks
MAS
0
 

Author Closing Comment

by:Eur0star1
ID: 41826321
After checking various settings -MAS- the long standing issue was resolved after rebuilding the profiles.

Thanks

Brian
0

Featured Post

Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now