Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 392
  • Last Modified:

Outlook 2016 for MAC throws SSL incorrect host name error

Hi experts, I'm using Exchange 2013 for my server. From outside the network, users get a prompt that shows my web server IP address along with the incorrect host name. That address is actually from my website that is hosted by a 3rd party. May I know how can I correct this to show the correct SSL certs? Windows client can get the correct cert but not MAC client.
0
totallypatrick
Asked:
totallypatrick
1 Solution
 
MASTechnical Department HeadCommented:
Hi,
You have to configure the URLs and split dns. Then configure autodiscover URL.
Please check these to configure your Exchange URLs and autodiscover.
http://www.mustbegeek.com/configure-external-and-internal-url-in-exchange-2013/
https://www.experts-exchange.com/articles/13676/Out-Of-office-not-working.html
0
 
Jason CrawfordExchange EngineerCommented:
Check for a wildcard DNS record.  Better yet try an nslookup for random subdomains of your domain.  Something like:

nslookup -q=a test.yourdomain.com

or

nslookup -q=a grizzlyadamshadabeard.yourdomain.com

If they return an IP chances are you have a wildcard DNS record that you should remove.  The issue is Outlook will query autodiscover.yourdomain.com upon startup, and just like the examples above DNS will return whatever the wildcard record is pointing at, most likely your webhost.
0
 
IvanSystem EngineerCommented:
Hi,

did you configure Outlook Anywhere, and what names did you enter in Outlook when configuring it?
Where is autodiscover record pointing?

Regards,
Ivan.
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 
totallypatrickAuthor Commented:
Hi all, I have a wildcard cert with autodiscover.domain.com in it. This issue only happens to Outlook 2016 MAC client. PC version works perfectly fine. Apparently PC and MAC version works differently. Refer to link 2. Exact error I encountered in link 1.

https://support.microsoft.com/en-sg/kb/3066652 
https://technet.microsoft.com/en-us/library/jj984202(v=office.14).aspx

My website domain.com is pointing to another IP address. How do I make "domain.com/autodiscover" point to my Exchange server? Is this the way to do it? I'm not sure.
0
 
totallypatrickAuthor Commented:
Doing a nslookup -q=a test.yourdomain.com returns the IP address of my Exchange server which is correct. However on MAC,  Outlook 2016 shows the IP address of my web server (hosting my company website) which is totally out.
0
 
IvanSystem EngineerCommented:
Hi,

if you have wildcard certificate for your domain, then you can simple install that cert on your domain.com website, and that will fix it.

When it comes to autodiscover, first thing that Outlook is going to connect is going to be domain.com, and not autodiscover.domain.com. That is why you have a problem.

As you said, PC Outlook works differently, so they don't have this problem, after profile has been configured.

Regards,
Ivan.
1
 
totallypatrickAuthor Commented:
Referring to the attached file, I think i'm stuck at point 2A and it throws the SSL host mismatch error. It doesn't seems to go to 2B which is autodiscover.xxx.com
Capture.JPG
0
 
totallypatrickAuthor Commented:
Hi Ivan, I'm not familiar with web hosting and I've got a 3rd party to host it for me. I can use the same exact cert I used in Exchange server? It doesn't matter if the IP for the website and Exchange server is different right?
0
 
IvanSystem EngineerCommented:
Hi,

if you have wildcard cert, which covers all possible names for your domain, then you can use it.
IP address does not matter, yes.

One thing, do you use SSL on that website? If you have it enabled, but you don't actually use it for anything, then you can also simple disable it. That way, when Outlook try to connects to domain.com website, it will see that SSL is disabled, and will automatically redirect to next address is process, which is autodiscover.domain.com.
That way, Outlook is still going to point to your Exchange, and nothing would have to be done.

Regards,
Ivan.
0
 
totallypatrickAuthor Commented:
Thank you Ivan. Let me give it a shot tom. I'll try to input the cert tom but disable SSL.
0
 
IvanSystem EngineerCommented:
If you disable SSL, then you don't need cert. That is if/ if solution. No need to do both things.
0
 
totallypatrickAuthor Commented:
Just discovered something. A SSL cert has indeed been applied by my web hosting company. If I go to https://119.31.237.67 there is indeed a cert applied as you can see and the certificate name matches what my Outlook shows. What should I do?
0
 
IvanSystem EngineerCommented:
Your domain is parked at 3rd party hosting, which is using it's on certificate. I am not sure if you can enter your certificate on it. Do you have some cpanel or some access to it, so that you try import or to try to disable SSl...
0
 
totallypatrickAuthor Commented:
Yup i have access to Cpanel. I can try to disable SSL tom
0
 
totallypatrickAuthor Commented:
Hi Ivan, you're right. I don't have the ability to disable SSL on the 3rd party hosting but nevertheless thanks a lot for your explanation.
0
 
totallypatrickAuthor Commented:
Right answer
0

Featured Post

[Webinar] Cloud and Mobile-First Strategy

Maybe you’ve fully adopted the cloud since the beginning. Or maybe you started with on-prem resources but are pursuing a “cloud and mobile first” strategy. Getting to that end state has its challenges. Discover how to build out a 100% cloud and mobile IT strategy in this webinar.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now