Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Multi Tenant Microsoft cenrtificate

Posted on 2016-10-19
3
Medium Priority
?
56 Views
Last Modified: 2016-11-07
hi,

Can you please help me resolve this certificateissue.

Simple environment
OS -- server 2008 R2, Exchange 2010 and one server (i.e.) hub and MB are running on same server.
Have 2 domains
1) abc.com
2) xyz.com
We have setup mail, owa and autodiscover records setup internally (internal IP) and externally (external IP) for both domain (both same to point to same IPs)

SAN SSL is added for both domains. SMTP role assigned to both
Users primary email address will be either username@abc.com or username@xyz.com depending on which company/branch there are from.

When we setup new profiles for the users in abc.com, We are getting an error message saying "the name on the security certificate is invalid or doesn't match the name of the site"
If I check certificate, it is showing autodiscover.xyz.com.
0
Comment
Question by:ukitsme
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 83

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1000 total points (awarded by participants)
ID: 41851503
do you have the 2 Cname records
autodiscover.abc.com pointing to mail.xyz.com
autodiscover.xyz.com  pointiong to mail.xyz.com

Certificate mail.xyz.com or *.xyz.com
0
 
LVL 27

Accepted Solution

by:
MAS earned 1000 total points (awarded by participants)
ID: 41851533
Hi,
Your certificate should have these names.
1.mail.abc.com  (common name)
2.autodiscover.abc.com
3.autodiscover.xyz.com
4. mail.xyz.com (This is required only if you common name for each domain).

Please check this article to configure your URLs
https://www.experts-exchange.com/articles/13676/Out-Of-office-not-working.html

If you want to keep only one autodiscover you should redirect autodiscover traffic of xyz.com to autodisocver.abc.com.
http://www.msexchange.org/articles-tutorials/exchange-server-2010/mobility-client-access/using-autodiscover-large-numbers-accepted-domains-part1.html

Hope it helps
1
 
LVL 27

Expert Comment

by:MAS
ID: 41876868
Enough information provided to close the card.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question