Solved

Exchange 2013 - Accidentally installed Client Access role on new Mailbox server - users get certificate pop-ups

Posted on 2016-11-17
10
50 Views
Last Modified: 2016-11-17
Installing a new mailbox server but accidentally installed Client Access Role too. As soon as the installation neared completion users started getting certificate errors from the new server.

1. Don't understand how this can be. We point all our clients to a load balancer which points to our existing CAS servers so I don't understand how outlook clients can see this new one.

2. Server is offline now because of the problems its caused. How do I remove the CAS role from it? I assume I need to be online to do this properly (so it can access AD)? Will need to do out of hours I guess.
0
Comment
Question by:paulfoel
  • 5
  • 3
  • 2
10 Comments
 
LVL 7

Expert Comment

by:Andy
ID: 41891264
Hi,

I'm assuming this isn't your only mailbox server as it's offline so you would need to remove all roles then reinstall the mailbox role only.
(The uninstall unfortunately doesn't support single role removal.)
Before removing, ensure any mailboxes are moved to another mailbox server meaning you can do this in hours (although always best to work out of hours for nay major exchange work)
Also, ensure the other mailbox server(s) has/have enough storage.
0
 

Author Comment

by:paulfoel
ID: 41891266
Thanks Andy. Assume its advisable for the server to be back on the network for when I do the uninstall so that it clears out of AD properly?

Still don't understand why the clients saw it as a CAS server though when they'd pointed to a loadbalancer?
0
 
LVL 7

Accepted Solution

by:
Andy earned 500 total points
ID: 41891272
Yeah that would be a good idea to clean up AD.

No, unless it adds itself to the autodiscover.
0
 
LVL 16

Expert Comment

by:Ivan
ID: 41891283
Hi,

since you have installed CAS role, then you should reconfigure or disable AutoDiscoverService on it.
From Exchange Shell type:
[PS] C:\>Get-ClientAccessServer <server name that you just installed> | fl to see autodiscoverserviceinternaluri
If it is not pointing to location where all other are pointing, then you can quickly disable it, so that users don't get certificate errors.
To do that:
Set-ClientAccessServer -Identity “<new_server_name>” -AutoDiscoverServiceInternalUri $NULL

If you want to reconfigure it, then use:
[PS] C:\>Get-clientaccessserver <server name that you just installed> | set-clientaccessserver -autodiscoverserviceinternaluri "https://servername.domain.com/autodiscover/autodiscover.xml"

PS: When you install CAS, it will store autodiscoverserviceuri into AD, and that is why all users can see it.

Regards,
Ivan.
0
 

Author Comment

by:paulfoel
ID: 41891323
Thanks all. Looks like even offline it caused problems because I guess it had inserted itself into AD.

So Ive not added it back onto network and uninstalled. This should fix?

Build document will be updated! Need to ensure CAS is not selected - would suggest Microsoft put a warning here that the addition of CAS server will cause a problem maybe.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 7

Expert Comment

by:Andy
ID: 41891328
some people love a multi role server (especially cost wise), personally I agree it's not a great idea, extra planning is needed for that scenario.
That should be fine.
0
 

Author Comment

by:paulfoel
ID: 41891339
Only problem is users are still getting pop-ups relating to certificates on the new server and if I run test email configuration on my outlook its still finding the new server. Or is it just a case of waiting for propagation etc?
0
 
LVL 16

Expert Comment

by:Ivan
ID: 41891361
Hi, as I wrote:

type command bellow on any exchange server, to see autodiscoverserviceinternaluri settings on that new server
Get-ClientAccessServer <server name that you just installed> | fl

Or type directly this command to disable autodiscoverserviceuri on new server:
Set-ClientAccessServer -Identity “<new_server_name>” -AutoDiscoverServiceInternalUri $NULL
After that, you can simple turn that server on, and do what you intended to do.

Regards,
Ivan.
0
 

Author Comment

by:paulfoel
ID: 41891388
Did that Ivan. Also completely uninstalled exchange on that new server so its gone in console and in AD.

Still looks like some users are getting errors. propagation?
0
 

Author Closing Comment

by:paulfoel
ID: 41891580
Excellent advice given. Saved my bacon,.,
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now