Exchange Autodiscover SSL issue

Status
Not open for further replies.
A

archibaldicus

Situation:

- Internal AD domain corp.domain.com with Exchange 2010 installed.

- OWA access: URL webmail.domain.com works fine with a valid SSL certificate for *.domain.com

- When outlook clients connect internally, they are presented with a certificate warning, saying that the host does not match the certificate. This is because the client access server presents itself as server.corp.domain.com, which doesn"t match the *.domain.com certificate.

Question:

How do we solve the ssl error for outlook clients on the LAN, taking into account that:

- We want to use the Autodiscover service;

- We do not want to change the OWA URL;

- We do not want to change the SSL certificate.

Do we setup a separate internal Autodiscover website with another valid certificate for *.corp.domain.com for the internal Outlook clients? If yes, can we create our own internal CA for the certificate?

Regards,

Stijn
 
S

Steve Goodman

Hiya,

Is there any reason why you don't want to change the cert to a subject alternative name certificate? This is the easiest fix to your problems and wildcard certificates aren't recommended.

Are there any issues stopping you creating a DNS entry like " server.domain.com" and then changing the InternalURL for EWS, OAB, which is what's probably tripping up your Outlook clients.

Steve

Steve Goodman
Check out my Blog for more Exchange info or find me on Twitter
 
A

archibaldicus

Hello,

Thanks for your reply. The DNS entry for server.domain.com already exists and works, but when you configure an outlook client, it automatically turns it into server.corp.domain.com and generates the SSL security warning. I must add that we actually have 2 AD's setup. One for domain.com as root domain, and the one we setup exchange in, i.e. corp.domain.com.

Regards,

Stijn
 
S

Steve Goodman

Hiya,

If you use the following commands:

get-oabvirtualdirectory

and

get-webservicesdirectory

Do you see the server.corp.domain.com listed for each?

Steve

Steve Goodman
Check out my Blog for more Exchange info or find me on Twitter
 
A

archibaldicus

Hi,

Both commands give the server.corp.domain.com as output.

On the certificate reply, I assume we should generate a certificate using the EMC and fill out all URLs (server.corp.domain.com for internal, webmail.domain.com, etc) and send that to Verisign or Godaddy or whatever?

Regards,
Stijn
 
S

Steve Goodman

Hiya,

OK, that output is what I expected. Those two URLs are used by Outlook to set Out of Office and download the Offline Address Book amongst other things. If you're getting the cert errors during usage of Outlook (and mail delivery into and out of Outlook works), then these are the likely culprit.

You could change the InternalURL to server.domain.com use the Set-OABVirtualDirectory and Set-WebServicesDirectory commands - however as it's your production environment and I'm not sure about your exact setup, you need to have understand what this is doing and if possible test it out first. If you make the changes server-side, you will need to get an Outlook client to update it's settings; it should do this automatically, but you can force this by choosing the " Repair" option in the Email Accounts settings panel in Outlook.

Regarding a SAN/UCC certificate, you are quite right about generating it using the EMC. You may want to have a think about if any other hostnames may be needed - the generation wizard will give you some pointers. Obvious ones are if you use another address/server name for Outlook Anywhere and of course autodiscover.corp.domain.com, autodiscover.domain.com.

Steve

Steve Goodman
Check out my Blog for more Exchange info or find me on Twitter
 
A

archibaldicus

Hello,

I pointed the OABVirtualDirectory and WebServicesDirectory to server.domain.com. The SSL errors seemed to have dissappeared until all of a sudden, I got it again. They appear a lot less frequently now, so I was wondering if Outlook is using an SSL connection for something else as well?

We will also try to get a proper SAN certificate that will cover all *.corp.domain.com and *.domain.com hostnames.

Regards,

Stijn
 
S

Steve Goodman

Hiya,

That sounds like when auto discovery is periodically running on the Outlook Client

You may want to also update the SCP record (that's the record in Active Directory that tells domain joined clients where to find AutoDiscover) to amtch that sever.domain.com value, or (preferably) if you have it configured in your internal DNS, autodiscover.domain.com - e.g.

Get-ClientAccessServer | Set-ClientAccessServer -AutoDiscoverServiceInternalUri https://server.domain.com/Autodiscover/Autodiscover.xml

or

Get-ClientAccessServer | Set-ClientAccessServer -AutoDiscoverServiceInternalUri https://autodiscover.domain.com/Autodiscover/Autodiscover.xml

Hope this helps and have a good holiday season!

Steve

Steve Goodman
Check out my Blog for more Exchange info or find me on Twitter
 
Status
Not open for further replies.
Thread starter Similar threads Forum Replies Date
EXChange2013 Exchange 2013 AutoDiscover Tweaks? Exchange Server Administration 0
A Exchange 2003 Outlook 2010 64 Bit- AutoDiscover Connection Err - Certificate Exchange Server Administration 9
N Exchange 2007 SP1 + Outlook 2007/2010 - Autodiscover for Outlook Anywhere and Out of Office not working Using Outlook 1
K testing autodiscover and exchange coexistence Exchange Server Administration 2
C Exchange server 2010 error "The Autodiscover service couldn't be located." Exchange Server Administration 1
J Autodiscover accounts on exchange 2003 with Outloook 2010 not working Using Outlook 4
Z Autodiscover Points to defunct Exchange 2010 Server Exchange Server Administration 5
I Exchange 2010 Profile AutoDiscover not working for some users Exchange Server Administration 1
S Exchange 2010 Autodiscover Problems, cannot connect Outlook clients using Autodiscover / Outlook Any Exchange Server Administration 4
G Exchange 2010/Outlook 2007 Can't get autodiscover to work for some users, but others work fine Exchange Server Administration 3
S Autodiscover issue Exchange 2007 Using Outlook 4
K Exchange 2010 Autodiscover Exchange Server Administration 1
P Autodiscover fails (Exchange 2010) Exchange Server Administration 7
P Autodiscover issues on Exchange 2010 Exchange Server Administration 7
S Exchange 2010 Outlook 2010 Autodiscover fails Exchange Server Administration 22
S Exchange 2010 autodiscover Exchange Server Administration 4
L Reinstall IIS / Autodiscover virtual directories on an computer running Exchange 2010 server? Exchange Server Administration 6
N Exchange 2007 - How to configure the autodiscover service? Using Outlook 22
N Backing Up Exchange Calendar Using Outlook 13
A Ol16 desktopT suddenly can't connect with Exchange Using Outlook.com accounts in Outlook 5
T How can Exchange be configured to sync/push one-way so that the server data can't be affected Exchange Server Administration 0
E How to display "Change Folder" in Change Default Email Delivery Location in Exchange Outlook 2016 Using Outlook 1
J Outlook 2016 Moving IMAP emails to Exchange Using Outlook 1
L How to Import Exchange OST file into Outlook? Using Outlook 3
O Outlook 365 Exchange .ost within Personal Vaul Using Outlook 0
D Outlook 2016 Migrate 'On My Computer' (local storage) Calendar from Mac Outlook to Exchange Account Using Outlook 5
A .restrict results changing after moving to Exchange online Outlook VBA and Custom Forms 0
D Can Exchange Admin Center create a pst for users email/contacts/calendar? Exchange Server Administration 0
S Messages moved / deleted by auto-archive are not synchronized to exchange Exchange Server Administration 8
llama_thumper Setting up forwarders on Exchange server Exchange Server Administration 0
D Importing Outlook Categories from another domain (Exchange 2016/Outlook 2016) Using Outlook 4
M WMI query for Get Disk IO performance in exchange Exchange Server Administration 0
B Outlook 2013/Exchange 2013 - Conf Rooms not fully booking "resolved conflict" meetings Using Outlook 3
D Adding Enterprise Exchange Email Account to Outlook Prevents Sending via Outlook.com Account Using Outlook.com accounts in Outlook 10
O Benefits of Exchange over IMAP and why would I choose Exchange? Using Outlook 2
F Delete/create/reset Exchange mailbox on Outlook.com Using Outlook.com accounts in Outlook 3
A Prevent connection to Public Folders on Exchange? Exchange Server Administration 3
S Add Exchange Account as Secondary to Existing PST? Exchange Server Administration 1
S Adding new Exchange (2016) rule very slow down Microsoft Outlook Exchange Server Administration 0
CWM030 A quick question for Diane about Exchange Exchange Server Administration 2
G How to have domain client use owa server instead of exchange server while connect to network Using Outlook 1
J Outlook 2016 message content does not display - outlook.com; exchange Using Outlook.com accounts in Outlook 9
C Filter/Search emails sent to internal Exchange address only Using Outlook 2
B Copy/Move Exchange inbox to Pop inbox Using Outlook 4
Fozzie Bear Correct Method to set up Outlook.com accounts as Exchange Using Outlook.com accounts in Outlook 7
P AutoArchive exchange folder to exchange folder Using Outlook 1
J Syncing notes between Outlook 2016/Exchange and Outlook for Android Using Outlook 2
Brian Murphy Exchange Online Everything a Transport Rule should do and cannot Exchange Server Administration 1
E Customer wants a portion of GAL from exchange to sync down to Android contacts via Activesync Using Outlook 2
R Problem with searching public folders Exchange 2013/16 Exchange Server Administration 2
Similar threads


















































Top