Jump to content

Recommended Posts

Posted (edited)

I have a Lync 2010 system with topology as follows:

Microsoft Forefront TMG -> Kemp load balancer -> (2) Lync Front End servers, (2) Lync Edge servers, (2) certificate servers, a monitoring server, and of course a few appliances to handle SIP and what not.

 

I've been working on this problem for a while, trying to learn my way through it, but it has become more urgent so now it's time to ask for help.

 

Users attempting to connect to Lync (using the soft client) from outside of our main employee network encounter SSL certificate errors ever since our old certificate expired. Using a web browser to connect to some of our Lync service host names, it is possible to see the old certificate still in place and expired. I cannot find the offending certificate; I believe I've replaced it everywhere with a new one.

 

The Lync Web Service certificate is definitely where the problem is, although I can't say for sure if the problem is anywhere else also. When I run Get-CsCertificate | fl I see only up-to-date certificates. They are listed for Default, WebServicesInternal, and WebServicesExternal. Looking in the Certification Authority MMC and IIS Manager on all my servers and checking in the load balancer I cannot find the expired certificate.

 

Where else should I look for it?

Edited by ronanian
Posted

Hi,

 

Can you run a Lync/OCS Remote Connectivity Test https://www.testexchangeconnectivity.com/ and just ensure what certificate it is showing here please.

 

- Run Deployment Wizard on Edge Server, Check what Public Certificate is assigned.

- Ensure that the certificate is not installed on the clients computer (doubtful..)

 

The TMG should only be publishing web services and so if the correct certificate is shown on your meet. and dial. services then TMG Listeners are configured correctly.

 

The only way the revoked cert would be provided by the client is if the edge certificates have not been configured correctly. That is the only scenario where I have seen this it's not generally due to it being on the client computer as you should be using a Public CA.

 

If you could send me some further detail, and i'll see what i can do to help.

 

Regards,

James.

  • Thanks 1
Posted

Deployment wizard shows only correct certificates, not the expired one.

 

testexchangeconnectivity's Lync test passes with this one warning:

Analyzing the certificate chains for compatibility problems with versions of Windows.

Potential compatibility problems were identified with some versions of Windows.

Additional Details

ExRCA can only validate the certificate chain using the Root Certificate Update functionality from Windows Update. Your certificate may not be trusted on Windows if the "Update Root Certificates" feature isn't enabled.

 

I'm completely out of my element working with the TMG, so if you could point me at some basic instructions...no wait, I think I got it:

Forefront TMG Management ->

Firewall Policy ->

Lync Web Services properties ->

Listener tab ->

Properties button ->

Certificates tab ->

Select Certificate... button ->

Choose certificate (which of course must first have been imported using Certs mmc) ->

Ok, Ok, until out of all dialog boxen

Click "Apply" at top of Firewall Policy pane

 

Man, that was pretty deep in the bowels of nested dialog boxes. If you had not said "TMG Listeners" I would never have found it.

 

I think that was it. It seems to be working properly now! THANK YOU!!!!! I've been struggling with this for way too long, though at least I learned a lot in the process.

  • 4 weeks later...
Posted
I have a Lync 2010 system with topology as follows:

Microsoft Forefront TMG -> Kemp load balancer -> (2) Lync Front End servers, (2) Lync Edge servers, (2) certificate servers, a monitoring server, and of course a few appliances to handle SIP and what not.

 

I've been working on this problem for a while, trying to learn my way through it, but it has become more urgent so now it's time to ask for help.

 

Users attempting to connect to Lync (using the soft client) from outside of our main employee network encounter SSL certificate errors ever since our old certificate expired. Using a web browser to connect to some of our Microsoft Lync service host names, it is possible to see the old certificate still in place and expired. I cannot find the offending certificate; I believe I've replaced it everywhere with a new one.

 

The Lync Web Service certificate is definitely where the problem is, although I can't say for sure if the problem is anywhere else also. When I run Get-CsCertificate | fl I see only up-to-date certificates. They are listed for Default, WebServicesInternal, and WebServicesExternal. Looking in the Certification Authority MMC and IIS Manager on all my servers and checking in the load balancer I cannot find the expired certificate.

 

Where else should I look for it?

 

hm do you have still those problems? did u fix them?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...