Jump to content

Recommended Posts

Posted

I'm in the process of decommisioning our last 2003 server which used to run ISA, and for the past 2 years has done nothing but OWA publishing, and email has just been setup to pass through it.....

 

So I've configured the firewall and exchange to ignore the isa entirely now, i've got everything working bar one last error pop up. I can send email in and out with a phone, with outlook externally and with outlook internally....but internal outlook clients keep getting a certificate error that i can't work out.

 

Security alert pops up telling me "The name on the security certificate is invalid or does not match the name of the site" if i view the certificate it's trying to use the correct certificate *.domain.net but the security alert is looking for the local name of the server. I've set all the virtual directories to look at webmail.domain.net, i've run a powershell comment to point autodiscover to webmail.domain.net....there must be one setting left somewhere that's still pointing at the local name of the server but i can't find it. Any ideas what it might be? It's not effecting functionality at all as i can send and receive email via ll avenues fine.

Posted (edited)

Just run that tool but i've already changed the settings on everything it wants to change to what it suggests changing them to via powershell.

 

I've got the dns zone of domain.net defined on my internal DNS too which webmail. autodiscover. both defined in there too.

 

EDIT: Ah, it may be a client setting.

 

I've just created a new outlook profile and let it recreate my account...pop up isn't appearing anymore. So some setting may be cached and not changing somewhere for users with a current profile....

Edited by mrbios
Posted
Do you have a local proxy server? I've seen this some times where a local proxy is doing SSL inspection

 

No, thankfully those days are long behind me :D

 

The issue appears to have cleared itself on the member of admin staff who was having the same popup, and it fixed it for me by just recreating my outlook profile. So i can only assume something was cached and took a bit of time to clear.

 

Everything seems to be functioning as i'd expect now and the microsoft connectivity tester tells me everything is fine for external clients (phone seems to work fine too though 3G) so i think that's problem resolved :)

 

It's nice to finally say goodbye to the last of server 2003, it's been the last server for a long time now, just took me ages to get around to doing this.

Posted

We have something similar occurring. We updated our autodiscover records in exchange to be FQDNs instead of using the .local names. (i.e. changed autodiscover setting from exchange.domain.local to exchange.domain.com. Local outlook 2013 clients are now giving the "The name on the security certificate is invalid" error because outlook still seems to be attempting to connect to "exchange.domain.local" which is no longer a name in the cert.

 

When I create a fresh outlook profile on a new PC it works fine, but the old server name seems to be cached in Outlook. Is there a way to change it manually or will it happen on its own? How long does that usually take?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...