mrbios Posted October 23, 2015 Posted October 23, 2015 I'm in the process of decommisioning our last 2003 server which used to run ISA, and for the past 2 years has done nothing but OWA publishing, and email has just been setup to pass through it..... So I've configured the firewall and exchange to ignore the isa entirely now, i've got everything working bar one last error pop up. I can send email in and out with a phone, with outlook externally and with outlook internally....but internal outlook clients keep getting a certificate error that i can't work out. Security alert pops up telling me "The name on the security certificate is invalid or does not match the name of the site" if i view the certificate it's trying to use the correct certificate *.domain.net but the security alert is looking for the local name of the server. I've set all the virtual directories to look at webmail.domain.net, i've run a powershell comment to point autodiscover to webmail.domain.net....there must be one setting left somewhere that's still pointing at the local name of the server but i can't find it. Any ideas what it might be? It's not effecting functionality at all as i can send and receive email via ll avenues fine.
jamesreedersmith Posted October 23, 2015 Posted October 23, 2015 Its to do with a name mismatch have a look at https://www.digicert.com/internal-domain-name-tool.htm gives you some useful info and a tool to make the change. You may need to create a DNS zone as well but the blog attached to the above helps.
mrbios Posted October 23, 2015 Author Posted October 23, 2015 (edited) Just run that tool but i've already changed the settings on everything it wants to change to what it suggests changing them to via powershell. I've got the dns zone of domain.net defined on my internal DNS too which webmail. autodiscover. both defined in there too. EDIT: Ah, it may be a client setting. I've just created a new outlook profile and let it recreate my account...pop up isn't appearing anymore. So some setting may be cached and not changing somewhere for users with a current profile.... Edited October 23, 2015 by mrbios
Phoenix_IT Posted October 23, 2015 Posted October 23, 2015 Do you have a local proxy server? I've seen this some times where a local proxy is doing SSL inspection
mrbios Posted October 23, 2015 Author Posted October 23, 2015 Do you have a local proxy server? I've seen this some times where a local proxy is doing SSL inspection No, thankfully those days are long behind me The issue appears to have cleared itself on the member of admin staff who was having the same popup, and it fixed it for me by just recreating my outlook profile. So i can only assume something was cached and took a bit of time to clear. Everything seems to be functioning as i'd expect now and the microsoft connectivity tester tells me everything is fine for external clients (phone seems to work fine too though 3G) so i think that's problem resolved It's nice to finally say goodbye to the last of server 2003, it's been the last server for a long time now, just took me ages to get around to doing this.
Squan_JRP Posted October 30, 2015 Posted October 30, 2015 We have something similar occurring. We updated our autodiscover records in exchange to be FQDNs instead of using the .local names. (i.e. changed autodiscover setting from exchange.domain.local to exchange.domain.com. Local outlook 2013 clients are now giving the "The name on the security certificate is invalid" error because outlook still seems to be attempting to connect to "exchange.domain.local" which is no longer a name in the cert. When I create a fresh outlook profile on a new PC it works fine, but the old server name seems to be cached in Outlook. Is there a way to change it manually or will it happen on its own? How long does that usually take?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now