Jump to content

Recommended Posts

Posted

Hi I've seen some threads touching this subject but i need some clarification.

 

I've installed Exchange 2007 and all I want is for my OWA users to get to OWA without having the cerficate error page come up. We're not allowed external access so we're not using Outlook Anywhere. So can i just create a self certificate using selfssl.exe and is there a way to install this via group policy to the clients? I just want the easiest method to get around this!

 

Thanks

Jenny

Posted
You can just use Windows' Certificate Servies to produce your own certificate and then install this via GPO.

With self signed certificates some web browsers throw a wobbly though don't they and you have to add exceptions? I know Firefox 3 does.

Posted
With self signed certificates some web browsers throw a wobbly though don't they and you have to add exceptions? I know Firefox 3 does.

 

Just make sure that they use IE for webmail, this picks the certs up automatically from the user and machine certificate store. Besides OWA has limited functionality on other browsers in comparison to IE, well the 2003 edition anyway.

 

You can use a GPO to add trusted certificate providers domain wide so this should allow for what the OP is after.

Posted

Thanks for replying everyone.. I ended up setting up the certificate server and issuing a certificate which has worked! yay.

 

There's only one last thing, I've deployed the certificate via group policy which has placed the certificate in the clients Trusted root certificates in IE. However, it still doesn't work without installing it. Firefox picks it up and prompts you straight away, you click yes and it works.. IE7 doesn't do this and you have to locate the error on the toolbar, and browse and install. Anyone know how to automate this?

 

Thanks

Jenny

  • 1 year later...
Posted

Hi all,

 

Having a SSL certificate nightmare again! All was good for a year when I implemented the initial certificate. This subsequently ran out so I renewed it, no problem. Now I've realised that the Out of Office isn't working in Outlook 2007. It's fine on OWA and Outlook 2003. So I've been searching the Internet for solutions to this problem which appears to be quite a common one... from what I've read this will be down to either wrong Autodiscover settings or wrong certificate. So I've tried amending the autodiscover settings but to no avail so I'm now trying to redo the certificate. I've removed the certificate and requested a new one using just the mailserver name as the common name because it's only for internal usage, sent it to the CA and OWA is ok with this, goes straight in with no certificate errors. However Outlook 2007 is not! When opening Outlook 2007, a security alert pops up and says "the name of the security certificate is invalid or does not match the name of the site. Do you want to proceed? Yes / No / View Certificate. Also Out of Office still doesn't work it says the server is unavailable. Have even tried just turning SSL off, but Out of Office still doesn't work! I've tried pretty much everything I can find. Really not sure what else to do to get it working. Has anyone solved this problem???

 

Cheers

J

Posted
With self signed certificates some web browsers throw a wobbly though don't they and you have to add exceptions? I know Firefox 3 does.

As others have pointed out that self-signed Certs throw an error because the Root cert of the CA that issued the cert is not in the clien't trusted root certficate authorities store. One way to do this would be for all domain managed station to roll out the CA's root cert using GPO as mentioned.

 

For exchange 2007 your cert really needs to be a SAN (Subject alternative Name) cert which allows you to add multiple names rather than usual one common name. This will cater for outlook anywhere, OWA etc.

 

The IPSCA unfortunately don't do SAN certs but they do do wildcard certs. Some wildcard certs are not supported on mobile devices so to sue active sync to sync your calendars etc would be a problem.

 

 

Best bet is to use on the commercial CAs becasue they have their CA's Root certs in most browsers on all most all PCs.

 

Ash.

Posted (edited)
What would happen after 2 years? does the renew for education is also free? i.e. beyond 2 years?

 

Ash.

 

Late last year I 'renewed' a couple of certs from IPSCA, no problem at all - their 'renewal' process is simply applying for a cert the same as you did first time around! So, yes, renewals are free too :-)

Edited by tonyd
Posted
Late last year I 'renewed' a couple of certs from IPSCA, no problem at all - their 'renewal' process is simply applying for a cert the same as you did first time around! So, yes, renewals are free too :-)

 

Brill!!

 

Ash.

Posted
If I install a wildcard certs from IPSCA on a Exchange 2003 box then later in the year move to Exchange 2007 on a different box can I use the same cert?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...