Jump to content

Exchange 2007 - Need help with certificates for autodiscover


Recommended Posts

Posted (edited)

I have had this issue for a while now with regards to exchange 2007 and outlook 2007/2010 and i need some help.

 

Every time i start outlook i keep getting 2 warnings..

 

Autodiscover.domain.co.uk

 

Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the site's security certificate.

 

"Red Cross" The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.

 

"Green Tick" The security certificate date is valid

 

"Red Cross" The name on the security certificate is invalid or does not match the name of the site.

 

Then i get this one:

 

"nameofServer.shs.com"

 

Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the site's security certificate.

 

"Red Cross" The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.

 

"Green Tick" The security certificate date is valid

 

"Green Tick" The name on the security certificate is invalid or does not match the name of the site.

 

Can anyone help me sort this on going problem out please. It has been driving me nuts for the last god knows how many years.

 

Thanks

Edited by timbo343
Posted
OK i have managed to get a green tick on autodiscover: The security certificate has a valid name but still got a red cross on The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.
Posted
Answer who its issued by, and then that should help, or install the certificate as part of the domain and then it will be automatically trusted on all domained PCs and jobs a good-un :)
Posted (edited)
Where did the certificate come from? How did you make it (or get it)?

 

Answer to those questions will save time talking about the wrong aspects here.

 

The certificate was set up by me on the exchange server using new-exchangecertificate in powershell giving it services such as SMTP, POP, IMAP and IIS.

 

@john: install the certificate part of the domain, just remind me how to do that... im starting to lose my mind and not in a good way.. Does it need to go into my certificate store on the exchange server? AMm blooming useless when it comes to certificates

Edited by timbo343
Posted

Thanks Chris. I shall see how that goes.

 

At the mo, exchange is only accessable internally, so at the mo not using ssl on OWA. With adding this certificate into trusted certificate authority in Group Policy, should i be able to use SSL on owa? If not, how do i go about it?

Posted
Eeer I'll remote to my DC and write down where you stick the certificates as I cannot remember off the top of my head, its done via GPO though so really simple. I have my Smoothwall HTTPS interception one there and its been great :)
  • Thanks 1
Posted
Eeer I'll remote to my DC and write down where you stick the certificates as I cannot remember off the top of my head, its done via GPO though so really simple. I have my Smoothwall HTTPS interception one there and its been great :)

 

Thanks mate :)

Posted

Export the certificate as normal, and then import it to the following location:

 

Default Domain Policy (or a fairly high up one of your choice) > Computer Config > Policies > Windows Settings > Security Settings > Public Key Policies > Trusted Root CAs on that screen, right click the panel and import, follow the wizard (normal standard MS style wizard as you get when import a SSL Certificate on a workstation). That then goes to all the machines that GPO covers and then it will check against that and go oh yeh I like it :)

 

Always worked well for me that way, fingers crossed it does for you as well. Autodiscover is great i've not configured anyones outlook manually since we moved to Exchange.

Posted
Thanks for the location. I have put it in there. Does that mean i can use the OWA as SSL internally or not?

 

Should do if it was certificate errors that were letting you down before.

Posted

::sob:: Beaten to it, just a few minor points worth adding..

 

"Self-signed" certificates are root certificates which is why it goes in the root store... if you let the certificate import dialog (part of CAPI the crypo API) choose where to put it, it never seems to get it right, but that may be smarter in Win7 (I haven't tried).

 

You said you'd flagged the cert for use in IIS, so it definitely should just work for OWA once you've got the cert distributed.

 

Do you use POP3 & IMAP? I always turn those off and just stick to OWA and full Outlook. At the very least try and get rid of POP3 before someone decides to use it then downloads (& deletes from server) their mail.. and by-and-by loses/trashes it.

Posted
::sob:: Beaten to it, just a few minor points worth adding..

 

"Self-signed" certificates are root certificates which is why it goes in the root store... if you let the certificate import dialog (part of CAPI the crypo API) choose where to put it, it never seems to get it right, but that may be smarter in Win7 (I haven't tried).

 

You said you'd flagged the cert for use in IIS, so it definitely should just work for OWA once you've got the cert distributed.

 

Do you use POP3 & IMAP? I always turn those off and just stick to OWA and full Outlook. At the very least try and get rid of POP3 before someone decides to use it then downloads (& deletes from server) their mail.. and by-and-by loses/trashes it.

 

Nah, i dont use POP3 or IMAP. Like you said, sometimes, it can do more damage than what it is worth.

Posted

Just to bring this up again. Thanks for letting me know where to put the certificate, the clients on the local domain seem happy enough.

 

My next problem is a certificate for the outside. I have set up a access rule on our cisco firewall so that outside IP address talks to the inside email server. The only problem is, obviously the certificate isnt there. Can i use a self signed certificate if i authorise it in a CA server or will i need to go to someone like thwates and get a certifcate from them? Once i have got a certificate, where do i store it on the exchange server?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...