• RSS
  • Twitter
  • FaceBook

Exchange Server Forums

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SAN certificate renewal issue

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Microsoft Exchange 2007] >> Outlook Web Access >> SAN certificate renewal issue Page: [1]
Login
Message << Older Topic   Newer Topic >>
SAN certificate renewal issue - 13.Mar.2010 11:49:59 AM   
lynnj57

 

Posts: 24
Joined: 22.Jun.2006
Status: offline
I renewed a GoDaddy SAN cert for my Exchange 2007 server.  Quick history of company – original email domain was domain1.com, but then, after they booted the founder, they changed the default email domain to domain2.com.  I renewed the SAN cert with the same names as the original.  Now, when users are outside the office, it gives a site mismatch error on the cert, but does say the cert is valid at least.  What is weird, is that the site is showing autodiscover.domain2.com, but everything I see in the web services stuff shows that the external fqdn is mail.domain1.com – I can’t figure out where the autodiscover.domain2.com is coming from.   Every article I’ve read talks about setting the –AutoDiscoverInternalUri , but how is that autodiscover.domain2.com coming into it?  Thanks!
Post #: 1
RE: SAN certificate renewal issue - 13.Mar.2010 4:15:07 PM   
jveldh

 

Posts: 2177
Joined: 12.Apr.2008
From: The Netherlands
Status: offline
Hi,

Can you give some more info, is this when using it internally or also externally ?

Perform the following command and post the output here:

get-webservicesvirtualdirectory |fl

_____________________________

Best regards,

Johan Veldhuis

Visit my Exchange blog

(in reply to lynnj57)
Post #: 2
RE: SAN certificate renewal issue - 13.Mar.2010 4:33:53 PM   
lynnj57

 

Posts: 24
Joined: 22.Jun.2006
Status: offline
Ok, a little more background.  It only happens externally, and from what I've read, it's because the primary SMTP domain has changed not too long ago - this is where the autodiscover.domain2.com is coming from, but the cert is still for autodiscover and mail.domain1.com.  What's the best way around this other than new certificate?  Thanks!

(in reply to jveldh)
Post #: 3
RE: SAN certificate renewal issue - 14.Mar.2010 2:33:45 PM   
jveldh

 

Posts: 2177
Joined: 12.Apr.2008
From: The Netherlands
Status: offline
Hi,

What you could do is implement autodiscover redirect, this will require an additional external IP-address but let's you redirect all request to domain2 to domain1. The best option although in this case is renewing the certificate.

For more information about redirecten see this page:

http://www.exchangeninjas.com/CasCertMethod3

_____________________________

Best regards,

Johan Veldhuis

Visit my Exchange blog

(in reply to lynnj57)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Microsoft Exchange 2007] >> Outlook Web Access >> SAN certificate renewal issue Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts


Follow TechGenix on Twitter