Cannot start front end service, service stucke on "startarting"

Hi,
I have installed lync server 2013 standard edition, the server is installed on a VM (if it makes any difference) with my Exchange 2013 server as well. I have went step by step over all the deployment steps and it seems that the server is installed properly
but when I go into services I see that "front end server" service is stuck on "starting".
I have tried the solution with the certificates but nothing helped. also I tried the solution with registry alteration. create the registry value as mentioned below
HKLM\System\CurrentControSet\Control\SecurityProviders\Schannel\
create a Key called "ClientAuthTrustMode" and the DWORD Value=2
can you advise.
 

Although TechNet doesn't say Exchange, it does mention Exchange UM not being collocated: http://technet.microsoft.com/en-us/library/gg398131.aspx
Installing Lync Server on a Domain Controller is also not a supported scenario.
Please mark posts as answers/helpful if it answers your question.
Blog
Lync Validator (BETA) - Used to assist in the validation and documentation of Lync Server 2013.

Similar Messages

  • I connected my iphone 3g to itunes which was in 4.1 firmware and itunes ask for an update which i downloaded an updated the phone to version 6.1.3 but my phone cannot start it shows no service my sim card is not getting network and i cannot use the phone.

    i connected my iphone 3g to itunes which was in 4.1 firmware and itunes ask for an update which i downloaded an updated the phone to version 6.1.3 but my phone cannot start it shows no service my sim card is not getting network and i cannot use the phone. what should i do.?

    First, you do not have a 3G if you could upgrade it to 6.1.3, because 4.2.1 is the last version that will work on the 3G. So you either have a 3GS or you somehow hacked the phone to install an incompatible version. You can check the model you have by entering your serial number here: https://selfsolve.apple.com/agreementWarrantyDynamic.do
    Assuming you have a 3GS the most likely reason for your problem is you have a gray market phone that was hacked or jailbroken to unlock it. When you upgraded it you removed the hack, so the phone is now locked to its original carrier.

  • Design Question: Can I use Rest-CsPoolRegisterState command in order start Front End Service when Quorum is lost and less than 85% of FES are available?

    Hi, 
    Assuming below setup for Enterprise edition Lync 2013
    Single Pool Stretched architecture with 4 FES servers
    Site A Data Center
    Site B Data Center
    FES
    2
    2
    SQL
    1 Primary
    1 Mirror
    Fact: In a situation when we lose network connectivity to Site A DC, and due to less than 50% FES servers, Quorum will be lost and as a result Front End Service will stop after 5 minutes. 
    The question is, would I be able to do a manual intervention by using this command
    Reset-CsPoolRegistrarState –PoolFqdn <pool name fqdn> –ResetType QuorumLossRecovery , and start FES with just 2 FES servers in Site B DC and 1 SQL
    Server?
    The reason I am asking this question is because it is mentioned in one of the Lync manuals that at least 85% of the servers must be available to recover once the Quorum has lost. The same manual also mentions to use above
    mentioned command in order to recover from Quorum Loss despite the fact that the lost FES servers are still not available.
    Thanks in Advance

    Hi,
    In Lync server 2013 Stretched pools are not supported for the Front End, Edge, Mediation, and Director server roles. It need two Lync pools.
    If one pool fail to connect, An administrator can declare an emergency and fail over the pool to the backup pool.  That is done by using the:
    Invoke-CsPoolFailover –PoolFQDN <Pool fqdn> –DisasterMode –Verbose
    More details:
    http://blog.avtex.com/2012/07/26/understanding-lync-2013-server-failover/
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information
    found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Problems with one of the front-end servers (service wont start)

    Hi,
    Having a pool with two front-end servers (Lync Server 2013 on Windows Server 2012) and I cannot get one of servers to work properly. 
    The Front-End service is not starting.
    Have removed both servers from the topology and installed one at the time. When adding the second server to the pool the service never starts, its in starting state and a bunch of error messages appears:
    - Server startup is being delayed because fabric pool manager is initializing.
    Cause: This is normal when Pool is bootstrapped and indicates that the Front-End is waiting for a quorum of other Front-Ends to be started.
    - Pool Manager failed to connect to Fabric Pool Manager.
    Cause: This could happen because insufficient number of Front-Ends are currently active in the Pool.
    I have tried restarted one at the time, both at the same time...
    Reset-CsPoolRegistrarState -ResetType QuorumLossRecovery
    Reset-CsPoolRegistrarState -ResetType FullReset
    I have also had a look at the kb saying that there could be a certificate issue. So I have ran that script but no certificate is misplaced in any store.
    I have removed the front-end certificates and requested new ones from the internal CA, I have also done the same to the OAuth certificates.
    How to proceed?

    Hi there,
    if you are still receiving, the same error, please try to shutdown the first Front-End Server, and give time for the services to start, however I would like also to add that with Lync server 2013 the Enterprise pool requirements is to have 3 Front-End Servers
    in a pool instead of 2, because  of introducing the brick model  architecture.
    Regards,
    Charbel Hanna
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread

  • New front end issue - services not starting

    Have build an additional lync 2013 standard edition server, the setup went through fine without error but the following services will not start and cannot figure out why.
    Lync Server Audio Test Service
    Lync Server Front-End
    Event logs only give the following
    This process was not able to update its health status
    The IM Conferencing Server failed to send health notifications to the MCU factory at https://Server/????.ac.uk:444/liveserver/mcufactory/.
    A component could not be started.  The service has to stop.
    Component: Live Communications Applications Module  Error code: C3F2765F!_HRX! (APIEM_E_ESBASE_MISSING!_HRM!)
    urn:application:testbot
       Exception: Microsoft.Rtc.ApplicationServerCore.ApplicationServerMethodTimeoutException > ErrorCode: 2 > Message: The method call CallStartAsync failed due to The method timed out. > TargetSite: Void CallMethod() > StackTrace: at Microsoft.Rtc.ApplicationServerCore.ApplicationMethodCaller.CallMethod()
    at Microsoft.Rtc.ApplicationServerCore.ApplicationHost.CallApplicationStart() > Source: Microsoft.Rtc.ApplicationServerCore > HResult: -2146233088  
    Cant find anything else in the event logs

    I have made sure they are all on the same CU update but the new front ends will still not start, following errorsWhere would i see if its a certificate related error as they look ok from the lync deployment wizard?
    Event log errors
    The UserServices module was not found in the Application List.
    Application Uri: 'http://www.microsoft.com/LCS/UserServices'
    Cause: The server configuration requires the UserServices module to be registered and active. However the configuration information is not found.
    Resolution:
    UserServices configuration is installed at setup time. Check the application list and ensure that it is present. If it is not present, reinstall the server. If this problem occurred after you installed a new application, contact the application vendor to rectify
    the problem.
    Failed to initialize the API subsystem.
    Cause: Review earlier events to determine the specific reason APIEM failed to initialize.
    A component could not be started.  The service has to stop.
    Component: Live Communications Applications Module  Error code: C3F2765F!_HRX! (APIEM_E_ESBASE_MISSING!_HRM!)
    The Lync Server Front-End service terminated with the following service-specific error:
    %%3287447135

  • Web Start beginner - Web Start front end to existing web app?

    Hi all,
    I'm new to Web Start, though have been hearing about it for some time. Even after reading the documentation, I have some basic questions about it.
    Specifically, is it possible to invoke business methods via something like a Struts ActionServlet through a Web Start gui? That is, say my Web Start app and my existing web-based Struts app were on the same server, could I easily invoke the ActionServlet by passing in a URL with parameters? Thus giving me the ability to completely reuse my 'MC' of my Model-View-Controller app, and just replacing/adding another view ('V')?
    Has anyone ever done this? If so, are there good examples?
    Thanks in advance,
    Mike

    WebStart is a deployment mechanism for otherwise perfectly normal Java applications. WebStarted applications run on the client, not the server. WebStarted apps run in a protected environment (the Java sandbox), meaning they can't do potentially harmful things on the client machine such as reading and writing files or creating network connections to any server other than the one they were loaded from, unless you obtain special permissions from the user (the application needs to be signed for this to happen).
    So there is nothing that specifically prevents you from using a WebStarted application as a front-end for a Struts webapp. If it makes sense to use a client-side application for that purpose is a question only you can answer.

  • Cannot start Oracle BI Scheduler service ---pls help.

    Hi all,
    I'm new in OBIEE.
    I already installed and created some reports and dashboards in OBIEE. I found the problems that they are not updated data when new data loaded into DB.
    I tried to start the Oracle BI Scheduler service but it has had the error like the message below;
    "The description for Event ID ( 21 ) in Source ( Oracle BI Scheduler ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details.
    The following information is part of the event: [68008] Scheduler Error: [nQSError: 67042] The Scheduler Configuration is incorrect.
    [nQSError: 67004] Registry value for SchedulerScriptPath not set.."
    Could anyone suggest me how would I be able to solve this error ?
    Thank you in advance.
    NNN

    hi
    First I do thank you for your answer quickly.
    For now, I have tried to follow your suggestion but I found a new error when I start bi scheduler service.
    ==========================================================================================
    The description for Event ID ( 21 ) in Source ( Oracle BI Scheduler ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: [68008] Scheduler Error:
    Current Table: S_NQ_JOB.
    [nQSError: 17001] Oracle Error code: 942, message: ORA-00942: table or view does not exist
    at OCI call OCIStmtExecute.
    [nQSError: 17010] SQL statement preparation failed.
    Current Table: S_NQ_JOB_PARAM.
    [nQSError: 17001] Oracle Error code: 942, message: ORA-00942: table or view does not exist
    at OCI call OCIStmtExecute.
    [nQSError: 17010] SQL statement preparation failed.
    Current Table: S_NQ_INSTANCE.
    [nQSError: 17001] Oracle Error code: 942, message: ORA-00942: table or view does not exist
    at OCI call OCIStmtExecute.
    [nQSError: 17010] SQL statement preparation failed.
    Current Table: S_NQ_ERR_MSG.
    [nQSError: 17001] Oracle Error code: 942, message: ORA-00942: table or view does not exist
    at OCI call OCIStmtExecute.
    [nQSError: 17010] SQL statement preparation failed..
    ===================================================================
    Any concern that I should know and how can I hanle this error ?
    Thank you

  • Cannot start the "Internet Directory" service for the infrastructure tier

    Hi, my "Internet Directory" service for the infrastructure tier cannot be started. I'm using 9iAS for Form service. Could anybody help me??
    Thanks much in advance!
    FreeBirdRita

    Hi Brain,
    what's version of SQL Server that you have installed and what's your operationg system version info?
    If you are running SQL Server 2008, which is not supported on the Windows Server 2008/2008 R2 domain controll (DC), even on Windows Server 2003 DC, there are limitations. Microsoft does not recommend to install SQL Server instances and DC on the same server,
    for more information, see Install SQL Server on a Domain Controller (http://msdn.microsoft.com/en-us/library/ms143506.aspx#DC_Support).
    There are some threads in the forum talked about installing SQL Server and DC on the same server, here are some for your references:
    http://social.technet.microsoft.com/Forums/en-US/sqlsetupandupgrade/thread/1a2963ff-90d7-4bba-97ce-fa15f70fb6a8/
    http://social.technet.microsoft.com/Forums/en-US/sqlsetupandupgrade/thread/981ef726-d04a-4063-8008-cc7bbad854ab/
    Hope this helps. Please feel free to let me know if you have more questions.
    Best Regards,
    Chunsong Feng [MSFT]
    Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Cannot start Oracle BI Server Service

    I had installed Oracle Bussiness Intelligence 10g Release 2 version on my system....I was able to generate reports properly with the Default Repository(SH)....But When I created an OLAP repository and loaded it....It worked fine for a few minutes....then BI server service was automatically stopped....later when the service was restarted,it worked for 5 min but agin it got automatically stopped....but on attempting to restart the service again I got a error message ERROR 1068: Service cannot be be started because groups or dependencies not loaded....How can I reinstate the server process? I tried changing the repository to the default one but it didn't work....
    Edited by: user10422576 on Oct 19, 2008 11:42 PM

    I have seen similar errors when the repository is corrupt. Are you able to open the repository in offline mode ? In online mode, when you check consistencies, does it pass or does it throw any errors ? Also check the log files. if you are not getting enough information, try changing the loglevel for that user and then try it. usually this gives a good amount of info to debug.
    Good Luck.
    Dinesh Veera

  • Cannot start mpd as systemd service

    Hi all,
    I have installed mpd. If I run
    mpd
    from a terminal, then everything is normal; I can open
    a client and use mpd. However, if I try to start it as a systemd service I get errors. That is, once I do
    sudo systemctl enable mpd
    and reboot, then
    jorge@flamingo:~$ systemctl status mpd
    ● mpd.service - Music Player Daemon
    Loaded: loaded (/usr/lib/systemd/system/mpd.service; enabled)
    Active: failed (Result: signal) since Thu 2014-09-25 22:01:48 EDT; 2min 20s ago
    Main PID: 1647 (code=killed, signal=ABRT)
    Sep 25 22:01:48 flamingo mpd[1647]: ALSA lib confmisc.c:1251:(snd_func_refer) error evaluating name
    Sep 25 22:01:48 flamingo mpd[1647]: ALSA lib conf.c:4259:(_snd_config_evaluate) function snd_func_refer returned erro...rectory
    Sep 25 22:01:48 flamingo mpd[1647]: ALSA lib conf.c:4738:(snd_config_expand) Evaluate error: No such file or directory
    Sep 25 22:01:48 flamingo mpd[1647]: ALSA lib pcm.c:2239:(snd_pcm_open_noupdate) Unknown PCM default
    Sep 25 22:01:48 flamingo mpd[1647]: alsa_output: Error opening default ALSA device: No such file or directory
    Sep 25 22:01:48 flamingo mpd[1647]: output: Attempting to detect a oss audio device
    Sep 25 22:01:48 flamingo mpd[1647]: oss_output: Error opening OSS device "/dev/dsp": No such file or directory
    Sep 25 22:01:48 flamingo mpd[1647]: oss_output: Error opening OSS device "/dev/sound/dsp": No such file or directory
    Sep 25 22:01:48 flamingo mpd[1647]: output: Attempting to detect a pulse audio device
    Sep 25 22:01:48 flamingo mpd[1647]: Assertion 'm' failed at pulse/thread-mainloop.c:236, function pa_threaded_mainloo...orting.
    Hint: Some lines were ellipsized, use -l to show in full.
    or,
    jorge@flamingo:~$ sudo systemctl start mpd
    [sudo] password for jorge:
    jorge@flamingo:~$ systemctl status mpd
    ● mpd.service - Music Player Daemon
    Loaded: loaded (/usr/lib/systemd/system/mpd.service; enabled)
    Active: failed (Result: signal) since Thu 2014-09-25 22:09:13 EDT; 8s ago
    Process: 2056 ExecStart=/usr/bin/mpd --no-daemon (code=killed, signal=ABRT)
    Main PID: 2056 (code=killed, signal=ABRT)
    Sep 25 22:09:13 flamingo mpd[2056]: ALSA lib confmisc.c:1251:(snd_func_refer) error evaluating name
    Sep 25 22:09:13 flamingo mpd[2056]: ALSA lib conf.c:4259:(_snd_config_evaluate) function snd_func_refer returned erro...rectory
    Sep 25 22:09:13 flamingo mpd[2056]: ALSA lib conf.c:4738:(snd_config_expand) Evaluate error: No such file or directory
    Sep 25 22:09:13 flamingo mpd[2056]: ALSA lib pcm.c:2239:(snd_pcm_open_noupdate) Unknown PCM default
    Sep 25 22:09:13 flamingo mpd[2056]: alsa_output: Error opening default ALSA device: No such file or directory
    Sep 25 22:09:13 flamingo mpd[2056]: output: Attempting to detect a oss audio device
    Sep 25 22:09:13 flamingo mpd[2056]: oss_output: Error opening OSS device "/dev/dsp": No such file or directory
    Sep 25 22:09:13 flamingo mpd[2056]: oss_output: Error opening OSS device "/dev/sound/dsp": No such file or directory
    Sep 25 22:09:13 flamingo mpd[2056]: output: Attempting to detect a pulse audio device
    Sep 25 22:09:13 flamingo mpd[2056]: Assertion 'm' failed at pulse/thread-mainloop.c:236, function pa_threaded_mainloo...orting.
    Hint: Some lines were ellipsized, use -l to show in full.
    Here is the mpd config file:
    jorge@flamingo:~$ cat ~/.mpd/mpd.conf
    music_directory "/home/jorge/Multimedia/Audio/Music"
    playlist_directory "/home/jorge/.mpd/playlists"
    db_file "~/.mpd/mpd.db"
    log_file "~/.mpd/mpd.log"
    pid_file "~/.mpd/mpd.pid"
    state_file "~/.mpd/mpdstate"
    audio_output {
    type "alsa"
    name "MPD"
    restore_paused "yes"
    follow_inside_symlinks "no"
    Any ideas what I'm doing wrong here?
    Thanks in advance.
    Last edited by geo909 (2014-09-26 02:12:30)

    Scimmia wrote:Yeah, you're out of date. Update your system and everything should work.
    *facepalm*
    Oh dear.. An update fixed the problem indeed, thank you.
    HilmTye wrote: if you're starting mpd as a system service, then your user's config won't be used
    You're right.. I just read the wiki more carefully. Indeed, I would like to run it for my user, so systemd is not
    the best option for me. But I still have trouble.. The problem is that I can't autostart it the way it mentions
    in the wiki. My mpd files are as follows:
    jorge@flamingo:~$ ls ~/.mpd
    mpd.conf mpd.db mpd.log mpd.pid mpdstate playlists
    I tried this as per the wiki:
    jorge@flamingo:~$ cat ~/.profile
    # MPD daemon start (if no other user instance exists)
    [ ! -s ~/.mpd/mpd.pid ] && mpd
    but it didn't work. mpd was not running after reboot.
    Then I tried /etc/profile:
    jorge@flamingo:~$ cat /etc/profile
    # /etc/profile
    #Set our umask
    umask 022
    # Set our default path
    PATH="/usr/local/sbin:/usr/local/bin:/usr/bin"
    export PATH
    # Load profiles from /etc/profile.d
    if test -d /etc/profile.d/; then
    for profile in /etc/profile.d/*.sh; do
    test -r "$profile" && . "$profile"
    done
    unset profile
    fi
    # Source global bash config
    if test "$PS1" && test "$BASH" && test -r /etc/bash.bashrc; then
    . /etc/bash.bashrc
    fi
    # Termcap is outdated, old, and crusty, kill it.
    unset TERMCAP
    # Man is much better than us at figuring this out
    unset MANPATH
    export GPODDER_HOME="/home/jorge/Applications/Application Data/gpodder"
    # MPD daemon start (if no other user instance exists)
    [ ! -s ~/.mpd/mpd.pid ] && mpd
    but it didn't work either.
    In both cases, if I try to run mpd again from the terminal, I get:
    jorge@flamingo:~$ mpd
    server_socket: bind to '0.0.0.0:6600' failed: Address already in use (continuing anyway, because binding to '[::]:6600' succeeded)
    and then mpd works.
    Any ideas on how to startup mpd automatically on boot without systemd?
    Last edited by geo909 (2014-09-26 04:03:15)

  • Cannot start OEM console & agent service

    I have 8i database, client & OEM installled on the same laptob (OS W2k). Machine is not connected to any network.
    I have created the OEM repository.
    I can start OMS service.
    But the agent service fail to start.
    Microsof Mgt console error msg: could not start Oracle Agent service on Local Computer. Error3221356559
    Is it true the machine need a static IP address ?
    Any advice, deeply appreciated.
    Tks

    I had an agent service problem which after a lot of trouble resorted to a reinstall of OEM. It created the last 2 service errors being teh OEM and apache. I used a registry cleaner from
    www.iomation.com. After running this utility I rebooted and the agent service worked again. The apache service was fixed by starting it in the console and reading the error to find that multiple entries were being made to the http.conf when reinstalling. The OEM service still doesn't work. I am assuming it is a problem with a configuration file which I am working on now.
    Hope some of this helps, I know what a pain these problems are. Darrel, I dont know if its me, but that link doesnt work. Its a water/landscaping site.

  • Cannot start the Semantic Logging service for out-of-proc

    I used the following command in the “Package Manager Console” window to download the below mentioned packages
    • install-package EnterpriseLibrary.SemanticLogging
    • install-package EnterpriseLibrary.SemanticLogging.Service
    • install-package EnterpriseLibrary.SemanticLogging.TextFile
    Once the packages were installed, from the "packages\EnterpriseLibrary.SemanticLogging.Service.2.0.1406.1\tools” folder i extracted the install-packages.ps1 file using the following command
    "powershell –file .\install-packages.ps1"
    All the assemblies are now extracted into the directory.
    Now i try to start the service using the "SemanticLogging-svc.exe –s –a=LocalSystem" but the service did not start.
    Please help me out in this issue as i had followed the same procedure on a couple of other machines (one on a 32 bit machine which had Windows 7 Enterprise with SP1 and another a 64 bit machine which has Windows 8.1 Enterprise) and the service started and i
    could log using semantic logging block out-of-proc. I have got the powershell version 4 installed on my machine.
    I did not receive any error message which details me what issue was nor i got any success message which displayed the service has started. I am sure i got these last time when i tried out on the above said two machines. Right now i have a 64 bit machine
    with Windows 7 Enterprise with SP1.
    Appreciate your help

    This forum is for POS for .NET. You might want to try and post to the regular Windows forums:
    http://social.msdn.microsoft.com/Forums/en-US/winforms/threads
    www.annabooks.com / www.seanliming.com / Book Author - Pro Guide to WE8S, Pro Guide to WES 7, Pro Guide to POS for .NET

  • Cannot start the SQL server service after you install Active Directory

    Good Morning,
    Im the system admin for a small company.  We have a dedicated domain controller but it is the only one.  To get a second domain controller up and running on our domain, I installed the AD role on our file and SQL server.  After the reboot
    we couldnt get SQL up and running.  I found this article
    http://support.microsoft.com/kb/929665
    In the article it reads
    To work around this issue, repair Windows Internal Database. To do this, run the following command line at a command prompt:
    Msiexec /i SSEE_10.msi CALLERID=OCSetup.exe REINSTALL=ALL REINSTALLMODE=omus /qn REBOOT=ReallySupress /l*v <var><Log_File_Path></var>
    My question is what is the Log_File_Path?  Is that where I installed the AD log path?
    My DBA is also looking into this as well.
    Thanks in advance,
    Brian
    Brian Fink, MCSE

    Hi Brain,
    what's version of SQL Server that you have installed and what's your operationg system version info?
    If you are running SQL Server 2008, which is not supported on the Windows Server 2008/2008 R2 domain controll (DC), even on Windows Server 2003 DC, there are limitations. Microsoft does not recommend to install SQL Server instances and DC on the same server,
    for more information, see Install SQL Server on a Domain Controller (http://msdn.microsoft.com/en-us/library/ms143506.aspx#DC_Support).
    There are some threads in the forum talked about installing SQL Server and DC on the same server, here are some for your references:
    http://social.technet.microsoft.com/Forums/en-US/sqlsetupandupgrade/thread/1a2963ff-90d7-4bba-97ce-fa15f70fb6a8/
    http://social.technet.microsoft.com/Forums/en-US/sqlsetupandupgrade/thread/981ef726-d04a-4063-8008-cc7bbad854ab/
    Hope this helps. Please feel free to let me know if you have more questions.
    Best Regards,
    Chunsong Feng [MSFT]
    Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • I keep getting a message, "cannot start the Bluetooth Stack Service:, what does this mean

    I have the c510a photosmart estation, windows  7, 64 bit.  How can I get rid of this message? 

    I thought the same too, looks like its not just me having this issue, hope Apple do something soon. Thanks for your help

  • Front End Services won't start with new cert, SChannel error about hostname

    We have an existing Lync 2013 Enterprise system set up, and many of the servers are using certs issues by our local CA. I want to move several of the certs to third-party certificates so that non-domain machines can connect. The first change I'm making is
    on our Edge pool. However, I'm having an issue. Here are the details:
    Our internal domain space is int.domain.com. Our external domain space is domain.com. Our Lync FE server is LS01.int.pool.com and our FE pool is pool01.int.domain.com. I have generated a CSR and requested a certificate from Globalsign with the following
    characteristics:
    SN: pool01.int.domain.com
    SAN: pool01.int.domain.com
    SAN: domain.com (wildcard)
    SAN: int.domain.com (wildcard)
    After applying the new cert using the topology builder, I've rebooted and the Lync Front-End Server service will no longer start. The following SChannel error is in the event logs:
    The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is ls01.int.domain.com. The SSL connection request
    has failed. The attached data contains the server certificate.
    After reverting back to the original local CA cert, the services start. The local cert has a ton of individual SANs set up but I was under the impression that the wildcard SANs were supported and would be ok for the hostnames.
    Why is it looking for my FE server name and not the pool? Is this an issue with my deployment, or is it with the cert? I'm not sure where to go from here.

    Hey Matt,
    As mentioned above wildcards are only supported for Lync web services such as lyncdiscover, dialin and meeting URL's. It is OK to have wildcards in the certificates SAN, but you must also specifically include the following:
    SN: pool01.int.domain.com (SN must be pool)
    SAN: pool01.int.domain.com (pool must also be included in SAN)
    SAN: lync-fe-001.int.domain.com (the machine name of your front end server)
    This should solve the issue for you.
    Andrew Morpeth
    Lync Server Specialist - Auckland, NZ
    Check out my blog

Maybe you are looking for