Exchange 2007 Out of Office Certificate Error
Hello,
I have an Exchange 2007 Server and for some odd reason this week, we have been having issues enabling Out of Office in Outlook. It is some sort of issue with the Autodiscover service, but despite reading forum post after forum post, nothing has worked for
me. At first when we would go into Outlook and click on Out of Office, it would freeze and then say the server is unavailable. I realized that it was trying to resolve a URL so I added a manual A record in the DNS server pointing to the local IP of the server
and it fixed the issue, kind of. Now when we click on Out of Office Assistant, we get a security certificate error and it is driving my users crazy. I have updated the SRV record and many things, still unable to get it to work.
Any help would be super!!
Thanks!
Hi,
1.First of all please check the name what you are using for autodiscover service is available on SAN certificate.
2.Please check the name resolution is happening for autodiscover namespace.
I.e if you try to resolve autodisccover.mydomain.com (or) mail.mydomain.com in your problematic PC it should have to resolved in to cas server ip address or in some scenarios it will get resolved in to LB
3.Then please check whether you have properly set the autodiscover internal URL in all the cas servers.
It might be like below
https:\\autodiscover.mydomain.com\autodiscover\autodiscover.xml
(or)
https:\\mail.mydomain.com\autodiscover\autodiscover.xml
4.Then please check for the web services url in all the cas servers and that is the major thing which will make the availability services (i.e OOF,free busy lookup) to work perfectly .
5.In the problematic please uncheck the internet proxy exceptions.
6.You cane use test email configuration to check whether the outlook client is fetching up the proper url for autodisocver and ews .
7.test-outlookwebservices (we can use this command to check the fuctionality of autodiscover for an problematic user account)
8.Please check the root certificates in the problematic client to check whether it is a expired or not .Root certificates is nothing but the one which will come by default with OS .
9.If all the above is set as perfect but still you are facing the issue.Please follow the below one and this may be not required.
Please export the san certificate from exchnage to pfx file which should have to include the certificate key by using MMC.Then import the pfx file in to problematic client .Let us see what happens .
Same on my side i am having few questions about your environment .
1.Are you facing any certificate errors in OWA .Because why i am asking please check the installed SAN certificate in exchange is valid and or it is not expired ?
2.what is the problematic client operating system veriosn?
Please reply me if you have any issues .
Regards
S.Nithyanandham
Similar Messages
-
Outlook 2007 & Exchange 2007 - Out of office assistant not working
Hi,
when using outlook 2007 and the users mailbox is on an Exchange 2007 server the out of office assistant doesn't work. When you start the out of office assistant the following message is displayed:
'Your Out of Office settings cannot be displayed, because the server is currently unavailable. Try again later.'
Using Outlook 2003 and connect to the same mailbox, the assistant works fine, however you don't have the additional features new to the Assistant.
Also, when using outlook 2007 and connect to an Exchange 2003 mailbox the out of office assistant is also functioning fine.
Using Outlook Web Access on Exchange 2007 to set the out of office assistant works also fine, so the error message is not correct.
Any idea how to fix this ?
Franc.Whilst I agree that auto-discover and other comment's could be upheld, I know that even when EWS and auto-discover are setup correctly that this problem will still occur.
I manage an Exchange 2007 environment with 300 users and and Exchange 2010 environment with 700 user's all using Outlook 2007. We are in the progress of deploying Outlook 2010 but I know with the new authentication process of the Outlook
client with Exchange 2007 or older and Outlook 2007 or older, this problem will still occur.
I know that their are just a few out of a 1,000 user base that experience this problem, so I don't see how global settings and configurations and settings are the culprit.
Just like the problem caused by a badly designed update in November or December of last year that meant auto-discover does not auto-configure a new Outlook profile because it would not detect the user's e-mail address but somehow create some random e-mail
address with the AD account name before the @ and the FQDN for the domain name, which involved a further release of another update several month's later to fix that.
Plus the other problem with the daily and frequent prompt's throughout the day for OWA domain login credential's despite being authenticated and Outlook contacting Exchange fine signified by the bottom-right hand corner status stating so. I press escape
and Outlook carries performing as normal for it do the same a few hours later, however I find that after about half a dozen prompt's over several days, it will disconnect the Outlook client saying 'Need Password' in the bottom-right, which despite left and
right-mouse clicking does not load a login prompt to re-enter credentials that I should not need to be doing in the first place considering that I am logged in with the correct domain account on my computer and using the destined mailbox for that AD account.
Exiting Outlook gracefully and re-launching Outlook a few seconds later allowing time for the background application handles and sub-handles amongst probably other things from the previous Outlook session to close (although, I do find every so often this
process is hampered every so often by having to end the Outlook.exe process directly through Task Manager before being able to re-attempt launching the Outlook client) and Outlook will just reconnect without the need or receiving a prompt to enter the login
details but I will no doubt receive another login prompt that I can likely just press cancel to or the escape button or perhaps, have to follow the above process again.
Just like releasing SP1 for Exchange 2010 to add more problems that worked without it but fixing those problems that existing in 2010.
I find that deleting a database result's in a failure error that in fact does successfully remove the database but since SP1, I know have to run a shell command to remove the database in the registry to delete an entry from a 'state' and 'lockstate' folder
before I am rid of the Exchange configuration, to then have to suspend all database copies on that server and re-start all of the Exchange services before I can actually delete the edb file. Just absurd.
It's all just a backwards and forwards exercise with Microsoft but would love permanent solutions to all of the above. Please advise on the above because it is a major irritation. -
Outlook 2013 with Exchange 2007 - out of office problem
We are using outlook 2013 with Exchange 2007. When users select their out of office it will work fine for the first day, however there after the Out of Office replies stop working. Out of Office is set correctly within Outlook, but what we have found
is that if the user opens Outlook the Out of Office starts to work again. Also when the user opens Outlook it takes around two minutes before it registers that Out of Office is on.
Any Ideas?Hi,
How do you configure your OOF? From standard OOF wizard or define an automatic reply template from Rule wizard?
If you are using a template, Outlook must be running for the Rules Wizard to automatically reply. Please refer to the Note in the following KB:
http://support.microsoft.com/kb/311107
If it is configured by using standard Out of Office assistance in File > Automatic Replies, please remove OOF settings in Outlook and set it from OWA 2007, then check whether the issue can be reproduced.
Regards,
Winnie Liang
TechNet Community Support -
Exchange 2010 Out of Office Assistant not working?
New server with a new Exchange 2010 install into an existing domain...
When users on both the internal network and external network try to access the Out of Office Assistant they get an error message of: " Your Out of Office settings cannot be displayed, because the server is currently unavailable".
I have done tons of research on WebServicesVirtualDirectory and AutodiscoverVirtualDirectory and set both internal and external URL's that work if you go to them in IE )internally and externally offsite).
Here are the settings of Autodiscover and Webservices:
[PS] C:\Windows\system32>Get-WebServicesVirtualDirectory | Format-List
RunspaceId : 86aaf7fc-ca19-45b2-87d1-45ec432a670d
CertificateAuthentication :
InternalNLBBypassUrl : https://MAILSERVER.domain_name.local/ews/exchange.asmx
GzipLevel : High
Name : EWS (Default Web Site)
InternalAuthenticationMethods : {Basic, Ntlm, WindowsIntegrated, WSSecurity}
ExternalAuthenticationMethods : {Basic, Ntlm, WindowsIntegrated, WSSecurity}
LiveIdSpNegoAuthentication : False
WSSecurityAuthentication : True
LiveIdBasicAuthentication : False
BasicAuthentication : True
DigestAuthentication : False
WindowsAuthentication : True
MetabasePath : IIS://MAILSERVER.domain_name.local/W3SVC/1/ROOT/EWS
Path : C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\exchweb\EWS
Server : MAILSERVER
InternalUrl : https://MAILSERVER.domain_name.local/EWS/Exchange.asmx
ExternalUrl : https://mail.domain_name.com/owa
AdminDisplayName :
ExchangeVersion : 0.10 (14.0.100.0)
DistinguishedName : CN=EWS (Default Web Site),CN=HTTP,CN=Protocols,CN=MAILSERVER,CN=Servers,CN=Exchange Adm
inistrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=First Organization,CN=M
icrosoft Exchange,CN=Services,CN=Configuration,DC=domain_name,DC=local
Identity : MAILSERVER\EWS (Default Web Site)
Guid : 4639e4b9-9cf3-4f92-8940-f7c31e07cd47
ObjectCategory : domain_name.local/Configuration/Schema/ms-Exch-Web-Services-Virtual-Directory
ObjectClass : {top, msExchVirtualDirectory, msExchWebServicesVirtualDirectory}
WhenChanged : 4/1/2010 2:47:37 PM
WhenCreated : 3/11/2010 11:02:22 AM
WhenChangedUTC : 4/1/2010 8:47:37 PM
WhenCreatedUTC : 3/11/2010 6:02:22 PM
OrganizationId :
OriginatingServer : DOMAINCONTROLLER.domain_name.local
IsValid : True
[PS] C:\Windows\system32>AutodiscoverVirtualDirectory | Format-List
RunspaceId : 86aaf7fc-ca19-45b2-87d1-45ec432a670d
Name : Autodiscover (Default Web Site)
InternalAuthenticationMethods : {Basic, Ntlm, WindowsIntegrated, WSSecurity}
ExternalAuthenticationMethods : {Basic, Ntlm, WindowsIntegrated, WSSecurity}
LiveIdSpNegoAuthentication : False
WSSecurityAuthentication : True
LiveIdBasicAuthentication : False
BasicAuthentication : True
DigestAuthentication : False
WindowsAuthentication : True
MetabasePath : IIS://MAILSERVER.domain_name.local/W3SVC/1/ROOT/Autodiscover
Path : C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\Autodiscover
Server : MAILSERVER
InternalUrl : https://MAILSERVER.domain_name.local/autodiscover/autodiscover.xml
ExternalUrl : https://mail.domain_name.com/autodiscover/autodiscover.xml
AdminDisplayName :
ExchangeVersion : 0.10 (14.0.100.0)
DistinguishedName : CN=Autodiscover (Default Web Site),CN=HTTP,CN=Protocols,CN=MAILSERVER,CN=Servers,CN=Exc
hange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=First Organiza
tion,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain_name,DC=loca
l
Identity : MAILSERVER\Autodiscover (Default Web Site)
Guid : 7a234ea2-20fc-412b-bbf0-3ea5f965d8da
ObjectCategory : domain_name.local/Configuration/Schema/ms-Exch-Auto-Discover-Virtual-Directory
ObjectClass : {top, msExchVirtualDirectory, msExchAutoDiscoverVirtualDirectory}
WhenChanged : 4/1/2010 3:00:49 PM
WhenCreated : 3/11/2010 11:02:07 AM
WhenChangedUTC : 4/1/2010 9:00:49 PM
WhenCreatedUTC : 3/11/2010 6:02:07 PM
OrganizationId :
OriginatingServer : DOMAINCONTROLLER.domain_name.local
IsValid : True
Test-OutlookWebServices comes up with errors. The Test E-mail AutoConfiguration within Outlook still appears to be looking for Autodiscover at different URLs...
OOF within Outlook Web App functions.
Any suggestions would be helpful!From your previous post, I understand that OOF doesn't work for both internal and external clients. Error message "Your Out of Office settings cannot be displayed, because the server is currently unavailable" was received from Outlook client side. Please correct me if I have any misunderstanding.
Before we go any further, I would appreciate your help in clarifying the following questions:
1. When did this issue begin to occur, since the installation of Exchange 2010?
2. Can we access and configure OOF from OWA?
As internal & external clients are using different methods/URL to access Autodiscover and EWS, which provided OOF service, I recommend we focus on the internal users first.
To troubleshoot this issue, please install the hotfix mentioned in the following KB on the Exchange Client Access Server first:
Outlook 2007 crashes or you cannot access OOF settings after you install a package that contains the .NET Framework 3.5 with SP1 and the .NET Framework 2.0 with SP2 on an Exchange 2007 Client Access server or on an Exchange 2010 Client Access server
http://support.microsoft.com/kb/958934
After that, check if the issue remains. If there is still problem, please help me collect:
1. Test E-mail AutoConfiguration from Outlook client
1. Launch Outlook 2007 using a correct configured profile.
2. Hold down the CTRL key on your keyboard and click the Outlook icon in the notification area of the Windows taskbar, also known as the notification area.
3. In the menu that appears, click Test E-mail AutoConfiguration.
4. Enter your E-mail Address and Password (if not logged into the domain) in the respective edit boxes.
5. Choose the desired auto configuration methods with Use Autodiscover, clear other selection.
6. Click Test.
7. Please send me the screenshot of the result tab and log tab.
2. Result files after running the following command on the Exchange 2007 server
Get-ExchangeCertificate | FL >C:\cert.txt
Get-WebServicesVirtualDirectory –Server ServerName | FL >C:\EWS.txt
Get-AutodiscoverVirtualDirectory –Server ServerName | FL >C:\Audis.txt
Get-ClientAccessServer | FL >C:\cas.txt
Email them to me at [email protected]
With the title as
"Exchange 2010 Out of Office Assistant not working?"
Regards
Fazal M khan -
Outlook 2007 Out of Office does not work
Hello,
Our local network uses Exchange Server 2008 and has clients connected with Outlook 2007 and Outlook 2010. Recently one of the users reported that Outlook 2007 cannot access the Out Of Office function. When he tries Outlook reports that the server is unavailable.
I confirmed this on 2 machines which use Outlook 2007. I also tested on 2 machines using Outlook 2010 and they do not have the problem. Per a ms support kb article, I tried using a new Outlook profile for one of the Outlook 2007 machines and it made no difference.
I am able to use the Out of Office feature when using Outlook Web Access for the machines which use Outlook 2007. Due to this I’m pretty sure the issue is Outlook 2007. The machines are current for Windows and Office updates. Any suggestions on how to resolve
this?
Thank you,I believe you mean Exchange 2007.
OWA is a completely separate mechanism to access the Out Of Office service. Not relevant.
Check your AutoDiscover for your OOF address, with that address attempt to connect to that address via client machine, you should get an XML return. If no return or error message, move forward from there. -
Exchange 2013 - Out of office unavailable when shared mailboxes added in
Good Morning all,
I have a strange issue with our MS Exchange 2013 environment concerning out of office.
When certain users try and access the OOO it gives them the below error message:
"Out
Of Office cannot be display because the server is currently unavailable"
As I mentioned, this is not affecting all users, here comes the strange part(I think so anyway)
The users in question have a shared mailbox added, if I remove the mailbox VIA ECP / Outlook client, out of office begins to work, once I add the mailbox back in, everything works, until the next day or some sort of refresh takes place and then OOO becomes
unavailable again.
Any help would be greatly appreciated.
Thanks,
San.Did you recently installed windows update?
If yes, then check this, see if it applies by uninstalling the update.
http://windowsitpro.com/blog/update-causes-outlook-2013-fail-open-archive-mailboxes
Cheers,
Gulab Prasad
Technology Consultant
Blog:
http://www.exchangeranger.com Twitter:
LinkedIn:
Check out CodeTwo’s tools for Exchange admins
Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose. -
Exchange 2007 Decommissioning, post Office 365 migration
Hello,
We have four Exchange 2007 servers in four different sites, single AD. All four Exchange servers are CAS, Mailbox, Hub, secondary domain controllers. We have migrated to Office 365 successfully, and would like to remove the Exchange 2007 servers.
I have stopped the Exchange services on all four for at least a week and tested Office 365 mail flow with no issues. My questions are:
1) Can I expect to simply uninstall Exchange 2007 from each server, one by one, without a negative impact to Active Directory?
2) Should/can the many Mailbox Databases be deleted prior to uninstalling Exchange 2007? Not all mailboxes had to be migrated to Office 365, and they contain data that we no longer need.
If there is a 'safe' method to remove Exchange in a multi-site setup, I would prefer to try that before having to dig through ADSIedit.
Thank you in advance.Hi Chase,
here's an
official guide for uninstalling Exchange 2007. Please also note the other documents in the same library directory (see navigation pane to the left).
Cheers,
Fred
There's no place like 127.0.0.1 -
Exchange 2007 Autodiscover certificate mismatch
Hello, the company that I work for is trying to switch from Exchange 2007 SP1 to Office 365. However, when we try the cutover migration, 365 doesn't recognize our Exchange server. After a bit of research, I discovered that there is a certificate
mismatch that is causing the problem.
I've been searching for a way to solve this problem for a couple of days now and have not yet found a solution. We'd like to keep the autodiscover location, but change the certificate that is bound to it. We
have a matching certificate installed, but for some reason, Autodiscover keeps pointing toward the wrong certificate (that doesn't even exist).
Any help would be greatly appreciatedWe purchased new certs from GoDaddy and inserted them into exchange (overwriting the old certs and CAs), and this seemed to correct the certificate mismatch. However, when I run the Remote Connectivity Analyzer, I get this:
Connectivity Test Failed
Test Details
<input class=" __ecpStyleButton" id="testSelectWizard___CustomNav3_buttonStartOver" name="testSelectWizard$__CustomNav3$buttonStartOver"
style="padding:8px 8px 8px 29px;text-align:left;border-style:none;cursor:pointer;background-image:url(https;background-background-repeat:no-repeat;" type="submit" value="Start Over" /><input class=" __ecpStyleButton"
id="testSelectWizard___CustomNav3_buttonRunAgain" name="testSelectWizard$__CustomNav3$buttonRunAgain" style="padding:8px 8px 8px 29px;text-align:left;border-style:none none none solid;cursor:pointer;border-left-color:#cccccc;border-left-width:1px;background-image:url(https;background-background-repeat:no-repeat;"
type="submit" value="Run Test Again" />
<input class=" __ecpStyleButton" id="testSelectWizard_ctl12_btnExpandAll" name="testSelectWizard$ctl12$btnExpandAll" style="padding:8px 8px 8px 29px;text-align:left;border-style:none
solid none none;cursor:pointer;border-right-color:#cccccc;border-right-width:1px;background-image:url(https;background-background-repeat:no-repeat;" type="submit" value="Expand All" /><input class="ecpStyleButtonImageOnly
__ecpStyleButton" id="testSelectWizard_ctl12_btnSaveXml" name="testSelectWizard$ctl12$btnSaveXml" style="padding-padding-bottom:6px;padding-text-align:left;border-style:none;cursor:pointer;background-image:url(https;background-background-repeat:no-repeat;"
title="Save as XML" type="submit" value="" /><input class="ecpStyleButtonImageOnly __ecpStyleButton" id="testSelectWizard_ctl12_btnSaveHtml" name="testSelectWizard$ctl12$btnSaveHtml" style="padding-padding-bottom:6px;padding-text-align:left;border-style:none;cursor:pointer;background-image:url(https;background-background-repeat:no-repeat;"
title="Save as HTML" type="submit" value="" />
The Microsoft Connectivity Analyzer is attempting to test Autodiscover for [email protected].
Testing Autodiscover failed.
Additional Details
Elapsed Time: 7624 ms.
Test Steps
Attempting each method of contacting the Autodiscover service.
The Autodiscover service couldn't be contacted successfully by any method.
Additional Details
Elapsed Time: 7624 ms.
Test Steps
Attempting to test potential Autodiscover URL https://paidwarranty.com:443/Autodiscover/Autodiscover.xml
Testing of this potential Autodiscover URL failed.
Additional Details
Elapsed Time: 1237 ms.
Test Steps
Attempting to resolve the host name paidwarranty.com in DNS.
The host name resolved successfully.
Additional Details
IP addresses returned: 12.192.135.43, 50.232.20.50
Elapsed Time: 129 ms.
Testing TCP port 443 on host paidwarranty.com to ensure it's listening and open.
The port was opened successfully.
Additional Details
Elapsed Time: 152 ms.
Testing the SSL certificate to make sure it's valid.
The certificate passed all validation requirements.
Additional Details
Elapsed Time: 342 ms.
Test Steps
The Microsoft Connectivity Analyzer is attempting to obtain the SSL certificate from remote server paidwarranty.com on port 443.
The Microsoft Connectivity Analyzer successfully obtained the remote SSL certificate.
Additional Details
Remote Certificate Subject: CN=www.paidwarranty.com, OU=Domain Control Validated, Issuer: CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US.
Elapsed Time: 247 ms.
Validating the certificate name.
The certificate name was validated successfully.
Additional Details
Host name paidwarranty.com was found in the Certificate Subject Alternative Name entry.
Elapsed Time: 1 ms.
Certificate trust is being validated.
The certificate is trusted and all certificates are present in the chain.
Test Steps
The Microsoft Connectivity Analyzer is attempting to build certificate chains for certificate CN=www.paidwarranty.com, OU=Domain Control Validated.
One or more certificate chains were constructed successfully.
Additional Details
A total of 1 chains were built. The highest quality chain ends in root certificate CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US.
Elapsed Time: 39 ms.
Analyzing the certificate chains for compatibility problems with versions of Windows.
Potential compatibility problems were identified with some versions of Windows.
Additional Details
The Microsoft Connectivity Analyzer can only validate the certificate chain using the Root Certificate Update functionality from Windows Update. Your certificate may not be trusted on Windows if the "Update Root Certificates" feature isn't enabled.
Elapsed Time: 5 ms.
Testing the certificate date to confirm the certificate is valid.
Date validation passed. The certificate hasn't expired.
Additional Details
The certificate is valid. NotBefore = 2/24/2014 3:11:57 PM, NotAfter = 2/24/2016 3:11:57 PM
Elapsed Time: 0 ms.
Checking the IIS configuration for client certificate authentication.
Client certificate authentication wasn't detected.
Additional Details
Accept/Require Client Certificates isn't configured.
Elapsed Time: 371 ms.
Attempting to send an Autodiscover POST request to potential Autodiscover URLs.
Autodiscover settings weren't obtained when the Autodiscover POST request was sent.
Additional Details
Elapsed Time: 241 ms.
Test Steps
The Microsoft Connectivity Analyzer is attempting to retrieve an XML Autodiscover response from URL https://paidwarranty.com:443/Autodiscover/Autodiscover.xml for user [email protected].
The Microsoft Connectivity Analyzer failed to obtain an Autodiscover XML response.
Additional Details
A Web exception occurred because an HTTP 404 - NotFound response was received from IIS7.
HTTP Response Headers:
Content-Length: 5401
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 02 Mar 2015 14:58:45 GMT
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Elapsed Time: 241 ms.
Attempting to test potential Autodiscover URL https://autodiscover.paidwarranty.com:443/Autodiscover/Autodiscover.xml
Testing of this potential Autodiscover URL failed.
Additional Details
Elapsed Time: 5175 ms.
Test Steps
Attempting to resolve the host name autodiscover.paidwarranty.com in DNS.
The host name resolved successfully.
Additional Details
IP addresses returned: 157.56.234.137, 157.56.244.217, 157.56.236.89, 157.56.232.9
Elapsed Time: 327 ms.
Testing TCP port 443 on host autodiscover.paidwarranty.com to ensure it's listening and open.
The specified port is either blocked, not listening, or not producing the expected response.
<label for="testSelectWizard_ctl12_ctl06_ctl00_ctl01_ctl01_tmmArrow">Tell
me more about this issue and how to resolve it</label>
Additional Details
A network error occurred while communicating with the remote host.
Elapsed Time: 4847 ms.
Attempting to contact the Autodiscover service using the HTTP redirect method.
The attempt to contact Autodiscover using the HTTP Redirect method failed.
Additional Details
Elapsed Time: 995 ms.
Test Steps
Attempting to resolve the host name autodiscover.paidwarranty.com in DNS.
The host name resolved successfully.
Additional Details
IP addresses returned: 157.56.234.137, 157.56.244.217, 157.56.236.89, 157.56.232.9
Elapsed Time: 16 ms.
Testing TCP port 80 on host autodiscover.paidwarranty.com to ensure it's listening and open.
The port was opened successfully.
Additional Details
Elapsed Time: 111 ms.
The Microsoft Connectivity Analyzer is checking the host autodiscover.paidwarranty.com for an HTTP redirect to the Autodiscover service.
The redirect (HTTP 301/302) response was received successfully.
Additional Details
Redirect URL: https://autodiscover-s.outlook.com/Autodiscover/Autodiscover.xml
HTTP Response Headers:
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Location: https://autodiscover-s.outlook.com/Autodiscover/Autodiscover.xml
Elapsed Time: 137 ms.
Attempting to test potential Autodiscover URL https://autodiscover-s.outlook.com/Autodiscover/Autodiscover.xml
Testing of this potential Autodiscover URL failed.
Additional Details
Elapsed Time: 729 ms.
Test Steps
Attempting to resolve the host name autodiscover-s.outlook.com in DNS.
The host name resolved successfully.
Additional Details
IP addresses returned: 132.245.64.242, 132.245.3.130, 132.245.92.226, 132.245.82.50, 132.245.81.194, 132.245.81.130, 132.245.88.194
Elapsed Time: 17 ms.
Testing TCP port 443 on host autodiscover-s.outlook.com to ensure it's listening and open.
The port was opened successfully.
Additional Details
Elapsed Time: 53 ms.
Testing the SSL certificate to make sure it's valid.
The certificate passed all validation requirements.
Additional Details
Elapsed Time: 221 ms.
Test Steps
The Microsoft Connectivity Analyzer is attempting to obtain the SSL certificate from remote server autodiscover-s.outlook.com on port 443.
The Microsoft Connectivity Analyzer successfully obtained the remote SSL certificate.
Additional Details
Remote Certificate Subject: CN=outlook.com, OU=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=WA, C=US, Issuer: CN=Microsoft IT SSL SHA1, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US.
Elapsed Time: 127 ms.
Validating the certificate name.
The certificate name was validated successfully.
Additional Details
Host name autodiscover-s.outlook.com was found in the Certificate Subject Alternative Name entry.
Elapsed Time: 1 ms.
Certificate trust is being validated.
The certificate is trusted and all certificates are present in the chain.
Test Steps
The Microsoft Connectivity Analyzer is attempting to build certificate chains for certificate CN=outlook.com, OU=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=WA, C=US.
One or more certificate chains were constructed successfully.
Additional Details
A total of 1 chains were built. The highest quality chain ends in root certificate CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE.
Elapsed Time: 38 ms.
Analyzing the certificate chains for compatibility problems with versions of Windows.
Potential compatibility problems were identified with some versions of Windows.
Additional Details
The Microsoft Connectivity Analyzer can only validate the certificate chain using the Root Certificate Update functionality from Windows Update. Your certificate may not be trusted on Windows if the "Update Root Certificates" feature isn't enabled.
Elapsed Time: 5 ms.
Testing the certificate date to confirm the certificate is valid.
Date validation passed. The certificate hasn't expired.
Additional Details
The certificate is valid. NotBefore = 1/21/2015 10:45:26 PM, NotAfter = 1/21/2016 10:45:26 PM
Elapsed Time: 0 ms.
Checking the IIS configuration for client certificate authentication.
Client certificate authentication wasn't detected.
Additional Details
Accept/Require Client Certificates isn't configured.
Elapsed Time: 158 ms.
Attempting to send an Autodiscover POST request to potential Autodiscover URLs.
Autodiscover settings weren't obtained when the Autodiscover POST request was sent.
Additional Details
Elapsed Time: 277 ms.
Test Steps
The Microsoft Connectivity Analyzer is attempting to retrieve an XML Autodiscover response from URL https://autodiscover-s.outlook.com/Autodiscover/Autodiscover.xml for user [email protected].
The Microsoft Connectivity Analyzer failed to obtain an Autodiscover XML response.
Additional Details
An HTTP 401 Unauthorized response was received from the remote Unknown server. This is usually the result of an incorrect username or password. If you are attempting to log onto an Office 365 service, ensure you are using your full User Principal Name
(UPN).
HTTP Response Headers:
request-id: d823479c-c259-4474-8b3f-df60b4898533
X-CasErrorCode: UnauthenticatedRequest
X-FEServer: BY2PR12CA0033
Content-Length: 0
Cache-Control: private
Date: Mon, 02 Mar 2015 14:58:53 GMT
Set-Cookie: ClientId=GILRU7BQ40ROHZE90FEIA; expires=Tue, 01-Mar-2016 14:58:54 GMT; path=/; secure; HttpOnly
Server: Microsoft-IIS/8.0
WWW-Authenticate: Basic Realm=""
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Elapsed Time: 276 ms.
end
I've enabled basic authentication on the RPC virtual directory on the Exchange CAS in IIS and then restarted IIS, as suggested in another forum (https://social.technet.microsoft.com/Forums/exchange/en-US/69d83444-0528-4e39-a5e9-eb9040501be1/remote-connectivity-analyzer-problem?forum=exchangesvr3rdpartyappslegacy)
and am still getting the same results from the Remote Connectivity analyzer.
On a side note, we have reviewed multiple Exchange Deployment Assistance, including the one that you referred to, and are attempting a cutover migration. -
Exchange Server 2007 sp1 to sp2 upgrade error
Hello,
I am trying to upgrade exchange server 2007 to exchange server 2010 but my exchange server 2007 is running sp1 which cannot be directly upgraded to exchange 2010. To do this I need to first upgrade my exchange server 2007 sp1 to sp2, i am stuck because I
keep getting the error below:
Error:
The well-known object entry with GUID 6c01d2a7-f083-4503-8132-789eeb127b84 on the otherWellKnownObjects attribute on the container object CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain,DC=mw refers to a non-USG CN=Exchange Servers,OU=Microsoft
Exchange Security Groups,DC=domain,DC=mw. Please either delete the well-known object entry or promote the target object to a universal security group.
Does anyone know how to resolve this error?? please assistMy recommendation to you is to upgrade it to Exchange 2007 SP3 with latest Rollup Updates.
Note: Before you start installing the SP3 make sure you upgrade the AD Schema for Exchange 2007 SP3.
For the error you are getting
https://social.technet.microsoft.com/Forums/exchange/en-US/a9d56cc7-dbf8-401c-b4ea-1bfd3c1f13fa/problems-installing-exchange-2007-sp1-ghost-guid?forum=exchangesvradminlegacy
Cheers,
Gulab Prasad
Technology Consultant
Blog:
http://www.exchangeranger.com Twitter:
LinkedIn:
Check out CodeTwo’s tools for Exchange admins
Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose. -
AutoDiscover is a new feature in Exchange 2007, to provide access to Microsoft Exchange features (OAB, Availability service, UM) for Outlook 2007
clients or later.
We can determine whether problems related to AutoDiscover via OWA.
For example:
OOF is not working in Outlook Client but it is working in OWA.
When we realized this issue is not related to Outlook Client side and network side after performing some troubleshooting steps, it should be something
abnormal on AutoDiscover.
There is a common tool to check AutoDiscover in Outlook, Test E-mail AutoConfiguration.
Today, we will introduce AutoDisocver and “Test E-mail AutoConfiguration” in details. Hope it is helpful for AutoDiscover troubleshooting and self-learning.
1. Differences between “Test E-mail AutoConfiguration” and other tools
The “Test-OutlookWebServices” cmdlet allows us to test the functionality of the following services:
Autodisocver
Exchange Web Services
Availability Service
Offline Address Book
When we run “Test-OutlookWebServices”, it returns all the web services’ states.
However, some information are useless for some scenarios.
For example:
We just want our Exchange 2010 Server working internally. So it is unnecessary to enable Outlook Anywhere.
However, when we run “Test-OutlookWebServices”, it returns Outlook Anywhere errors because the Outlook Anywhere does not need to been enabled.
In contrast, using “Test E-mail Autodiscover” is more intuitive.
If there is any problems, it will return error code from the test result, like 0x8004010F etc. We can do some research from TechNet articles or MS
KBs.
Although it is difficult to say where the specific problem is just via the error codes, we can combine with IIS logs to perform troubleshooting and
find the root of problem.
2. How to use “Test E-mail AutoConfiguration” Tool
a. Open Outlook, we can find there is an Outlook Icon at the right bottom of System tray. Holding down “Ctrl” button and right click the Outlook Icon, we will see “Test E-mail
AutoConfiguration” option. Please see Figure 01.
Figure 01
b. Click “Test E-mail AutoCofiguration” and input user name, uncheck the “Use Guessmart” and “Secure Guessmart Authentication” checkboxes, then click “Test”. Please see
Figure 02.
Figure 02
c. “Test E-mail AutoConfiguration” result panel and log panel. Please see Figure 03 and Figure 04.
Figure 03
Figure 04
3. How to understand “Test E-mail AutoConfiguration” result
According to the Figure 03, we found there are many URLs in the “Test E-mail AutoConfiguration” result panel. Let us understand the details of these
URLs.
If we these URLs are not the correct ones, we can re-setting or re-creating them via commands.
- Internal OWA URL:
https://vamwan310.vamwan.com/owa/
OWA internal access.
- External OWA URL:
https://mail.vamwan.com/owa/
OWA external access.
- Availability service URL:
https://vamwan310.vamwan.com/EWS/Exchange.asmx
Free/Busy, OOF and meeting suggestions.
- OOF URL:
https://vamwan310.vamwan.com/EWS/Exchange.asmx
Out of Office access.
- OAB URL:
https://vamwan310.vamwan.com/OAB/023ef307-b18a-4911-a52c-de26700f6173/
OAB access.
- Exchange Control Panel URL:
https://vamwan310.vamwan.com/ecp/
ECP access.
4. AutoDiscover Tips
- AutoDiscover Service itself is a web application running on the AutoDiscover virtual directory (not a server service) designed to provide connection information to various
clients.
- The AutoDiscover service is automatically installed and configured when CAS role is added to any Exchange Server.
- AutoDisocver virtual directory is created in IIS within the Default Web Site.
- A Sercive-Connection-Point (SCP) object is created in AD.
- The SCP contains a URL to the AutoDiscover service. This is for intranet clients so they do not have to use DNS to locate the AutoDiscover service.
- In AD this object is located at the following location:
DC=<domain>, CN=Configuration, CN=Services, CN=Microsoft Exchange, CN=First Organization, CN=Administrative Groups, CN=Exchange Administrative
Group, CN=Servers, CN=<CAS Name>, CN=Protocols, CN=AutoDiscover, CN=<CAS Name>
- Setup creates the AutoDiscover URL based on the following structure:
<CASNetbiosName>.domain.com/AutoDiscover/AutoDiscover.xml
If a PKI certificate is not already present, a self-signed certificate is installed on the Default Web Site.
To help allow this certificate pass the Issues to test it is set up with a Subject Alternative Name containing urls.
If a PKI certificate is present, that certificate is utilized and configured for use in IIS.
The Outlook Provider is used to configure separate settings for the Exchange PRC protocol (internal to network), Outlook Anywhere (Exchange HTTP protocol), and WEB:
EXCH, EXPR, WEB
The
EXCH and EXPR setting are vital for the proper configuration of Outlook.
5. AutoDiscover Workflow
General Process flow:
There are various components surrounding the AutoDiscover Service and all are necessary to complete a request. Including IIS, AutoDiscover service
itself, the provider, and AD.
a.
Client constructs service URL and submits Autodiscover Request. First attempt to locate the SCP object in AD. So, DNS is not needed.
b.
IIS Authenticates User.
c.
Is the Autodiscover service in the appropriate forest?
+ If YES.
1)
Parse/Validate Request
2)
Is there a provider that can service the Request?
++ If YES
a)
Config provider processes request and returns config settings.
b)
Return config setting to client
++ If NO
Inform client we cannot process request
+ If NO.
Redirect client to Autodiscover service in the appropriate forest.
Methods to find Autodiscover services: SCP and DNS
Domain-joined
a. Find SCP first.
The SCP contains the URL to the AutoDiscover service.
URL: https://CAS01.contoso.com(CAS’ FQDN)/AutoDiscover/AutoDiscover.xml
If more than one SCP object is found in AD (it means there are multiple CAS servers in the Exchange organization), Outlook client will choose one of the SCP entries that
are in the same site to obtain the AutoDisocover URL.
b. If we cannot find SCP object, then Outlook client will use DNS to locate AutoDiscover.
Outlook parses out the domain (SMTP suffix) via your EmaiAddress, then attempts to connect to the predetermined order of URLs via the suffix.
For example: If my email address is
[email protected]
Outlook tries POST commands to the following order of URLs:
https://contoso.com/autodiscover/autodiscover.xml
https://autodiscover.contoso.com/autodiscover/autodiscover.xml
NOTE: The URLs above is by design, hardcode
and cannot be changed.
c.
If those fail, Outlook tries a simple redirect to another URLs in IIS:
http://contoso.com/autodiscover/autodiscover.xml
http://autodiscover.contoso.com/autodiscover/autodiscover.xml
If none of these URLs work then DNS is most likely not set up correctly.
We can test that by pinging one of the above URLs.
If that is successful, we must ensure the URLs contoso.com or autodiscover.contoso.com are actually pointing to the CAS server.
If the ping fails then there is a chance that DNS is not set up correctly so be sure to check that the URLs are even registered.
NOTE: If contoso.com is a non-CAS server,
we should add a Host record with just AutoDiscover. And point that entry to your CAS server that is running AutoDiscover.
d.
If still failed, we can use DNS SRV lookup for _autodiscover._tcp.contoso.com, then “CAS01.contoso.com” returned. Outlook will ask permission from the user to continue
with AutoDiscover to post to https://CAS01.contoso.com/autodiscover/autodiscover.xml
Non-Domain-joined
It first tries to locate the Autodiscover service by looking up the SCP object in AD. However the client is unable to contact AD, it tries to locate
the Autodiscover service by using DNS.
Then, same as step b, c, d in
Domain-joined scenario.
6. How to change the AutoDiscover
service location order forcibly?
By default, Outlook client locates AutoDiscover service in that order above.
We can also change the order forcibly.
a.
If we want to locate AutoDiscover service via one of the autodiscover URLs, please running following command in EMS:
Set-ClientAccessServer -identity <servername> -AutodiscoverServiceInternalUri https://autodiscover.contoso.com/autodiscover/autodiscover.xml(URL
that you want)
b. If we want to locate AutoDiscover service via
SRV record, please follows this KB to set up SRV:
http://support.microsoft.com/kb/940881
7. How to check AutoDiscover Healthy
a. We should make sure the AutoDiscover
is healthy before using AutoDiscover to perform troubleshooting.
b.
We can browse following URL in IE explorer:
https://autodiscover.vamwan.com/autodiscover/autodiscover.xml
If it returns “code 600”, that means AutoDiscover is healthy.
Screenshot as below:
c. AutoDiscover itself returns errors to the requesting client if the incoming request does not contain the appropriate information to complete a
request.
The following table explains the possible errors that could be returned.
Error Value
Description
600
Mailbox not found and a referral could not be generated.
601
Address supplied is not a mailbox. The provided email address is not something a client can connect to. It could
be a group or public folder.
602
Active Directory error.
603
Others.
The 600 “Invalid Request” error is returned because a user name was not passed to the service. That is OK for this test because this does confirm
the service is running and accepting requests.
d.
If AutoDiscover service is not working well, I suggest re-building the AutoDiscover Virtual Directory for testing.
Steps as below:
1) Running following command in EMS to remove the AutoDiscover VD (we cannot delete it via EMC):
Remove-AutodiscoverVirtualDirectory -Identity "CAS01\autodiscover(autodiscover.contoso.com)"
Please refer:
http://technet.microsoft.com/en-us/library/bb124113(v=exchg.141).aspx
2)
Running following command in EMS to verify whether we have removed the AutoDisocver VD successfully:
Get-AutodiscoverVirtualDirectory | FL
Please refer:
http://technet.microsoft.com/en-us/library/aa996819(v=exchg.141).aspx
3)
Running following command in EMS to re-creating a new AutoDiscover VD:
New-AutodiscoverVirtualDirectory -Websitename <websitename> -BasicAuthentication:$true -WindowsAuthentication:$true
Please refer:
http://technet.microsoft.com/en-us/library/aa996418(v=exchg.141).aspx
8. Common issues
a. Outlook Disconnection
Issue and Troubleshooting
Issue:
Sometimes the Outlook clients cannot connect to the Exchange server after migrating to a new Exchange server or changing to new CAS. The Outlook clients
always connect to the old CAS server.
Troubleshooting:
To solve this issue, we should change the SCP via following command:
Set-ClientAccessServer -Identity
<var>CAS_Server_Name</var> -AutodiscoverServiceInternalUri
https://mail.contoso.com(newCAS’FQDN)/autodiscover/autodiscover.xml
b. Autodiscover
Certificate issue
Tips on Certificate:
Exchange requires a certificate to run an SSL protocol such as HTTPS. We can use the certificate that supports subject alternate names (SAN) in Exchange.
This is to allow the certificate to support resources that have different names, such as Outlook Anywhere and the Autodisocver Web application.
Issue and Troubleshooting
Issue:
We receiver the Certificate Principal Mismatch error when we use a SAN certificate.
Troubleshooting:
1) Please determine the FQDN that the client
uses to access the resource. Steps as below:
OutlookàToolsàAccount
SettingsàE-mailàclick
the Exchange accountàChangeàMore
SettingsàConnectionàExchange
Proxy Settingsànote the FQND that list in the
Only connect to proxy servers that have this principal name in their certificate box.
2)
Please using EMS to determine the value for the CerPrincipalName attribute: Get-OutlookProvider
This command returns the result for the EXPR name.
3)
Please re-setting the CertPrincipalName attribute to match the FQDN via following command:
Set-OutlookProvider EXPR –CertPrincipalName: “msstd:<FQDN the certificate is issued to>”
9. Resource for reference:
Autodiscover and Exchange 2007
http://technet.microsoft.com/en-us/library/bb232838(v=exchg.80).aspx
White Paper: Understanding the Exchange 2010 Autodiscover Service
http://technet.microsoft.com/en-us/library/jj591328(v=exchg.141).aspx
Certificate Principal Mismatch
http://technet.microsoft.com/en-us/library/aa998424(v=exchg.80).aspx
Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.HI,
I get following? when run the test? user is login to Domain A but accessing exchange in Domain B? -
Exchange 2007 SP3 Search Problems
I reset all the search indices on my mailbox databases. Event viewer has told me the crawl is complete and everything checks out when I do “test-exchangeSearch”
from PS. However, the index folders are considerably smaller than the original ones, (1.3GB vs 7GB) and only about 1% of database size. Multiple users can prove to me that searches are incomplete and not returning reliable results when just doing basic folder
searches from Outlook 2007. help!
IanAfter speaking with a senior MS Engineer, if you already have SP3 applied and tried to reinstall the search as I outlined above, you have corrupt your Exchange install and the ONLY option is to rebuild the box. After reinstalling Windows and Exchange, the
proper procedure to get search working perfectly is outlined below:
4. If you haven’t already,
upgrade toExchange Server 2007 Service Pack 3.
Exchange 2007 SP3 includes several major Search-related fixes and upgrades MSSearch 3.0 to MSSearch 3.1. This is a highly significant
upgrade.
5. Update to the latest available Rollup Update.
There are some very significant search fixes in the Rollup Updates for Exchange 2007 SP3. Some of these fixes are absolutely essential to install.
For example, Exchange 2007 SP3 Rollup Update 2 includes a fix that allows Exchange server to index emails even when the attachment cannot
be parsed – this is the number one call generator for Exchange 2007 search support cases.
To restate, upgrade to the very latest available Exchange 2007 SP3 rollup update, as there are many more search fixes available in the latest
rollup updates.
6.
Install IFilters and register them – follow ALL the steps below.
Install Filter Pack 1.0, which allows Exchange 2007 to index Office 2007 documents:
2007 Office System Converter: Microsoft Filter Pack
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=20109
7. Install the hotfix which addresses a known issue when search crawls a .vsd file.
960502 Description of the 2007 Office system hotfix package (Offfiltx.msp, Visfilter.msp): December 16, 2008
http://support.microsoft.com/default.aspx?scid=kb;EN-US;960502
Additional Information on the hotfix:
960166 Error message when a search process crawls a .vsd file on a Windows 64-bit operating system that is running the 2007 Office Filter
Pack: "The filtering process has been terminated"
http://support.microsoft.com/default.aspx?scid=kb;EN-US;960166
8.
Register the Filter Pack 1.0 IFilters. This is a manual process with Exchange 2007 but we have created a script to automate the process.:
944516 How to register Filter Pack IFilters with Exchange Server 2007
http://support.microsoft.com/default.aspx?scid=kb;EN-US;944516
9. Install Filter Pack 2.0 which allows Exchange to index Office 2010 attachments as well as some additional file types.
Download details: Microsoft Office 2010 Filter Packs
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=5CD4DCD7-D3E6-4970-875E-ABA93459FBEE&displaylang=en
10. Register IFilters 2.0 with Exchange 2007.
How to Register IFilters 2.0 with Exchange 2007 and Exchange 2010
http://technet.microsoft.com/en-us/library/ff354976(EXCHG.80).aspx
11. Disable signature verification for the Exchange 2007 search services by putting 127.0.0.1 crl.microsoft.com in the HOSTS file.
Certificate Revocation List
When the Microsoft .NET Framework 2.0 loads a managed assembly, the managed assembly calls the CryptoAPI function to verify the Authenticode signature
on the assembly files. The CryptoAPI function checks a Certificate Revocation List
(CRL) that is available at http://crl.microsoft.com
. This action requires an Internet connection.
The
Microsoft Search Indexer service (Microsoft.Exchange.Search.ExSearch.exe)
is a managed assembly that is loaded by Microsoft .NET Framework 2.0. After installing Exchange 2007 SP3, if the Exchange server or DNS cannot resolve
http://crl.microsoft.com for any reason
the outgoing HTTP requests may be dropped and an error message is not returned. This delay causes the CRL to time out and cached CRLs will expire. This affects the Microsoft Search Indexer service in such a way that any new email fails to be indexed.
Instructions to Modify HOSTS file on the Exchange 2007 Server
Add the following:
127.0.0.1 crl.microsoft.com – here are the instructions:
a. Go Start – Programs and choose Command Prompt and choose Run as Administrator.
b. Within the Command Prompt, change to this directory (the drive will be the one where you installed the OS):
C:\Windows\System32\drivers\etc\hosts
c. Add the following entry to the HOSTS file:
127.0.0.1 crl.microsoft.com
d. Save the HOSTS file.
13.
Rebuild Indexes
using ResetSearchIndexes.ps1
How to Rebuild the Full-Text Index Catalog
http://technet.microsoft.com/en-us/library/aa995966(EXCHG.80).aspx
a. Go Start – Programs and choose Exchange Management Shell and choose Run as Administrator.
b. Change to this directory (the drive will be the one where you installed Exchange 2007):
C:\Program Files\Microsoft\Exchange Server\Scripts
c. It is suggested that you rebuild indexes for one or a few databases at a time – use the following command to rebuild the indexes for 1
databases called dbname1 and dbname2:
.\ResetSearchIndex.ps1 –force dbname1 dbname2
d. It is suggested not to run the following command unless you have 1 Exchange 2007 server only in your environment because it will cause
all databases on all Exchange 2007 (and all Exchange 2010 servers, if there are any) to be reindexed at that same time:
.\ResetSearchIndex.ps1 –force all
14.
Monitor the Application Event Log for Event ID 110 for a particular database.
This will indicate the new index is complete for that database.
15. After receiving Event ID 110 for a database, check to see if the size of the CatalogData folder for that database is the expected
5% to 10% of the database size. If the size of the CatalogData folder is significantly smaller than that or if the size is a few kb or a few mb, go
to Step 17.
16. After you have received Event ID 110 and the size of the CatalogData folder is normal, test searching in Outlook online mode
and OWA to make sure search is working.
<strike>
</strike>
Ian -
Is there a problem using CFPOP in CF MX 7 with Exchange 2007?
We have a scheduled task that checks a mailbox and, depending
on the request, responds to the sender with information from our
contact database. It has worked fine for several years using CF MX
7 Standard and MS Exchange 2000. We just changed to MS Exchange
2007 and we get an error as follows: "Logon failure: unknown user
name or bad password." We can access the mailbox directly from
Exchange using the account and password, so we think we are passing
the correct information (example below).
<CFPOP ACTION="GetHeaderOnly" SERVER="192.168.1.15"
USERNAME="testaccount" PASSWORD="testpassword" NAME="getMail">
Is there something we're missing? We are certain that the IP,
account and password are still correct. We have assigned this mail
server to the Mail tab in CF Administrator and it can see it and
route CFMAILs through it.
Any help is appreciated.We discovered that Exchange 2007 has five specific steps that
have to occur in a particular order for CFPOP to resume working
properly. We did this (despite several security issues) because
this function is strictly internal. Not recommended for an
application available to the general public.
Steps for making Exchange 2007 work for CFPOP:
1) Start the POP service on the Exchange 2007 server.
2) Allow the necessary email accounts to use POP3.
3) Lower the security requirements on those accounts to allow
CF to send clear text instead of encrypted (SSL) requests to POP3.
4) Set the Exchange server to allow relay.
5) Lower the security requirements for relay.
I hope I explained this correctly. This is how my network
supervisor explained it to me. -
Cannot uninstall Exchange 2007
When I try to uninstall Exchange 2007 I get the following error under the Mailbox Role.
The virtual directory 'ExchWeb' already exists under 'server.domain.com/Default Web Site' Parameter Name: VirtualDirectoryName.
I actually tried removing the ExchWeb virtual directory on the Exchange 07 server but that didn't help. I haven't been able to find anything else on the internet regarding this issue.
Vincent SpragueHi,
From error "Exchange server "server" was not found. Please make sure you have typed it in correctly", I recommend you check if the Exchange 2007 server is under the CN=Servers container in ADSIEDIT.
If it is there, based on the situation, you couldn't uninstall Exchange 2007 Mailbox role via Add/Remove Programs or using Setup.com /mode:uninstall /role:<server roles to remove> command. The last resort is to uninstall Exchange 2007 Mailbox role
using ADSIEDIT, the method using ADSIEDIT should be only be used carefully.
If it isn't there, maybe the suggestion mentioned in the following thread can help you.
Unable to uninstall Exchange 2007 SP2 'Exchange server was not found.' - manual uninstall time?
http://social.technet.microsoft.com/Forums/exchange/en-US/fbea8afb-3d50-4ed1-b2f5-9bd28f648815/unable-to-uninstall-exchange-2007-sp2-exchange-server-was-not-found-manual-uninstall-time?forum=exchangesvrgenerallegacy
Here is an article about how to remove Exchange 2007 from a computer for your reference.
How to remove Exchange 2007 from a computer:
http://support.microsoft.com/kb/927464
Best regards,
Belinda
Belinda Ma
TechNet Community Support -
Hi
I'm looking for a solution that I can't seem to find. I have an Exchange 2010 server running in a dot local domain (domainname.local), so my SSL certificate is installed using the servers external email DNS name. email.mycompany.com
I have followed the instructions to resolve this on the Exchange server, implemented the changes so autodiscovery sees the server as email.mycompany.com. This works great for my Outlook 2007 users. The downside is that none of my Outlook 2013
clients can access their email without the certificate error server name mismatch.
I know Outlook 2013 has tighter security but I need to get rid of these cert errors, any thoughts out there?Hi,
Since both your Outlook 2007 users and Outlook 2013 users are using Exchange 2010 with the same server configuration, it should be working in both Outlook client version.
Please restart your IIS service by running IISReset /noforce from a Command Prompt window in Exchange to have a try. In Outlook, please re-create a Outlook profile to check whether the issue persists.
Regards,
Winnie Liang
TechNet Community Support -
Out of office sending out old messages - Exchange 2010 - Outlook 2007
Tracking down an issue of a user (I think it's only one) having their Out of Office Message always being a previous message from a year or two back. Doesn't matter if it's changed in Outlook 2007 or in OWA.
I've read some older post on this, but didn't find a clear answer.
This current Exchange 2010 setup is a migration from 2003. Could this be a leftover migration issue?
Anybody have this happen recently?Hi,
How do you know this is an old reoccurring message? Based on the content or time?
Since the MailboxAutoReplyConfiguration is correct, I suspect the issue can occur by certain client machine. At this stage, I suggest you disable OOF and re-enable
OOF on the problematic machine. If the issue persists, please refer to the following article to clean the problematic client’s Outlook rules. (run Outlook.exe /cleanrules in Run console.)
http://www.tech-recipes.com/rx/2161/outlook_2007_clean_up_command_line_switches/
Thanks.
Novak Wu
TechNet Subscriber Support in forum
If you have any feedback on our support, please contact
[email protected]
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Maybe you are looking for
-
i have a wrt54gs2 router, besides factory settings, i have some ports forwarded, i have my xbox 360 in the DMZ zone, wifi is set up without wpa or wep, i use mac address filtering. mixed mode, channel 11.... all other settings are factory, i have the
-
IPhone 4, Flip leather case and the 'Compass' app..just some info
Hello Members, and anyone new to the iPhone 4 with a 'Flip' type case that has a magnetic clasp. I had just got my new Iphone 4, and after fully updating it to iOS 4.1, I'd successfully managed to fix the screen protector that came with the all 'leat
-
Send forecast to another system
Hi, We are on APO 5.0 and want to send our forecast from a planning book to a partner. Has anybody ever done this via XML? Note that we are not planning to use ICH. But we have XI setup. Thanks. GM
-
Error while to trying to retrieve text
Hi, I created a web site using pl/sql, with the Apache Web server and the mod_plsql, but sometimes, when I browse on the pages , I have this error: Error while to trying to retrieve text for error ORA-03113 I also have problems with words like "h", "
-
DAG/cluster network troubleshooting
We have a 2 DAG cluster EX01 and EX02. EX02 holds all active copies and EX01 holds all passive copies. When trying to move active copies from 02 to 01 it fails everytime. Also trying to move Primary active manager from 02 to 01 fails. There is an e