Exchange 2013, Lync 2013, PKI,

http://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx?PageIndex=2&wa=wsignin1.0&CommentPosted=true
Hi,
I would like to implement this 2-tier PKI, but for Windows Server 2012 R2 & Windows 8.1 ENT.
I tried to do the win2013 pki but it failed to validate Exchange 2013 certificate, and a lot more problems, but this article seem very stable and working.
Just a few questions:
this is just for test, my setup will be:
External Domain: test2013.cu.cc   (free cu.cc domain)
                             name servers: NS1.he.net to NS5.he.net
External Domain: test2013.com (secondary domain, not really needed, from godaddy.com)
                             A   72.252.214.6
                             MX 5 mail2.test2013.com
                   mail2  A  72.252.214.7
                   7        PTR mail2
                   6        PTR test2013.com
External DNS: dns.he.net (free from he.com. Control all dns stuff for test2013.cu.cc)
          test2013.cu.cc  A  72.252.214.6
                          MX 5 mail.test2013.cu.cc
                          TXT "v=sfp1 mx ipv4:72.252.214.7 mx:test2013.cu.cc mx:test2013.com -all"
                          SPF "v=sfp1 mx ipv4:72.252.214.7 mx:test2013.cu.cc mx:test2013.com -all"
          mail            A 72.252.214.7
        # 72.252.214 rdns (reverse dns use standard octet)
         6                 PTR  test2013.cu.cc
         7                 PTR  mail.test2013.cu.cc
Internal Domain: test2013.lan
                            A   192.168.0.3
                            NS 192.168.0.3
                            MX  5 mail.test2013.lan
               mail   A     192.168.0.5
               DC1     A   192.168.0.3
               APP1  A   192.168.0.4
               firewall  A  192.168.0.1
               lync1    A   192.168.0.6
              lync2    A    192.168.0.7
Software used:
Windows Server 2012 R2
Exchange 2013
Lync 2013
VM1 = firewall (clears 5.2)   nic1=72.252.214.6 nic2=72.252.214.7 nic3=192.168.0.1
VM2 = DC1 (AD/DOMAIN/DNS/DHCP) nic1=192.168.0.3
VM3 = CA (offline CA) nic1=192.168.0.2 (not connected)
VM4 = APP1 (Issuing CA) nic1=192.168.0.4
VM5 = mail (Exchange 2013 CU3) nic1=192.168.0.5
VM6 = lync1 (Lync 2013 front server) nic1=192.168.0.6
VM7 = lync2 (Lync 2013 edge server) nic1=192.168.0.7 nic2=72.252.214.8
How do I setup this infrastructure with all info information provided.
How to make Exchange 2013 and Lync 2013 live as one on this network.
How to pass mxtoolbox.com  spf-test, smtp-test, reverse-dns-test  and spam-test.
How to make Exchange 2013 send all emails immediately, and not put it in draft when you click send.
How to make exchange 2013 & Lync 2013 certificate from the PKI setup VALID.
How to make external user access there mailbox using outlook 2013.
How to make external user access there lync account using lync client & outlook 2013.
How to fix "Move to DRAF, when click on send" ?

Hi Fbifido,
From your description, I would like to clarify the following things:
1. Exchange 2013 is not supported to run on Windows Server 2012 R2.
2. For Windows-based users, computers, and services, trust in a CA is established when there's a copy of the root certificate in the trusted root certificate store and the certificate contains a valid certification path. For the certificate to be valid,
the certificate must not have been revoked and the validity period must not have expired.
What's more, here is a helpful article for your reference.
Digital Certificates and SSL
http://technet.microsoft.com/en-us/library/dd351044(v=exchg.150).aspx
Besides, in order to avoid confusion and keep track of troubleshooting steps, we usually troubleshoot one issue per thread.
Hope it helps.
Best regards,
Amy
Amy Wang
TechNet Community Support

Similar Messages

  • Using IIS AAR as a reverse proxy for Exchange 2010 & Lync 2013

    hi
    i am planning to use IIS AAR as reverse proxy solution for both Exchange 2010 & Lync 2013 . need clarifications on the below.
    Is it production ready proof solution of using IIS AAR as a reverse proxy solution , if yes what is the sizing considerations for the same.
    Can we have exchange reverse proxy and lync reverse proxy on the same IIS ARR server.
    Is there any special consideration(license/certificates/cal licenses) needs to be taken care while using this solution
      4.  Deployment Guide available?

    hi steve.. thanks for reply..
    1 have gone through that.. however having both exchange & lync reverse proxy on single server is unanswered and the reason for having this in exchange forum is to have consideration from exchange prospective as well ... 
    I am also wondering this.  Can both exist on the same set of proxy servers?  I also plan to have a load balanced solution.  Has anyone had any luck with doing that?

  • Exchange 2013 Lync 2013 IM "Invalid Contact Information"

    Hi All,
    I'm setting up a new Exchange 2013 server using SP1 (CU5) as the baseline. I'm trying to get Lync 2013 integration for IM working, but I seem to getting a different error message from everyone else. While the first line is the same for people who have certificate
    errors, the third line is very different.
    2014-07-24T13:32:40.522Z,6,1,,,,0,ERROR:InstantMessageOCSProvider.ResetPresence. SelfDataSession not established.,
    2014-07-24T13:32:40.631Z,141,5,,,,0,"DEBUG:InstantMessageOCSProvider.SignInCallback. Context: [email protected], Sip address=sip:[email protected], Lyncserver=lync2013.geosoft.com",
    2014-07-24T13:32:40.647Z,141,1,,,,0,"ERROR:UCWEB Failure: Code=OcsRegisterFailure, SubCode=Undefined, Reason=None\r\nMicrosoft.Rtc.Internal.UCWeb.Utilities.UCWException: The endpoint was unable to register. See the ErrorCode for specific reason. --->
    Microsoft.Rtc.Signaling.RegisterException: The endpoint was unable to register. See the ErrorCode for specific reason.\r\n   at Microsoft.Rtc.Signaling.SipAsyncResult`1.ThrowIfFailed()\r\n   at Microsoft.Rtc.Signaling.Helper.EndAsyncOperation[T](Object
    owner, IAsyncResult result)\r\n   at Microsoft.Rtc.Internal.UCWeb.UCWAuthenticatedEndpoint.OotyUserEndpointEstablish_callback(IAsyncResult asyncResult)\r\n   --- End of inner exception stack trace ---\r\n   at Microsoft.Rtc.Internal.UCWeb.Utilities.AsyncHelper.EndAsyncCall[T](IAsyncResult
    asyncResult, String methodName, T ucwScopeInstance)\r\n   at Microsoft.Rtc.Internal.UCWeb.UCWAuthenticatedEndpoint.EndSignIn(IAsyncResult asyncResult)\r\n   at Microsoft.Exchange.Clients.Owa2.Server.Core.InstantMessageOCSProvider.<>c__DisplayClass33.<SignInCallback>b__32(RequestDetailsLogger
    logger)",
    So, I did the trace and it appears things are getting malformed when sending data? This is what the Exchange server is attempting to send.
    >>>>>>>>>>>>Outgoing SipMessage c=[<SipTlsConnection_369013E>], 192.168.0.x:11535->192.168.0.y:5061
    REGISTER sip:geosoft.com SIP/2.0
    FROM: <sip:[email protected]>;epid=AFEB7BEF65;tag=e284bb12fb
    TO: <sip:[email protected]>
    CSEQ: 1 REGISTER
    CALL-ID: 0506b0822fa640c1a2975f8ebcb60c3b
    MAX-FORWARDS: 70
    VIA: SIP/2.0/TLS 192.168.0.x:11535;branch=z9hG4bK40a2e4b3
    CONTACT: <sip:exch2013.geosoft.com:5075;transport=Tls;ms-opaque=91a37e8f3d315774>;methods="Service,Notify,Benotify,Message,Info,Options,Invite";+sip.instance="<urn:uuid:494c7ee5-e77e-52a8-86dc-a8a029d396c8>";text;audio;video;image
    CONTENT-LENGTH: 0
    EVENT: Registration
    EXPIRES: 1800
    SUPPORTED: gruu-10
    SUPPORTED: ms-forking
    SUPPORTED: msrtc-event-categories
    SUPPORTED: ms-userservices-state-notification
    SUPPORTED: ms-cluster-failover
    USER-AGENT: RTCC/5.0.0.0 OWA/15.00.0913.021
    This is the error it's getting back:
    <<<<<<<<<<<<Incoming SipMessage c=[<SipTlsConnection_369013E>], 192.168.0.x:11535<-192.168.0.y:5061
    SIP/2.0 400 Invalid Contact information
    FROM: <sip:[email protected]>;epid=AFEB7BEF65;tag=e284bb12fb
    TO: <sip:[email protected]>;tag=37D128C333B73F1A9B13488593AFDD4D
    CSEQ: 1 REGISTER
    CALL-ID: 0506b0822fa640c1a2975f8ebcb60c3b
    VIA: SIP/2.0/TLS 192.168.0.x:11535;branch=z9hG4bK40a2e4b3;ms-received-port=11535;ms-received-cid=5B37800
    CONTENT-LENGTH: 0
    SERVER: RTC/5.0
    ms-diagnostics: 1018;reason="Parsing failure";source="lync2013.geosoft.com"
    Is this a bug? I've been at this for 3 days replacing certificates and resetting Lync user accounts, but now I'm having doubts. 

    Additional information I was able to dig up using the Lync 2013 logger tool.
    Severity: warning
    Text: Routing error occurred; check Result-Code field for more information
    Result-Code: 0xc3e93f13 SIPPROXY_E_CONTACT_NOT_AUTHORIZED
    SIP-Start-Line: REGISTER sip:geosoft.com SIP/2.0
    SIP-Call-ID: 64f2f5422044488492ed1e9ee6fa7fd3
    SIP-CSeq: 1 REGISTER
    Peer: 192.168.0.y:29754
    $$end_record

  • Exchange 2013/Lync 2013 IM integration into OWA

    I had a quick question on the certificate requirements for Exchange/Lync 2013 integration for IM in OWA.
    Can I use the same public certificate I've used to secure OWA or do I need to create an internal cert?
    Not sure how that will work with the thumbprint or if I can use the same cert for two different services.
    Thanks
    Bryan

    Hi,
    It’s highly recommended that you use the same certificate across Lync and Exchange, as this will simplify troubleshooting.
    The simplest approach to configuring a certificate is to use the Lync certificate wizard to request and assign a certificate from your internal Certificate Authority (CA). Lync only has a single global realm, so the Subject Name of the certificate
    will be the default SIP domain. Once you have this certificate installed in Lync, export it to the Exchange environment. By default, Exchange will use a self-signed certificate, so you’ll need to replace the existing certificate using the Set-AuthConfig cmdlet
    in the Exchange Management Shell (EMS).
    More details:
    http://technet.microsoft.com/en-us/magazine/jj878110.aspx
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Message Error : Visual Basic for Applications (VBA) is not installed - Office Home & Business 2013 - Lync 2013

    Hi,
    I have an issue related to Office h&b 2013 and Lync 2013.
    Office h&b is installed on many computers, and we are deploying Lync 2013.
    In Lync 2013 it's possible to share Powerpoint presentation (if you have a Office Web Apps server installed).
    With a PC using Office Pro 2013, no problem. Powerpoint sharing with Lync 2013 is working.
    With a PC using Office H&B 2013, I have a message : 
    "XXXXX.pptx couldn't be converted for presentations because Visual Basic for Applications (VBA) is not installed on this computer. Please
    install VBA and try again."
    VBA is installed and usable in all Office applications.
    Office H&B is a click to Run installation and doesn't permit to add or remove features.
    Lync 2013 custom install permit to choose the installed features. VBA is already installed.
    I searched in many forums, including this one, and... no answers, or better say, no good answers.
    Because :
    - It's not possible add VBA from Office H&B 2013 install.
    - Repairing Office does not solve the problem.
    Any Idea ?
    Thanks for your help !
    Regards
    Stéphane

    As far as I know, Lync 2013 is not available with Office Home & Business 2013, you can check
    http://office.microsoft.com/en-in/home-and-business/
    Lisa Zheng
    TechNet Community Support
    Dear Lisa,
    Yes, it's true, Lync 2013 is not part of Office home & Business 2013, but you can install,it as standalone product.

  • Outlook 2013/lync 2013- promping for password

    In our setup we have an exchange 2007 server, and running office 2013 incl lync 32 bit. When I login to a computer and enter outlook or lync, it connect without any problems or credentials popup.
    But if the pc goes to standby and "wakes" up again, outlook request for login info. The strange thing is, that username should be like domain\username, but sometime outlook in username already have typed
    [email protected] - and then it won´t work even password is entered correctly
    The same goes for lync. Actually even lync is prompting for login, lync in the background already are signed in - so why come with this login prompt in lync?.
    The above was also the same in office 2010 and 2007, but just wondering if that is something that can not be changed. Is it is something with security settings or is this password prompt caused on client side or is it something setup on server. If users
    are logging into windows 7 after standby, there should be no need to sign in several more times in the different programs.

    As per your description, Lync is actually signed in while it prompts for login. Lync generally prompts you for credentials only after you're signed in and when it must connect to an external service such as the Microsoft Exchange Free/Busy service or the
    Exchange Calendar service. If Lync continues to prompt you for credentials after it has done this several times, there's probably an issue with Outlook or with the Exchange services. 
    So, according to your statement, you might need to troubleshoot on Outlook/Exchange side. Please try steps/method listed in this article to see if they can stop this prompt:
    http://support.microsoft.com/kb/290684/en-us

  • Exchange 2013 Dynamic Distribution Groups in Lync 2013

    Working on a new Exchange 2013 Lync 2013 environment.    I'm having trouble getting Dynamic Distribution groups that exist in Exchange to populate in to the Lync Address book.  Currently If I create a normal Distribution list in Exchange,
    it populates in to Lync as I would expect and can be searched and added to a users Contact list.  But for whatever reason the Dynamic distribution groups do not show at all in Lync.  They do show properly in the Exchange & Outlook Client GAL.
     And I can use them to send email to recipients.  I'm stumped and can;t find any documentation that addresses if it is by design or if I have missed something.

    By design it won't work, here is documentation.
    http://technet.microsoft.com/en-us/library/gg398577.aspx
    Lync Server 2013 uses the Distribution List Expansion Protocol (DLX) to expand distribution lists. This protocol also specifies the web service method that is used to get the membership of a distribution list. Microsoft Exchange Server supports dynamic groups
    that do not have members statically assigned to them. Instead, they store queries that are evaluated when the group is expanded. DLX does not support dynamic distribution lists.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • Lync 2013 Group Chat not working

    We have a 2010 server and when I move people over to 2013 group chat does not work. I can select the people I want to talk to, but they don't see any of the conversations. When I move the back to the 2010 it works again.
    We are running office 2013, lync 2013 and exchange 2010. 
    Any suggestions?

    Have you installed Persistent Chat in Lync 2013? You'll need to migrate the group chat data to the Persistent Chat pool and setup a Persistent Chat Endpoint for the legacy 2010 group chat clients, see: http://technet.microsoft.com/en-us/library/jj204901.aspx
    Please mark posts as answers/helpful if it answers your question.
    Blog
    Lync Validator - Used to assist in the validation and documentation of Lync Server 2013.

  • Lync 2013 crashes when double-clicking on contact to send IM...

    I have a 64 bit Windows 7 machine. I have Office 2010 and 2013 installed. I am able to successfully run Lync 2013 and login to the Lync Server and see my contacts and their statuses online.  However, every time I double-click on a contact name to send
    them an IM i get a message saying "Microsoft Lync has stopped working" and Lync shuts down and restarts. When I debug the error using Visual Studio 2010 I get an "Unhandled exception... Access violation" error.
    Here is what I know so far... It has to do with some incompatibility with Office 2010, because when I uninstall Office 2010, Lync 2013 starts working properly.  (However, I need Office 2010 installed for supporting my clients. <sigh>)
    Here's is what I've done so far...
    1. Uninstalled Office 2013 = Lync 2013 still crashes.
    2. Uninstalled Office 2010 = Lync 2013 works fine now.
    3. Reinstalled Office 2013 w/out Office 2010 present = Lync 2013 works fine.
    4. Reinstalled Office 2010 followed by Office 2013 = Lync 2013 still crashes.
    5. I've also delete the sip_ folder to have Lync recreate it = that doesn't work either.
    I have also updated Lync 2013 to the latest version update provided by Microsoft, but nothing seems to help.
    My Event Viewer says the following:
    Faulting application name: lync.exe, version: 15.0.4675.1000, time stamp: 0x54629b57
    Faulting module name: lync.exe, version: 15.0.4675.1000, time stamp: 0x54629b57
    Exception code: 0xc0000005
    Fault offset: 0x00f50000
    Faulting process id: 0x1564
    Faulting application start time: 0x01d024b896c56e36
    Faulting application path: C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
    Faulting module path: C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
    Report Id: 282d47fc-90ac-11e4-8ed2-14feb598d143
    Any help will be greatly appreciated!!!

    Hi bihtime3,
    I understand the inconvenience caused by this issue. I would like to confirm if you have tried the following scenarios.
    1. Repairing Office 2013 after installing Office 2010.
    2. Installing Office 2010 before installing Office 2013.
    Best regards,
    Eric

  • Install Lync 2013 by OCT Tools

    Dears,
    I have Lync 2013 and I wants to install it for client computers via SCCM 2012, I wants to use OCT tool for deploying the package, kindly I need all the steps for creating OCT tools and I wants to know where shall I put lyncentry.exe and MSP file after
    creation I mean which folder? Shall I put in main folder which are contains both 64bit and 86bit or I have to create separate OCT package for each 64bit and 86bit?  please snapshot.
    Thanks..

    Here is an article that talks about deploying Office 2013
    Lync 2013 is shipped as part of Office 2013
    http://technet.microsoft.com/en-us/library/cc179097.aspx
    http://blog.naevette.com.au/2013/10/15/packaging-lync-2013-for-enterprise-deployment/
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer" Regards Edwin Anthony Joseph

  • Issues with Hosted Exchange, UM and Lync 2013.

    Hello everyone!
    I am trying to deploy UM with Office 365 Hosted Exchange. We are using one Lync 2013 Standard Edition FE and have deployed one edge server. We have set up our firewall to host the Reverse Proxy.
    We do not use wildcard certs. External DNS resolves the _sipfederation and sip._tls SRV records to the external face of the edge server. The edge server functions as it should for remote users and mobility.
    I have tried to follow these instructions to the letter three times over to no avail.
    http://y0av.me/2014/01/07/lyncum365/
    Neither Snooper or Event Viewer show any particular issue, though when I try to dial out to voice mail I will get one to two rings and then 5 seconds of silence a fast busy, and finally "Call Unsuccessful".
    When checking the firewall logs I notice a seemingly random 10.x.x.x address being sent to the firewall by the external leg of the edge server. Wireshark captures it as STUN packets on port 3478 being sent to port 3478. These are being dropped by our firewall.
    I believe them to be RTP packets but I do not know if this is normal behavior. Has anyone any ideas?

    My mistake. Here is the snooper result.
    TL_INFO(TF_PROTOCOL) [edge\edge]0C4C.05E4::06/18/2014-15:43:34.153.0000000C (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265)) [3770767507]
    Trace-Correlation-Id: 3770767507
    Instance-Id: 2E5A
    Direction: incoming;source="external edge";destination="internal edge"
    Peer: exap.um.outlook.com:5061
    Message-Type: response
    Start-Line: SIP/2.0 488 Compression algorithm refused
    From: sip:sip.domain.net;tag=08FB9ED133BA396696FE6546EA6F3031
    To: sip:exap.um.outlook.com;tag=B8FFE4E9267ED6ECB78ADCC60126B53F
    Call-ID: 66602CE1F9980BFA94AD
    CSeq: 1 NEGOTIATE
    Via: SIP/2.0/TLS 10.11.11.23:50752;branch=z9hG4bK2132316E.5B3AF52DE2753A36;branched=FALSE;received=207.46.5.9;ms-received-port=50752;ms-received-cid=60172700
    Content-Length: 0
    Server: RTC/5.0
    TL_INFO(TF_NETWORK) [edge\edge]0C4C.05E4: :06/18/2014-15:43:34.153.0000000D (SIPStack,NegotiateLogic::SetCompressionType:NegotiateLogic.cpp(2701)) [559249495]( 00000079B1274FB8 ) Compression type is now CompOff
    TL_INFO(TF_NETWORK) [edge\edge]0C4C.05E4: :06/18/2014-15:43:34.153.0000000E (SIPStack,NegotiateLogic::ProcessCompressionResponse:NegotiateLogic.cpp(2217)) [559249495]( 00000079B1274FB8 ) Peer refused [488] our request for compression
    TL_INFO(TF_NETWORK) [edge\edge]0C4C.05E4: :06/18/2014-15:43:34.153.0000000F (SIPStack,NegotiateLogic::AdvanceOutboundNegotiation:NegotiateLogic.cpp(910)) [559249495]( 00000079B1274FB8 ) Outbound negotiation sequence is complete
    $$end_record
    And finally..
    TL_INFO(TF_PROTOCOL) [edge\edge0C4C.05E4::06/18/2014-15:43:49.379.0000002E (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265)) [962697980]
    Trace-Correlation-Id: 962697980
    Instance-Id: 2E61
    Direction: incoming;source="internal edge";destination="external edge"
    Peer: fe1.domain.net:61254
    Message-Type: request
    Start-Line: BYE sip:uminternal.um.prod.outlook.com:5066;transport=Tls;ms-fe=CO1PR02MB111.namprd02.prod.outlook.com SIP/2.0
    From: <sip:[email protected]>;tag=b736386270;epid=9bcee72318
    To: <sip:[email protected];opaque=app:voicemail>;tag=eced411395;epid=07C3F2A933
    Call-ID: 4266a095bdef8280d67c7e7df58446fc
    CSeq: 2 BYE
    Via: SIP/2.0/TLS 10.10.10.25:61254;branch=z9hG4bKC848F11A.A88BCA6858661A50;branched=FALSE
    Via: SIP/2.0/TLS 10.10.10.125:49156;ms-received-port=49156;ms-received-cid=401200
    Route: <sip:edge.domain.net:5061;transport=tls;opaque=state:Si;lr>
    Route: <sip:exap.um.outlook.com:5061;transport=tls;epid=07C3F2A933;lr;ms-key-info=AAEAARc45bIQE6UJAYvPAR8eV4QTvCH3EE2Kxtie7I2PMCSj-2aArKHP8dStYlJe-9jphIkz_mDEkCD_v8hY-mghQEHD6-F12E7E14YG-TJ2gEcQE0Bx2r_rDB3LrzRZzgQ0WVvxreLPWGI80elWF-xfbc_X3JE8mOR2OB9KQM8-e9WOjfq2kj6CnDGeL0yzgz4OB8zm-ao03Yo4gMZ-BpwaxC3BNuvvVDJo9wqrYftq_Z3MIVewWrqcDt5Td4vxCsMiXdwEqtEIRKVvQoqboleBJAyQl-C3qGgfEoSkUnApFuTSnQYRa4kbZ1iPaACpdKT-VTQGjc9HXfps48YJCsIXW0Ab_NSM2uvhUyw900men1ukXSmoZoWZbwqe5siuWVUcFoQl1h1Jcy4lCyZUfDZoqPzDioLqTk9iUmS8fa-PAJjsq72yGjVB_y1aJSxtHVsw7MiDqOGOPqT3dmF-sINkeyuokCy8UCf_cQHmEHwVzZLUJqaVccr3QNCLsBzhcWSypnC60ZZphOKuwl6RvUXWICPf0ubLTL2ppC3tWEgFdUUWOPVd84uGlMcqRLKGb1qrmpj8Nu6Lte7t5n2pMEBCfgAe79t4GO0C5KScdKT_XBM1iIBRXdNkPKHfSgC-wPQgRikdw7vRD-hOWlN5Lay7-zkQ4Ag6rauszFTAwbft99OieAOxKIsgYcxXxcG6;ms-route-sig=fiEMuzbN4_PyEz_I5gG3g8FtqNAonwgZCoRnOq-ByfYEtywTZp-Hk_eAAA>
    Max-Forwards: 69
    Content-Length: 0
    ms-client-diagnostics: 22; reason="Call failed to establish due to a media connectivity failure when both endpoints are internal";CallerMediaDebug="audio:ICEWarn=0x40003a0,LocalSite=10.10.10.125:6735,LocalMR=10.11.11.23:51430,RemoteSite=10.27.46.15:5286,RemoteMR=207.46.5.80:54106,PortRange=1025:65000,LocalMRTCPPort=51430,RemoteMRTCPPort=54106,LocalLocation=2,RemoteLocation=2,FederationType=0"
    $$end_record

  • No users are being migrated to the Unified Contact Store (UCS) for Lync 2013 - Exchange 2013

    I'm having difficulty getting the unified contact store to work on a migrated Lync/Exchange environment. Both servers have been upgraded to 2013 CU2, and almost everything appears to be working properly...except UCS.
    By default the global CsUserServicesPolicy has UcsAllowed set to True. In that mode, none of the Lync users were being migrated to UCS, so I set the global policy to False and created a new Policy called "AllowUCS" and set UcsAllowed to True. I then
    assigned that policy to myself and a couple other test accounts. Still, my contacts are not being migrated to the UCS after logging in with Lync 2013.
    Other Lync/Exchange integration features are working properly. I have set up OAuth, and it tests successfully, and Lync integration with OWA is working successfully, so I know at least some communication is happening properly between the servers.
    Here is what I'm getting when I run some diagnostics from the Lync server:
    PS C:\Users\administrator> get-csuser jdoe |FL Name,UserServicesPolicy
    Name               : Jon Doe
    UserServicesPolicy: AllowUCS
    PS C:\Users\administrator> Get-CsUserServicesPolicy |FL
    Identity  : Global
    UcsAllowed : False
    Identity   : Tag:AllowUCS
    UcsAllowed : True
    PS C:\Users\administrator> Debug-CsUnifiedContactStore -Identity [email protected] |FL
    UcsMigrationAttemptCount : 0
    LastUcsMigrationAttempt  :
    SipUri                   : [email protected]
    UcsMode                  : Disabled
    PS C:\Users\administrator> Debug-CsUnifiedContactStore -PoolFqdn lync.domain.org
    FrontEnd          : lbclync.domain.org
    UcsDisabledCount  : 141
    UcsAllowedCount   : 0
    UcsMigratingCount : 0
    UcsMigratedCount  : 0
    FailedUserData    :
    PS C:\Users\administrator> Test-CsUnifiedContactStore -UserSipAddr
    ess [email protected] -TargetFqdn lync.domain.org
    Target Fqdn   :lync.domain.org
    Result        : Failure
    Latency       : 00:00:00.0654970
    Error Message : User has not been migrated. Verify that the user has a mailbox
                    in Exchange and that the user has been migrated.
    Diagnosis     :
    Anyone know what I am missing?

    Hi,
    Please make sure the user has been provisioned with an Exchange 2013 mailbox and has signed into the mailbox at least once.
    If the user logs in with a Lync 2010 or earlier client, or if the user is not connected to an Exchange 2013 server, the user services policy is ignored and the user's contacts remain in Lync Server.
    Please also check the registry key on the client computer:
    HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Lync\<SIP URL>\UCS
    If the user's contacts are stored in Exchange 2013, this key contains a value of InUCSMode with a value of 2165.
    Kent Huang
    TechNet Community Support

  • Exchange 2013 SP1 Object is corrupted and inconsistent state after Lync 2013 Installation

    Hi Fellows,
    I am facing an issue with Exchange 2013 SP1 (5.0.847.32)
    environment. I recently installed Lync 2013 (version: 5.0.8308.0) a week ago and just recently start getting the below error when configuring delegation or modifying the users/groups from Exchange Control Panel:
    "The Object <object DN> has been corrupted, and it's in an inconsistent state. The following validation errors happened:
    The access control defines the ObjectType <object guid> that can't be resolved.."
    I can see some forum threads with same issue (links given below) but unable to find if this is a known issue and how to get it resolved. Need assistance if anyone has faced same and could help me out to figure it.
    http://social.technet.microsoft.com/Forums/exchange/en-US/72310530-d1de-4b39-a0fb-1592247df03f/access-control-entry-issue-after-installing-lync-2013-into-the-forest?forum=exchangesvrdeploy
     http://www.networksteve.com/exchange/topic.php/Issue_with_exchange_2013_lync_2013_intergration/?TopicId=37192&Posts=2
    J.A

    Hi
    Usually the affected SID objects are referring to deleted objects.
    Use the PsGetSid tool to try to resolve them.

  • Lync 2013 On Premises integration with Exchange Online Unified Messaging

    I am working on deploying Lync 2013 Server on premises and integrating it with Exchange Online. We do not use Exchange on premises.
    My question is how to integrate with Unified Messaging specifically. Other functions like Calendar, call logs seem to be working fine.
    There are many guides online on how to do this, and I have read many and attempted to follow with no luck. All seem to assume that UM has already been deployed on prem which I don't have. Is this possible to integrate Lync with Exchange Online without having
    and Exchange deployment on premises first.
    Another source of confusion is the Office Voice Access number and how Lync clients dial voicemail. Where does this go if somebody dials internally (from Lync) and externally (from PSTN)? Exchange online or Lync on prem? And if Lync, then my guess would be
    Lync forwards on to Exchange Online UM somehow. Do I have to purchase a number from somewhere because of it being on 365 or can I use a spare DID?
    From my tests so far, when I call voicemail as any user, it seems to dial that same user and then the call fails.
    Hopefully someone can shed some light on this for me.

    You can integrate Exchange UM with Lync Server 2013.
    Please check the deployment process at http://technet.microsoft.com/en-us/library/gg398968.aspx
    Lisa Zheng
    TechNet Community Support

  • LYNC 2013, Exchange 2013 / OWA presence not updating from calendar entries

    Have a test environment of LYNC 2013 and EXCHANGE 2013.
    No software clients - pure OWA access.
    IM works within OWA and I can manually set availability which is seen correctly by other users.  What does not happen is any calendar entries - they do not update the presence status (ie. does not go to busy when in a meeting ).
    I did install Lync client 2013 and that did work ( and updated OWA ) - but I want a pure web environment without the need for additional software based clients.
    Can this work?  If so is there anything that can be checked to see where the issue is?
    Thanks in advance.

    Hi,
    Maybe it's my misunderstanding. Did you mean you don’t want additional software based clients (including Lync client 2013)?
    If you don’t install a Lync client on user workstations, you cannot see presence of Lync users from OWA.
    What’s more, for Lync side, if you do not install Lync client software the only way to use Lync is Lync Web App (a browser-based meeting client). Lync Web App only support to join Lync Meetings. However, Lync meeting cannot schedule by Lync Web App and OWA.
    Here is a link about Lync Web App may help you:
    http://office.microsoft.com/en-in/lync-help/what-is-lync-web-app-HA103699740.aspx
    If you want to create Lync Meetings but don’t have Microsoft Outlook you can use Lync Web Scheduler (a web-based program)
    More details:
    http://office.microsoft.com/en-in/lync-help/lync-web-scheduler-HA103466460.aspx?CTT=5&origin=HA103699740
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

Maybe you are looking for

  • How to downgrade boot camp?

    I was wondering if someone can give me a link to a Boot Camp that support Windows 7 Ultimate 32-bit?

  • Web Service With Dynamic URL (Very Basic Conceptual Question)

    Hi everyone, I would like to employ JAX-WS to generate and publish a web service along with a web-based client which uses the service. The problem is: I want to deliver both the server (with its service) and the client to a customer, who will install

  • How to clear "other" storage space

    How do you clear storage space taken up by "other"?

  • Which jar files should I use for XSLT?

    I'm trying to do one of the examples from the Java/XML tutorial on this site. I can't get it to work. I started with the JAXP jar file and couldn't compile because it couldn't find one of the classes it needed. I then added the XALAN jar file to my C

  • Creating Survey URL

    Hello frenz, I followed the config doc C22 Lean Campaign Mgt., but after generating the Survey URL and while Testing it, whenever I click the SAVE push button, I get this error : "The request method ïPOST is not supported by HTTP Provider service.