Internal server name .local and having a certificate mismatch

I have one RD server with all the roles on it and I'm receiving a SSL certificate error because my internal server name is a .local and the SSL has been assigned to my apps.domainname.com address.
I've ran the powershell cmdlet Set-RDPublishedName to reflect the apps.domainname.com, but this doesn't seem to make a difference.

Hi Bill,
1. We know Set-RDPublishedName worked because it shows apps.domainname.com for Remote computer in the prompt.
2. In Server Manager -- RDS -- Overview -- Tasks -- Deployment Properties -- Certificates tab, please make sure you have set your certificate for all purposes (RDCB Single Sign On, RDCB Publishing, RDWeb, RDG).  We know it is not set (at least) for
publishing because you are seeing the Unknown publisher warning.
3. On the client PC, please make sure you have mstsc.exe version 6.2.9200 or later installed.  For Windows 7 you need to download and install the DTLS and RDP 8.0 updates.  Windows 8 and later already includes the new client.
4. On your server, please enter the following in an administrator command prompt:
wmic /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSGeneralSetting Set SSLCertificateSHA1Hash="e2f034c171b92afc96b23b7f4da15728c1e461a9"
Substitute your certificate's thumbprint for the Hash listed above.  The quickest way to get your cert's thumbprint is to open the certificate, on the Details tab highlight the thumbprint with your mouse, press Ctrl-C to copy it, then paste it
into the command prompt using the system menu Edit--Paste command.  After pasting simply delete out the spaces in the thumbprint using backspace and the left arrow key.
5. For best results with RD Web Access, please use IE and Allow and Run the Activex control when prompted.  Selecting the Private option on the RD Web logon page is preferred.
Once you finished with the above items please test again and reply back here with your results, whether positive or negative.
Thanks.
-TP

Similar Messages

  • Lync 2013 - Easy way to insert internal server name onto client

    A little background.  Currently only the IT dept is using Lync 2010 or Lync 2013.  We are not using Exchange(happening soon though).  Our Lync Server is only internal(again working on building an edge server).  Our Lync
    clients used to connect automatically with their AD name when restarting or logging into Lync. 
    Last week we noticed that Lync 2013 has upgraged to Skype for Business. This made us not log into Lync until we figured out why.  We finally figured out that if we put the FQDN in the Internal Server name Lync 2013 will work again(was left blank
    before).  We stopped the updates from going out but a few still got it. We manually went around and fixed those Lync 2013 clients.  My question for you all is there an easy way to push the FQDN to the internal server name under Tools-->Personal-->advanced..? Looking
    for a script that I can have them click or some other way.   

    Hi Hurley081182,
    Agree with others, it’s recommend to use Lync 2013.admx Administrative Template, which contain the registry-based policy settings that you configure for Group Policy objects in the domain.
    For more details, please check out the following article.
    Configuring client bootstrapping policies in Lync Server 2013
    https://technet.microsoft.com/en-us/library/gg425941%28v=ocs.15%29.aspx
    Best regards,
    Eric
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • I am trying to set up my college email on my phone, but it says it can't verify my account. I have tried just about every server name possible and I don't know what to do. Help?

    I am trying to set up my college email on my phone, but it says it can't verify my account. I have tried just about every server name possible and I don't know what to do. Help?

    Yes. Check your student manual or contact your help desk.

  • "Is it possible to hide/remove/change the server name/type and

    Is it possible to change the server name/type and version number being sent in the http response header by iPlanet Web server so a hacker can't see what server and version I'm running? If yes, what is the procedure to do it?

    Hi,
    I have tried the ServerString none entry in magnus.conf but still it is showing the Server information in the header if you use telnet . Is there any other way to hide or to mask this information.
    Thanks,
    Ramki

  • What does 500 internal server error mean and how do i fix it???

    When I try and update my Producteev app it keeps telling me that I have a 500 internal server error! What does that mean and how do I fix it! I recently had to have my logic board replaced and my mac is only 3.5months old! I thought this thing wasn't suppose to be giving me problems like this!!! Please help!!!

    500 errors in the HTTP cycle
    Any client (e.g. your Web browser or our CheckUpDown robot) goes through the following cycle when it communicates with the Web server:
    Obtain an IP address from the IP name of the site (the site URL without the leading 'http://'). This lookup (conversion of IP name to IP address) is provided by domain name servers (DNSs).
    Open an IP socket connection to that IP address.
    Write an HTTP data stream through that socket.
    Receive an HTTP data stream back from the Web server in response. This data stream contains status codes whose values are determined by the HTTP protocol. Parse this data stream for status codes and other useful information.
    This error occurs in the final step above when the client receives an HTTP status code that it recognises as '500'. Frank Vipond. September 2010.
    Fixing 500 errors - general
    This error can only be resolved by fixes to the Web server software. It is not a client-side problem. It is up to the operators of the Web server site to locate and analyse the logs which should give further information about the error.
    Fixing 500 errors - CheckUpDown
    Please contact us (email preferred) whenever you encounter 500 errors on your CheckUpDown account. We then have to liaise with your ISP and the vendor of the Web server software so they can trace the exact reason for the error. Correcting the error may require recoding program logic for the Web server software, which could take some time.
    http://www.checkupdown.com/status/E500.html

  • I am receiving 2 errors 500 internal server error nginx and 404 internal server error nginx

    I also cannot go from and email message in outlook to the youtube website nor can I get youtube.com to come up. That page gives me a 404 internal server error nginx. Until the last few days I have been able to get to you tube and have not received these errors.

    Which security software (firewall, anti-virus) do you have?
    Some have been reported to cause these errors.<br />
    Panda anti virus may cause the 404 internal server error nginx<br />
    I can't remember which software can be causing the 500 internal server error, but it is usually caused by security software adding a proxy to monitor internet traffic

  • Characters in the Server Name ( '_' and '-')

    Hi
    The notes 1824494 and 1796993 highlight problems that may occur if the server name with the underscore character '_':
    for example, "SAP_SERVER."
    Can anyone tell me if you may have problems if the server name has the character '-':
    for example, "SAP-SERVER"?
    I need to install the version SAP 9.0 PL 10.
    Thanks
    MissN

    Hi,
    The following special characters are not allowed for server name.
    &, <, >, ", or ’.
    You can use hyphen symbol.
    Thanks & Regards,
    Nagarajan

  • Exchange 2010 - Outlook Anywhere trying to connect to internal server name first before connecting to proxy server

    Hello,
    I have an Exchange 2010 question which I will post in the Exchange 2013 section since the Ask a question button in the legacy Exchange Servers section of technet takes me back to the part of Technet where I can only ask questions regarding Exchange 2013.
    If someone can point me to a part where I can place a question in an Exchange 2010 forum please let me know.
    We have Exchange 2010 setup with a CAS array listening to outlook.internaldomain.com
    We have TMG 2010 setup with a rule for Outlook Anywhere, the rule listens to mail.externaldomain.com and traffic that meets this rule is let through to outlook.internaldomain.com.
    When I fire up my laptop, which is connected to the internet, and start Outlook and let it configure my profile through autodiscover it sets it up correct and fills the Outlook profile with a servername stating outlook.internaldomain.com and a proxyserver
    to be used stating mail.externaldomain.com. After initial setup when my Outlook starts it almost immediatly prompts me for a username and a password so this is working fine.
    At the office we have an internal network segment where DHCP is servicing the connecting clients and giving them our internal DNS servers because they need connection to some other network segments which are not available to the internet. This network segment
    does not have access to our internal Exchange environment but has full access to the internet. Clients in this network segment do want to use Outlook so using Outlook Anywhere for them is the logical way to go. When I connect my laptop to this network segment
    I get handed an IP address and our internal DNS servers, when I start Outlook it takes about two minutes before a the credential prompt pops up and another 2 to 6 minutes after entering credentials before it says all folders are in sync. This is quite long
    and our clients find this unacceptable.
    I started testing what might be going on here and I have found that when I manually enter external DNS servers the Outlook password prompt will popup in seconds and all is working as expected so it seems Outlook is trying to connect to the internal servername
    when using our internal DNS servers (which can resolve outlook.internalnetwork.com) instead of directly going to the proxy server which is to be used for Outlook Anywhere.
    When I start a network monitor trace my thoughts are confirmed because when I am connected to the internal network segment OUTLOOK.EXE first tries to connect to outlook.internaldomain.com, it almost immediately gets a response stating that this route is
    inaccessible but OUTLOOK.EXE keeps on trying to connect untill some sort of time out is reached (somewhere around two minutes) after which it connects to mail.externaldomain.com and Outlook shows the credential prompt.
    So to round it up, when connected to DNS servers that can resolve the internal servername Outlook tries to connect to the internal servername in stead of the external name, Outlook does not reckognize the answer from the network that the internal route is
    not acessible (or it does but does nothing with this information).
    Has anybody experienced this behaviour in Outlook?
    Does anyone have a solution in where I can force Outlook to connect to it's proxyserver and disregard the internal servername?

    Thank you for your reply.
    The client computers that are experiencing the issues are not domain joined, the only reason I can think of why this is occurring is because the DNS servers are able to resolve the internal hostname of the server, but I would expect Outlook to always use
    the proxy server that has been set in the configuration of the Outlook profile. Or at least acknowledging the answer that the initially tried route is inaccessible and immediately continue to the proxy server.
    For setting the same hostname for internal and external use, we use different namespaces internally and externally, do you mean setting the external hostname on the CAS array for internal use ? Wouldn't that push all internal communication to the internet
    and to the outside interface of the TMG where the server is published with that hostname ?

  • Internal Server Error #(IS6532) and Auth701 Servis...

    Dear Sirs
    To save you repeating yourselves by trying to give me fruitless advice, I'm going to start by telling you what I already know. Please rest assured though that this is a complaint.
    I know that BT have fallen out with Yahoo and that you're transferring our email services to another email provider. I have lately endured an intermittent break in my email service which puts my email out of action for hours at a time. This interrupts my ability to contact my friends - some of them customers of mine - and to fulfil my responsibilities to the charity I have certain duties with AND (you'll be perturbed to hear) prevents me being notified on those regular occasions when my BT bill becomes payable. I am 'paperless' as far as possible; indeed, I congratulate you on providing me with this web form as a means of submitting a complaint to you, though clearly, it seems you're not too fond of email yourselves....
    I say intermittent breaks in service; I mean almost daily for about eight months now.
    At first I was prompted to call you. I had had a problem – my password continually being refuse and needing to be changed then being unable to log on to the email servers. I understand you 'solved' that by deciding to terminate the contract with Yahoo. I was told on those all too frequent occasions when I contacted you, it was a problem with my POP3 mail client that had prompted me for my password - several times a day for months on end - that if I refrained from logging-in to multiple devices - like a LOT of people, when I ONLY use one PC, I don’t use my smartphone to access my messages
     Like you though, I never understood why such a common situation – such as millions of people accessing their email on numerous device like this these days - should mean the Yahoo email servers couldn't cope. I applaud your decision therefore to look for a better service elsewhere... Can you see where this is going? Please bear with me.
    After a few short months, in March 2013 if memory serves, I heard that BT was ditching Yahoo and that my email service would be transferring to the comforting bosom of BT. Or rather, to another American company - but not Yahoo.
    Shortly thereafter, this problem started to occur again, though with a slight tweak that has added to my irritation. These days - almost daily for eight months - I find I can't log-on to the Yahoo email servers, I'm given the frightening news that 'suspicious activity' has been detected on my account, and am told, on those frequent occasions, almost daily, when I contact you, that I must change my password and/or I must change my security questions in order to make the problem go away.
    Initially I followed your advice. I changed my password. I changed my security questions. I changed them again. I changed them again. I barely know where I was born now, nor who my mother was. Each time though, the problem recurred after a day or two. I checked I wasn't letting my different devices auto-sync as before. I changed the security software on my PC. Nothing changed, so I stopped following the very high quality, NOT, advice of the highly qualified BT help line staff that is when I could understand their gibbering.
    In bitter reflection of what I presently perceive to be BT's corporate aspirations, I am now enduring an effective break in service - almost daily for eight months - which lasts for a few hours before everything returns to normal. I stopped wasting my time changing my password and contacting customer (no) help (at all) line. Now I'm hoping you'll stop wasting my time telling me that I should contact customer help.
    Regrettably, I've spoken to numerous people in the last few months -who despite my explaining the above at length couldn't resist telling me I should change my password no less than eight times between them. With the end result that next day I’m back to square one having to go online and change my password etc AGAIN.
    As you can see from my signature I no fool, I’ve worked with computer for almost 30 years now, with the causation in 99.9999% of case like this being POOR CODEING in the main program or subroutine, usually caused by an undertrained **bleep** that thinks he/she knows it all but knows jack
    Yours NOT respectfully
    P Mason
    M. Eng.Tec

    Welcome to this forum.
    This is a customer to customer forum only,
    This is where customers help each other get the most out of BT products & services.
    Anything you post here does not go to BT. Although the forum is moderated by BT, not all posts are read.
    If you need direct help from BT or have an urgent problem please use this linkContact Us.
    This is a public forum which can be viewed worldwide, so please do not post any personal information, especially phone numbers, account numbers, fault numbers, address information or email addresses, as this could be used to impersonate you.
    Thanks
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Getting the HTTP server name, port and context name inside the init()

    I have a servlet which is initialized when the Web server comes up. Is there any way I can print the complete URL from this servlet?
    I am aware that this can be done by using request object. But note that in this case, there is no request object. All we have is the ServletConfig and ServletContext.
    Pasting a part of my code here.
    public class MyInit extends HttpServlet
    private ServletContext m_servletContext = null;
    public void init(ServletConfig config) throws ServletException
    super.init(config);
    m_servletContext = config.getServletContext();
    //System.out.println("Print the URL here...")
    }

    Only a request has a URL. It's possible for servlets to be mapped to respond to more than one URL, and the server can be configured to respond to more than one host and at more than one port. So none of those things you are asking for have any meaning without an actual request.

  • My Ipad will receive e-mails but cannot send e-mails. I use comcast email and have check server names etc and everything is correct. Any suggestions?

    How do I get my Ipad to send e-mails when I can receive them. I use comcast.net and all the settings are correct?

    iOS: Unable to send or receive email
    http://support.apple.com/kb/TS3899
    Can’t Send Emails on iPad – Troubleshooting Steps
    http://ipadhelp.com/ipad-help/ipad-cant-send-emails-troubleshooting-steps/
    Setting up and troubleshooting Mail
    http://www.apple.com/support/ipad/assistant/mail/
    Using a POP account with multiple devices
    http://support.apple.com/kb/ht3228
    iOS: Adding an email account
    http://support.apple.com/kb/HT4810
    iOS: Setting up an Outlook.com, Hotmail, Live, or MSN email account
    http://support.apple.com/kb/ht1694
    iPhone, iPad, iPod touch: Microsoft Outlook 2003, Outlook 2007, Outlook 2010 may not display contacts and calendars after sync
    http://support.apple.com/kb/TS1944
    Server does not allow relaying email error, fix
    http://appletoolbox.com/2012/01/server-does-not-allow-relaying-email-error-fix/
    Why Does My iPad Say “Cannot Connect to Server”?
    http://www.ehow.co.uk/info_8693415_ipad-say-cannot-connect-server.html
    How to Delete Email on the iPad
    http://ipad.about.com/od/iPad_Guide/ss/How-To-Delete-Email-On-The-Ipad.htm
    How to Mass Delete Emails from iPhone and iPad Inbox (with video)
    http://suiteminute.com/how-to-mass-delete-emails-from-iphone-and-ipad-inbox/
    How to add, send and open iPad email attachments
    http://www.iskysoft.com/apple-ipad/ipad-email-attachments.html
    How to Sync Contacts with Your iPad Using iTunes
    http://www.dummies.com/how-to/content/how-to-sync-contacts-with-your-ipad-using- itunes.html
    iOS: ‘Mailbox Locked’, account is in use on another device, or prompt to re-enter POP3 password
    http://support.apple.com/kb/ts2621
    iCloud: Create a group and add contacts to it
    http://support.apple.com/kb/PH2667
    eMail Groups - You can use a third party app that many users recommend.
    MailShot -  https://itunes.apple.com/us/app/mailshot-pro-group-email-done/id445996226?mt=8
    Group Email -  https://itunes.apple.com/us/app/mailshot-pro-group-email-done/id445996226?mt=8
    iPad Mail
    http://www.apple.com/support/ipad/mail/
    Configuration problems with IMAP e-mail on iOS with a non-standard SSL port.
    http://colinrobbins.me/2013/02/09/configuration-problems-with-imap-e-mail-on-ios -with-a-non-standard-ssl-port/
    Try this first - Reset the iPad by holding down on the Sleep and Home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons. (This is equivalent to rebooting your computer.)
    Or this - Delete the account in Mail and then set it up again. Settings->Mail, Contacts, Calendars -> Accounts   Tap on the Account, then on the red button that says Remove Account.
     Cheers, Tom 

  • What is 500 internal server error? and how to resolve it?

    I'm unable to open any website through mozill. other browsers working fine, but i need mozilla only but its not working.
    plz help me to resolve this problem.
    i completely uninstalled and reinstalled the mozilla still the same problem

    Hi ajaythamke, 
    This is a commercial line product. For the best answer to your questions you will need to repost your question to the following links. 
    http://h30499.www3.hp.com/t5/Business-Support-Forums/ct-p/business-support 
    http://h30499.www3.hp.com/t5/Printers-LaserJet/bd-p/bsc-413 
    I am an HP employee.
    Say Thanks by clicking the Kudos Star in the post that helped you.
    Please mark the post that solves your problem as "Accepted Solution"

  • Server name in outlook profile stay the same after SSL changed from local to public fqdn

    Hi,
    I switched our UCC certificate for exchange 2010 so that it is no longer include .local in it. I used different FQDN url for external and internal (i.e externaURL is ExSrv.abc.com and internalURL is InSrv.abc.com). After I changed all settings, I found that
    the outlook profiles are still using the internal server name (i.e. myexchangesrv.abc.local). Is this normal? Should I expect the server name to be the new internalURL? The following are the commands I used and I also used EMC to change the OWA and ECP's internal
    URL to "InSrv.abc.com" as well. Did I missing anything?
    Set-ClientAccessServer -Identity MyExchangSrv -AutodiscoverServiceInternalUri https://InSrv.abc.com/autodiscover/autodiscover.xml
    Set-WebServicesVirtualDirectory -Identity "MyExchangSrv\EWS (Default Web Site)" -InternalUrl https://InSrv.abc.com/ews/exchange.asmx
    Set-OABVirtualDirectory -Identity "MyExchangSrv\OAB (Default Web Site)" -InternalUrl https://InSrv.abc.com/oab
    set-ActiveSyncVirtualDirectory -Identity "MyExchangSrv\Microsoft-Server-ActiveSync (Default Web Site)" -InternalUrl "https://InSrv.abc.com/Microsoft-Server-ActiveSync
    Thank you,
    Aldous

    Hi,
    When an Outlook client goes to connect to an Exchange 2010 database, it looks at an attribute associated with the mailbox database called RPCClientAccess to determine which client access server/client access server array to use for connectivity.
    Outlook 2007 and Outlook 2010 clients do not pickup this change automatically when you change the value of RPCClientAccess server, you need to repair Outlook Profile to update new RPC endpoint.
    However, be careful to Change this property, because this can broke Outlook Clients to Exchange:
    http://blogs.technet.com/b/exchange/archive/2012/05/30/rpc-client-access-cross-site-connectivity-changes.aspx
    Meanwhile, this attribute must be point to client access server or client access server array. You must have an CAS array named “InSrv.abc.com” as your expected.
    Also I find an similar thread about your concern, please refer to below link as “Brian Day” mentioned:
    https://social.technet.microsoft.com/Forums/exchange/en-US/2d0c0f5f-e4ec-4f33-a37d-b94fd7a2319f/cas-array-and-autodiscover-for-internal-and-external-access?forum=exchange2010
    “The only place the clients will ever use the CAS Array name is when the value of RPCClientAccessServer on their database is looked up and returned to them so they can then resolve the name via DNS and connect through MAPI. This is why the CAS Array
    name is not required to be on a SSL cert unless an admin chose to use the same FQDN for OWA/EAS/EWS/etc...., which would not be recommened for the reason Mitch points out above.”
    Thanks
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Allen Wang
    TechNet Community Support

  • Server Name in Certificate

    Hi!
    We renewed our Exchange 2010 SSL Certificate from Godaddy and followed the document provided by Godaddy to change the internal names of our Exchange Server URLs to external names but we are still getting error about the internal server name mismatch
    when our users open outlook internally. Can we have the correct and complete procedure to change Exchange Server settings for this purpose?
    Thanks.

    Use the resolution section as a guide and ensure all URLs and autodiscoverURIs are set correctly:
    https://support.microsoft.com/en-us/kb/940726
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Internal server error - Http server and OC4J intance

    Hi
    Internal Server error ( GET/&lt;app name&gt;
    Hi,
    We are using AS10g R1: 9.0.4.0.0 in production and occasionally getting Internal Server Error. And to overcome this problem, everytime we have to restart the HTTP server; we tried re-staring the OC4J instance to find out whether OC4j is causing the problem, however it doesn't work until we restart the Http server. Interestingly Http server serves well other OC4j instances during the error for a particular app runing in different OC4J instance.
    ANY HELP WILL BE HIGHLY APPRECIATED.
    Here are more details:
    It's a J2ee (struts) app.
    Operating System: Sun Solaris- 5.10
    Http server access log msg:
    "GET /&lt;app name&gt; HTTP/1.1" 500 544
    Http server error log msg:
    MOD_OC4J_0184: Failed to find an oc4j process for destination: OC4J_1
    [Mon Sep  8 17:55:13 2008|http://forums.oracle.com/forums/] error MOD_OC4J_0145: There is no oc4j process (for destination: OC4J_1) available to service request.
    [Mon Sep  8 17:55:13 2008|http://forums.oracle.com/forums/] error [ecid: 51865290138,1|http://forums.oracle.com/forums/] MOD_OC4J_0119: Failed to get an oc4j process for destination: OC4J_1
    [Mon Sep  8 17:55:13 2008|http://forums.oracle.com/forums/] error [ecid: 51865290138,1|http://forums.oracle.com/forums/] MOD_OC4J_0013: Failed to call destination: OC4J_1's service() to service the request.
    [Mon Sep  8 17:55:15 2008|http://forums.oracle.com/forums/] warn [ecid: 51865292545,1|http://forums.oracle.com/forums/] MOD_OC4J_0184: Failed to find an oc4j process for destination: OC4J_1
    OC4J Log:
    Nothing unusual; looks good
    Mod_oc4j.conf
    LoadModule oc4j_module libexec/mod_oc4j.so
    Oc4jConnTimeout 300
    Oc4jCacheSize 0
    # in response to eSecure findings
    RewriteEngine on
    RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
    RewriteRule .* - [F]
    Work around:
    Re-starting HTTP server

    Greetings,
    Since we see a 500 error below in the Http server access log msg: the server is unavailable. I suggest changing the OC4J logging to "FINEST" and then run your test again (server reset etc.) and post the log here.
    THX
    -Mike

Maybe you are looking for