Outlook 2010 Certificate does not match

I have a problem with a new installation of Exchange 2013 on a Windows 2012 Server.  Most of the clients are Outlook 2010.
All the internal users are getting the error message:
"There is a problem with the proxy server's certificate. The name on the security certificate is invalid or does not match the name of the target site exchange2013.myinternaldomain.local
This is shortly followed by another box "the name on the security certificate is invalid or does not match the name of the site"
Of course the issue is my purchased SSL certificate is MAIL.REALDOMAIN.ORG  while the server's name is exchange2013.myinternaldomain.local
With Exchange 2010 servers I have deployed I have had success following KB article 940726 but this time it didn't fix it with Exchange 2013.
There must be a solution!
I found this article:
http://support.microsoft.com/kb/2783881   the first suggestion from MS were impractical and the registry edit didn't work either (plus the thought of going to all my clients to do a registry
fix doesn't make me happy!)
I tried creating a local DNS zone for my external domain name and pointing to the internal IP but that didn't fix it.
In the ECP under the Outlook Anywhere section --  "*Specify the internal host name such as contoso.com that users will use to connect
to your organization:"  I changed the internal host name to the external .org address but this caused Outlook clients internally not to work.
I used the -AutodiscoverServiceInternalUrl command to point it to the .org address on the certificate but didn't work either.
I have a service record in both external and internal DNS pointing to the mail.realdomain.org address.
Any other suggestions?
Thanks in advance!
Mike

Thanks for the information. I actually finally got this resolved a few weeks ago by speaking directly with a Microsoft technician. I am going to post what finally fixed my problem with the hopes that it will help others in my position.
Again, the problem which I am sure is common is a .local domain internally and a "real" domain on the outside.  The solution that the MS tech had me do was to simply point EVERYTHING both internally and externally to the external host name - the one that
matched the certificate I had.
I'm surprised this solution isn't found elsewhere - it seems so obvious. 
He had me run an number of commandlets which I will post here - with the caveat that they were for my environment! (I've masked my real domain name and substituted - mydomainame.org)
Set-Webservicesvirtualdirectory -Identity "EXCHANGE2013\ews (Default Web Site)" -InternalURl
https://mail.mydomainname.org/ews/exchange.asmx
Set-OutlookProvider EXCH -CertPrincipalName msstd:mail.mydomainname.org
Set-OutlookProvider EXPR -CertPrincipalName msstd:mail.mydomainname.org
Set-OutlookAnywhere -Identity "EXCHANGE2013\Rpc (Default Web Site)" -InternalHostName "mail.mydomainname.org" -InternalClientsRequireSsl $True -InternalClientAuthenticationMethod NTLM
Set-Webservicesvirtualdirectory -Identity "EXCHANGE2013\ews (Default Web Site)" -InternalURl
https://mail.mydomainname.org/ews/exchange.asmx
Set-OutlookAnywhere -Identity "EXCHANGE2013\Rpc (Default Web Site)" -ExternalHostName "mail.mydomainname.org" -ExternalClientsRequireSsl $True -InternalClientAuthenticationMethod NTLM  --ExternalClientAuthenticationMethod NTLM -IISAuthenticationMethods 
Basic, NTLM, Negotiate
Set-OutlookProvider EXCH -CertPrincipalName msstd:mail.mydomainname.org
Set-OutlookProvider EXPR -CertPrincipalName msstd:mail.mydomainname.org
Set-OutlookAnywhere -Identity "EXCHANGE2013\Rpc (Default Web Site)" -InternalHostName "mail.mydomainname.org" -InternalClientsRequireSsl $True -InternalClientAuthenticationMethod NTLM
The last thing we did was ADD in DNS on the internal DNS server the mail.mydomainname.org and point it my Exchange Server private IP (192.168.1.2)  If you do the whole host name and not just mydomainame.org it wont mess up access to say an external
website.
hope this helps!

Similar Messages

  • Cannot open install assistant.  I get this error message: The application cannot be installed due to a certificate problem.  The certificate does not match the installed application certificate, does not support application upgrades, or is invalid.  Pleas

    How can I downloade a trial of Adobe Elements 12? 
    I followed the instructions to download assistant...but get this message: The application cannot be installed due to a certificate problem.  The certificate does not match the installed application certificate, does not support application upgrades, or is invalid.  Please contact the application author.

    Hi alposer,
    Please remove the copy of the Adobe Download Assistant you currently have installed and then reinstall the Adobe Download Assistant.
    Regards,
    Rave

  • The application cannot be installed due to a certificate problem.  The certificate does not match

    the application cannot be installed due to a certificate problem.  The certificate does not match the installed application certificate, does not support application upgrades, or is invalid.  Please contact the application author.
    i DONT HAVE THE DISK FOR aDOBE 6.0 ANYMORE HOW DO i UPGRADE??

    You cannot in any case buy an upgrade from Acrobat 6, it is too old. So it's a full price purchase I'm afraid.

  • Certificate does not match a unique certificate on this host for the issuer

    Hey everyone!
    I've been working with a strange issue on my persistent chat pool. I added a pool to my current deployment, all of which went without issue, until I tried to connect to one of my chat rooms, where I was met with the infamous "Your chat room access may
    be limited due to an outage". The logs were filled with the following error
    "The persistent chat server can not establish or maintain MTLS connection to the Lync Server
    Reason String: RemoteDisconnected"
    When I went to renew the internal cert, I get the message:
    WARNING: "4f000000139c71d470b9a56af1000000000013" does not match a unique certificate on this host for issuer "CN=hosting-EXAD2-CA-1, DC=hosting, DC=email".The following certificate was assigned for the type "Default":Default:
    E1864894FD306300A16F301AA21446CF45F7ABD3 EXPCPOOL.hosting.email 02/16/2017 CN=hosting-EXAD2-CA-1, DC=hosting, DC=email 4F000000161F1E51F1F5EB8C57000000000016ImageWARNING: "Set-CSCertificate" processing has completed with warnings. "1" warnings
    were recorded during this run.ImageWARNING: Detailed results can be found at "C:\Users\administrator.HOSTING\AppData\Local\Temp\1\Set-CSCertificate-[2015_02_17][08_29_57].html".
    Any thoughts on this?

    Hi,
    Check this old thread
    https://social.technet.microsoft.com/forums/lync/en-US/3d569519-8a43-4cd2-b322-718ee575e140/lync-frontend-certificates-vanish
    https://guybachar.wordpress.com/2014/04/16/certificate-requirements-for-lync-2013-enterprise-persistent-chat-server/
    Whenever you see a helpful reply, click on Vote As Helpful & click on Mark As Answer if a post answers your question.

  • HTTPS - certificate does not match the name of the site

    Hi all.
    We created an http destination to an external server in sm59. We are going to use SSL, certificate has been imported in strust.
    Our https settings are correct (we already use https in antother scenario), but there seams to be something wrong with the certificate of the http destination.
    When I use the windows-console on our XI server and try to open the URL of the http destination with Internet Explorer, Windows tells me that "The name on the security certificate ... does not match the name of the site".
    Is there a way to tell the server to ignore this security warning or is it necessary to create a new (correct) certificate?
    Any help is appreciated.
    Best regards,
    Philipp

    Philipp,
    Don't know much about this topic, but my guess would be that will have to create a new certificate with the appropriate credentials.

  • When trying to set up syn with outlook 2010 - it does not show as an option

    When trying to set up syn with outlook 2010 - outlook it does not show as an option

    Hi smrkevin,
    Welcome to the BlackBerry Support Community.
    What version of BlackBerry Desktop Software do you have installed? If you do not have the latest version listed here: http://bbry.lv/ds97JW I would advise upgrading it.
    If you already have the latest version of Desktop Software, can you verify if you are running a Click to Run installation of Outlook? You can check this in Outlook -> Help -> About Microsoft Outlook. If you are using a Click to Run installation, you will need to install a full version of Microsoft Outlook to setup synchronization. For more information, see: http://bbry.lv/qDIoXO
    Hope this helps.
    -FS
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.
    Click Solution? for posts that have solved your issue(s)!

  • IPhone4 MS Outlook 2010 Sync - DOES NOT WORK

    Syncing between MS Outlook and iPhone4 Contacts and Calendars does not work. Is there a fix for this? Music and videos sync, but anything related to MS Outlook 2010 does not.
    Help! Any fixes or suggestions. I want to keep my iPhone4 and not toss it.
    Computer OS: Windows 7 64 bit, MS Office 2010 Ver: 14.0.5128.5000 (32-bit. iPhone4 Version: 4.3.1 (8G4).

    My life and contacts are in the hands of MS Outlook 2010. I need to get a new smart phone that will sync with Outlook. I was shocked to see that Windows Phones running Windows Mobile 7 and having the latest version of MS Office Mobile WILL NOT sync contacts with MS Office Outlook 2010 running on one's PC. There is a very limited work around using a Hotmail account, but it will only work with a relatively small number of contacts (I have 3,500!).
    To what extent does the iPhone 4 sync using the procedure you outlined above? Does it sync 100% of all info in your MS Outlook contacts? For example, does it sync "Categories" and "Groups" information? Also, does the sync work both ways? I.e, does a new or updated contact in one device update the other, regardless of whether the change was originally entered into the iPhone 4 or the computer on which one has MS Outlook 2010?
    Thanks
    Chip
    MS Office 2010 Professional running on HP computer with Windows 7 64 bit and 8 MB of RAM.

  • OUTLOOK 2010. Does not reply to emails using the same address that received it.

    Hello,
    Since last week our Outlook accounts are not working properly, when users reply a message it does not reply using the same address that received it, it appears the personal account instead.
    We are using exchange accounts, using Outlook 2010  and the accounts affected are automapped to a principal account (.ost).
    We already tried to recreate outlook .ost profile, repair Outlook installation, reinstall Office.
    Can somebody help?
    Thanks in advance.

    Hi,
    We have received many reports as your description since last week. It sounds like the sending behavior in Outlook 2010 has been changed by some Windows/Office update and goes back to the behavior before.
    Before we go any further, I have to mention some of the history for Outlook 2010. In Outlook 2010 without SP1, Mailto’s will use the default/principal account for message when you use Microsoft Outlook 2010 which has multiple accounts delivered to different
    data file. However, in later version (Outlook 2010 SP1/SP2), Outlook doesn’t use the default account set in Account settings for new messages. Instead, it uses the account associated with the mailbox or *.pst file you have in focus.
    Actually, this behavior is controlled by the registry keys. At this point, I suggest we check the following registry entries are exist and set it to the proper value.
    HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Options\Mail
    DWORD value: NewItemsUseDefaultSendingAccount
    Value type: REG_DWORD: 1 for force, 0 to disable.
    HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\14.0\outlook\options
    Value Name: ForceAccountSelection
    Value type: REG_DWORD: 1 for force, 0 to disable.
    Close the registry editor and restart Outlook to check if the behavior what you want would come back.
    In addition, our Outlook MVP, Diane Poremsky has written an article with more detail information:
    http://www.slipstick.com/outlook/outlook-2010/multiple-accounts-and-the-default-account/
    By the way, we still cannot figure out which update is the root of the issue, if someone could test it and share the result here, I would appreciate that. Feel free to post back.
    Tony Chen
    TechNet Community Support

  • Outlook 2010 autoarchive does not delete items from server

    I have read similar Qs & As, but I don't think they apply to my circumstances.
    I use Outlook 2010 with Windows 7 32 bit for a GMAIL IMAP account.
    My email pst file is 7GB in size and I think this is affecting performance. I'd like to auto-archive all emails more than 15 months old to a separate pst file, and to do this every 14 days. I've set up
    1) file/clean-up/archive all folders according to their auto-archive settings/OK
    2) Options/advanced/auto-archive
    run every 14 days
    delete expired items
    archive or delete old items
    move old items to c:\... my archive folder.
    The auto-archive fires up automatically at the right time (I've been testing using a 1 day interval), but despite all this, it still doesn't delete emails from the IMAP (Gmail) folders, and I have emails going back to 2010.
    How do I get this to work please? I don't want my IMAP folder to increase in size for ever - is there a practical limit?
    Simon Brew

    What are your gmail settings? Gmail will archive messages that Outlook deletes from the server unless you change the setting and tell gmail to delete them. (It's under Forwarding and POP on the settings page at gmail.com.)
    You can configure gmail to only provide the most recent 1,000, 2000, 5,000 or 10,000 messages - leaving the older messages archived in the gmail mailbox. 
    Do you have the Gmail \ All Mail folder subscribed? That duplicates all of your mail - unsubscribe it to reduce the file size. 
    Diane Poremsky [MVP - Outlook]
    Outlook & Exchange Solutions Center
    Outlook Tips
    Subscribe to Exchange Messaging Outlook weekly newsletter

  • MSExchangeTransport 12014 3rd Party SSL Certificate does not match internal domain name.

    I have a co-existance of Exchange 2003 and Exchange 2010 and after installing a new 3rd party cert I'm getting The following error.   All mail is flowing and OWA is working. 
    Microsoft Exchange could not find a certificate that contains the domain name Exchange.domain.local in the personal store on the local computer. Therefore, it is unable to support the STARTTLS SMTP verb for the connector Default EXCHANGE with a FQDN parameter
    of Exchange.domain.local. If the connector's FQDN is not specified, the computer's FQDN is used. Verify the connector configuration and the installed certificates to make sure that there is a certificate with a domain name for that FQDN. If this certificate
    exists, run Enable-ExchangeCertificate -Services SMTP to make sure that the Microsoft Exchange Transport service has access to the certificate key.
    Our GoDaddy UC SAN cert is not allowed to have .local SAN names, so I have no way of adding it to the cert.   Is it possible for me to install a local CA and generate a self signed cert for the personal store or would it be better to disable
    TLS for the receive connector?  

    Change the name on the Receive Connector (2010) or on the SMTP Virtual Server (2003) to match the name in the new certificate. One of them is sending the "exchange.domain.local" in the 220 banner when it accepts a connection.
    --- Rich Matheisen MCSE&I, Exchange MVP

  • Windows 7 x64 - outlook 2010 - search does not work

    Hi,
    I have a sbs 2011 essentials, and 5 workstations win 7 pro 64 bits.
    On one of these Workstation (and not the others), searching for a text in mails in Outlook doesn't work. System tells indexing is in progress. No text can be found (even the sender of a mail displayed on the screen).
    Antivirus is MS Security Essentials. The mailbox is not very big.
    No Windows live account, mails are stored on the LAN (sbs server).
    => Indexing status: shows everything is indexed (0 remaining).
    => delete/rebuild index then reboot: no change.
    => tried chkdsk /f: no change (and no error found)
    => deleted temp files. No change.
    => checked indexed contents. Outlook, office Note, and a few (small folders). Appdata is excluded from c:\users.
    => Tried when disabling Security Essentials Real-Time protection, no change.
    It seems that either text indexing blocks / freezes on a file (perhaps the last one, perhaps due to something else like Antivirus), either doesn't tell Outlook/Windows that indexing is finished.
    Is there any way to see where this indexing tool stops? To force it to continue, ...?
    Regards,
    Alain
    Alain Bourgeois

    Hi,
    Regarding the issue here, Please first take an attempt to repair your Outlook personal folder file (.pst) :
    How to repair your Outlook personal folder file (.pst)
    We might also take a try to reinstall the Windows Search feature:
    If your installation of Windows Search got damaged, we can remove and reinstall it in the following way.
    Control Panel-> Programs-> Turn Windows features on or off
    Deselect: Windows Search
    Press OK and wait until the installer is finished.
    Reboot your computer.
    Repeat the above steps to enable it again.
    If still have troubles with outlook search, we may need to take a look in the Event Viewer and look for any errors logged by the “Search” or “Microsoft Outlook”, And if they are not helpful to you, please post them back in together
    and we will help you troubleshoot it.
    In addition, we might consider seek help in the forum below regarding outlook issues:
    Outlook IT pro discussions
    http://social.technet.microsoft.com/Forums/office/en-US/home?forum=outlook
    Hope this may help
    Best regards
    Michael Shao
    TechNet Community Support

  • When i try to install story desktop i get this message: The application cannot be installed due to a certificate problem.  The certificate does not match the installed application certificate, does not support application upgrades, or is invalid.  Please

    can anyone help

    Please follow these steps:
    - Remove the currently installed Adobe Story app from your system
      - If you are using windows, you can do it through control panel
      - If you are using Mac, open the Applications folder and move 'Adobe Story' application to Trash. (Please remove it from trash too)
           ( Please make sure that no other installation of Adobe Story is present in your system by searching 'Adobe Story' in Spotlight. Remove if present. )
    - Then install the latest version by downloading the installer file directly from: http://story.adobe.com/AIR/AdobeStory.air

  • The application cannot be installed due to a certificate problem.  The certificate does not match the installed application certificate, does not support application upgrades, or is invalid.  Please contact the application author.

    Has anybody seen this in Mac OS 10.10?

    Ok, just Acrobat XI Pro? Nothing else? (I've seen talk of this message, but for different Adobe products).
    And was Acrobat XI Pro ever installed before?

  • Exchange 2013 w/Outlook 2013 "The name of the security certificate is invalid or does not match the name of the site"

    I've completed an upgrade from Exchange 2003 to Exchange 2013 and I have one last SSL message that I can't get rid of.  I've installed a 3rd party cert that is working great for webmail and cell phone access but for some reason the Outlook 2010/2013
    clients get prompted for a security warning.  I just implemented the SSL cert yesterday and I've noticed that new installs of Outlook seem to work just fine.  My Outlook 2013 client doesn't prompt me with the message but I have other users who are
    still getting the "The name of the security certificate is invalid or does not match the name of the site" error.  The domain on the cert error show up as server.mydomain.local.  I've gone through all the virtual directories and pointed
    all of my internal and external URL's to https://mail.mydomain.com.   This made one of the two warnings go away but not the second.  I've dug around on google and gone through everything I could find here and as far as I can tell my internal
    and external url's are configured properly and I can't figure out where this error is originating from.  Any ideas on where I should look outside of the virtual directories? 
    I'm including a good link I found that contains all of the virtual directories I updated.  I've checked them through both CLI and GUI and everything looks good.
    http://www.mustbegeek.com/configure-external-and-internal-url-in-exchange-2013/
    http://jaworskiblog.com/2013/04/13/setting-internal-and-external-urls-in-exchange-2013/

    Hi,
    When the Outlook connect to Exchange 2013/Exchange 2010, the client would connect to Autodiscover service to retrieve Exchange service automatically from server side. This feature is not available in Exchange 2003 Outlook profile.
    Generally, when mailbox is moved to Exchange 2013, the Outlook would connect to server to automatically update these information. It needs time to detect and update the changes in server side. I suggest we can do the following setting For autodiscover service:
    Get-ClientAccessServer | Set-ClientAccessServer –AutodiscoverServiceInternalUri https://mail.mydomain.com/autodiscover/autodiscover.xml
    Please restart IIS service by running IISReset in a Command Prompt window after all configuraions.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Exchange 2010 - The name on the security certificate is invalid or does not match the name of the site

    Scenario - Two Domains in different forests in production
    Domain ABC.com - Contains Exchange Server 2010 + Windows 2008 R2 AD Domain controllers
    Domain XYZ.com - Windows 2008 R2 Domain controllers + Contains all users + Desktop compuer accounts.
    User logs in to the domain XYZ.com from a desktop and he configures outlook using the user ID in  domain ABC.com.
    When he opens Outlook it is getting connected and he gets an error message pop -up saying 'The name on the security 
    certificate is invalid or does not match the name of the site'
    I am using an external certificate from Thawte for autodiscover.ABC.com & webmail.ABC.com
    I read about one solution provided in MS KB article - http://support.microsoft.com/kb/2772058 
    But in my scenarion there are two domain involved. Pls guide how to clear this.
     

    Hi,
    How about logon [email protected] on ABC domain via OWA?
    If OWA works well, it seems and issue on the Autodiscover side.
    Please run "Test E-mail AutoConfiguration" on Outlook to check whether this issue caused by Certificate Mismatch.
    1.
    Firstly make sure how many host name in your certificate the certificate. Run “Get-ExchangeCertificate | select certificatedomain”.
    2.
    Secondly, check the web services URLs which Outlook are trying to connect to. Run “Test Email AutoConfiguration”.
    3.
    In this scenario, you need to check the host name for the following services:
    Autodiscover, EWS, OAB, ECP, UM
    4.
    If any of the urls above does not match the one in the certificate, refer to the following article to change it via EMS:
    http://support.microsoft.com/kb/940726 
    More details to see following FAQ on "Checklist for Exchange Certificate issues":
    http://social.technet.microsoft.com/Forums/en-US/fa78799b-5c55-4c71-973b-0e186612ff6f/checklist-for-exchange-certificate-issues?forum=exchangesvrgeneral
    Thanks
    Mavis Huang
    TechNet Community Support

Maybe you are looking for

  • Bug in SQL Developer relating to handling of XMLTYPE columns

    Hi, I have found a bug in SQL Developer relating to its handling of XMLTYPE columns. Given a table with the following data: ID, XML_DATA 1, <xml here> 2, <xml here> 3, <xml here> And the following SQL to extract a value from the XML and also an XML f

  • 8.1.7- How to load an LDIF file

    hai, I understand that there's bulkload.sh to load LDIF file. But I think this is for unix. How can I load LDIF file in Windows? thanks in advance, Evan

  • Where to find or check DSN3@ATH and DSN3@SGN?

    I have an auditor asking me questions about SDNSEXIT and whether it has been modified. They want me to prove that DSN3@ATH and DSN3@SGN have not changed. I have no idea even how to figure this out. I tried looking on the IBM site and they talk about

  • JTREE with CheckBox Option

    Hi All, Can somebody help in how to add a CheckBox in JTREE node concept. Please let me if sites are there for the same. Rgds Sudhama

  • Error Msg - reload software 552

    Hi everyone, Can someone help me pls I downloaded the Blackberry Protect, it asked me to reboot. I did and it came back with RELOAD SOFTWARE 552. Its not coming on apart from that message.  I have tried taking out and putting back both the battery an