SBS 11 - Exchange 2010 and SSL certificates - Event ID 12014

I've recently upgraded my Exchange '10 to SP3 on our SBS11 server and I've noticed an event ID 12014:
Microsoft Exchange could not find a certificate that contains the domain name
mail.mydomain.com in the personal store on the local computer. Therefore, it is unable to support the STARTTLS SMTP verb for the connector Windows SBS Internet Send
SERVERNAME with a FQDN parameter of mail.mydomain.com. If the connector's FQDN is not specified, the computer's FQDN is used. Verify the connector configuration and the installed certificates to make sure that there is a certificate
with a domain name for that FQDN. If this certificate exists, run Enable-ExchangeCertificate -Services SMTP to make sure that the Microsoft Exchange Transport service has access to the certificate key.
I currently have a third-party cert installed on this server with SMTP, POP, IMAP, and IIS services attached to it. The cert is for
remote.mydomain.com
I do not have a cert installed (self-signed or otherwise) for mail.mydomain.com
My send connector HELO/ELHO is mail.mydomain.com
My receive connector  HELO/ELHO is SERVERNAME.mydomain.local
My MX record at NS is pointing to mail.mydomain.com
My question is should I change both my send and receive connectors to
remote.mydomain.com?
Would I then change my MX record with NS to point to
remote.mydomain.com? Any potential errors with doing this?
Should I buy another third-party cert for mail.mydomain.com and install that cert for mail services? (Although it seems SBS hates using more than one third-party cert).
What's my best option here and what is best practice?
Thanks in advance!

I'm using SBS 2008 but it should be the same
Send Connector
Send -> remote.xxxxxx.com
Receive Connector
Default SBServer -> SBServer.xxxxx.local
Windows SBS Internet Receive SBSERVER -> remote.xxxxxxx.com
Windows SBS Fax Sharepoint Receive SBSERVER - > SBSERVER.xxxxx.Local
Network Solutions
  A Record
     remote.xxxxxxxxxxxxxxxxx.com  Points to   SBS server ip address
  MX Record
     Points to remote.xxxxxxxxxxxxxxxxx.com

Similar Messages

  • Mail, Exchange 2010, and certificates

    Hi.
    The company I work for just upgraded their Exchange server to 2010 and all of a sudden my email account in Mail doesn't work anymore. In sheer desperation I tried to connect using Microsoft Outlook and the only way that I could create an account there was by submitting my certificate before entering my email account credentials. I get the feeling that this might be a kind of setting on the server side that someone turned on when we were transferred to Exchange 2010.
    In Mail, when I try to set up my Exchange account there is no way of submitting my certificate, or am I missing something? If not, does anyone know a way around this (by associating Mail with my certificate somehow – I don't know...)
    Many thanks in advance!
    /Cristian

    I added back the send connector on the 2010 exchange. everything still works fine since I still have the send connector on the 2003. However...
    I connected through telnet to server2 (the exchange 2010) and was able to mail internally. however I couldn't send mail externally, it gives me a "cannot relay" error when I enter my rcpt to:... command.
    I am guessing that this may be the reason why the queue is not emptying itself through that send connector.
    Anything else I could try to test my "send connector" on the 2010 exchange?

  • Exchange 2010 and iphone calendar sync issues

    Hey,
    I know this question has been asked plenty of times before and just need a straight resolution. We have just migrated our environment to Exchange 2010 and the major issue is that when an event is created in Outlook 2011 it is not always showing up on their iphone and also vis versa. Is their a resolution to this problem so I can implement it in an emergency change. Thank you for all your help!

    Here let me explain the scenario again any user who logs in to exchange from outlook working fine password not expired and he has iphone active sync working no issues , now while all devices are working when he starts his ipad after a week or so when he
    opens his email on ipad it prompts the password on ipad and same time on iPhone , he does not want to enter the password and wants a technical justification , I told the user something to do with Exchange 2010 sp2 and ios 7 ,but that is invalid justification
    . if you have any other valid justification please let me know. or a solution to this issue. user wants to login without any password prompt while the password is saved in device and not expired , is there any feature in Exchange 2010 sp2 that would recognize
    how many days device has not logged it and would force to enter the password.

  • Error synchronizing folder [8004010F-501-8004010F-0] - Exchange 2010 and Outlook 2010, multiple users get dozens of these per day

    15:27:30 Synchronizer Version 14.0.6025
    15:27:30 Synchronizing Mailbox 'abc xyz'
    15:27:30 Error synchronizing folder
    15:27:30
     [8004010F-501-8004010F-0]
    15:27:30
     The client operation failed.
    15:27:30
     Microsoft Exchange Information Store
    15:27:30
     For more information on this failure, click the URL below:
    15:27:30
     http://www.microsoft.com/support/prodredirect/outlook2000_us.asp?err=8004010f-501-8004010f-0
    15:27:30 Done
    kbj

    Hi,
    Please try below steps:
    - Remove all organizational forms libraries (subfolders under EFORMS Registry) if they are not needed, and re-create the Outlook profile of affected users.
    - Alternatively, if the organizational forms libraries are needed, remove the replica from Exchange 2010 and re-add it
    Best Regards!

  • Microsoft Exchange 2010 and Outlook 2013

    My colleagues computer suddenly crashed yesterday and it wouldn't restart without a system restore.
    Now when we try to open up Outlook it says that you must connect to Microsoft Exchange at least once before you can usse your Outlook Data file (.ost)
    Also The PC has lost the trust relationship on the domain
    We have exchange 2010 and the servers OS is Microsoft Windows Small Business Server 2011 and the Client PC is running off of Windows 8.
    Can you please help me resolve this issue?
    kind regards
    Steve Bradshaw
    [email protected]

    It might be possible that the MAPI key (which enables Outlook to synchronize with Exchange) has been deleted due to the System crash. So, in order to establish the connection, you need to Reconnect the OST file to the original MAPI profile and then reconnect
    then MAPI profile to Exchange Server. 
    If the above method fails to resolve the issue, then the best option for you would be to take the help of any professional OST to PST Conversion Software, which will help you to Extract data from your OST file and convert it to PST file which you can import
    back to your Outlook to establish the connection with Exchange Server again.
    You can check this
    presentation for more info.
     

  • Single name space in between Exchange 2010 and 2013

    Hi,
    In my current environment I have 2 Exchange 2010 servers with DAG no CAS NLB. I installed Exchange 2013 with 2 CAS with WNLB and 2 Mailboxes with DAG. The main requirement is to configure Single name space to access in between Exchange 2010 and Exchange
    2013. On Exchange 2010 DAG there is a URL using is owa.domain.com and I also configured in Exchange 2013 all the virtual directories with this name owa.domain.com but having an issue that when I open explorer and use the owa.domain.com URL the user on Exchange
    2013 gets their mailbox but user on Exchange 2010 gets error HTTP 403 blank page.
    I observed that in Exchange Organization settings CAS settings one server OWA, ECP etc shows their internal external URL but the other server unable to open the OWA, ECP URL and give error message that "An IIS directory entry
    couldn't be created. The error message is Access is denied. HResult = -2147024891"
    Please guide how to resolve this issue and use the same name URL in Exchange 2010 and Exchange 2013
    Thanks, 

    Hi,
    See the below brief:
    User will connect to mail.contoso.com as his namespace endpoint. CAS2013 in Site1 will authenticate the user, do a service discovery, and determine that the mailbox version is 2010 and is located within the local AD site. CAS2013 will proxy the
    request to an Exchange 2010 Client Access server which will retrieve the necessary data from the Exchange 2010 Mailbox server
    Go through the full blog for better understanding of the redirection.
    Client Connectivity with Exchange 2013
    Hope you have changed your DNS records to direct connections only to your new Exchange 2013 server. You'll move the host names (for example, mail.contoso.com) users have been using to connect to Outlook Web Access, Autodiscover, and so on, from your
    Exchange 2010 server to your Exchange 2013 server. When an Exchange 2010 user tries to open their mailbox, the Exchange 2013 server will proxy their request and communicate with the Exchange 2010 server on their behalf.
    Configuring DNS includes the following:
    Change the primary host names, such as mail.contoso.com, autodiscover.contoso.com, and owa.contoso.com (if used) to point to the external, publically-accessible, IP address of the Exchange 2013 Client Access server with your public DNS provider.
    Change the primary host names, such as mail.contoso.com (or internal.contoso.com if you're using different internal host names) and owa.contoso.com (if used) to point to the internal machine name of the Exchange 2013 Client Access server on your internal
    DNS servers.
    NOTE- Go through the Exchange Deployemnt Assitant - Configure DNS Records section
    Regards,
    Satyajit
    Please“Vote As Helpful”
    if you find my contribution useful or “MarkAs Answer” if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Exchange 2010 and 2013 coexistence Internal and external URL

    Hi all,
    been reading alot of threads about Outlook anywhere and virtual directories in co-existence exchange 2010 and 2013.
    Still i dont get any smarter.
    Here is scenario:
    Exchange 2010
    Cas1
    Cas2
    Mailbox1
    Mailbox2
    Casarray is Exchange.casarray,com ( internal dns pointed to CAS1 in exchange 2010).Seems like by default both exchange 2013 cas servers are added to the casarray.
    Exchange 2013
    CAS+Mailbox
    Cas+Mailbox
    DNS
    mail.exchange.com pointing to VIP (kemp loadbalancer)
    Autodiscover ( pointed to same vip ,kemp load balancer)
    Outlook anywhere on all servers (2010 and 2013)
    Internal ( pointing to VIP on Kemp)
    External ( pointing to external IP,then it passes firewall that again passes to kemp)
    Problem we are having is when migrating users from Exchange 2010 - 2013.
    Users using Outlook 2010
    restart of outlook and mail  works fine.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Users using Outlook 2013
    Outlook in disconnected status,only fix is to create new profile.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Question is,what should be set for internal and external url (active sync,owa,ews)on 2010 and 2013 servers?
    Where is the config wrong?
    Thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

    Hi Martina,
    did the test as mentioned,even tried both CAS 2013 servers.Flush and registerdns didnt help.
    Still Outlook is Connected to the cas.exchange.as (which again Points to 1 of Exchange 2010 servers),
    Tried repair Outlook profile,no og.Only fix is to setup New account.
    Any more tips?
    thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

  • Can't access Exchange ActiveSync server - SSL certificates not being used

    When I try to set up my email via Exchange ActiveSync to a corporate server, I am unable to connect. I am using the same exact settings as on an iPhone, where I am able to successfully connect.
    Reading the console log in the iPhone configuration utility, the problem appears to be that the iPad is not using the corporate certificates I have installed to enable SSL access to the Exchange server. These certificates are installed in the exact same way they are on my iPhone, where they work correctly.
    Has anyone else had a similar problem accessing Exchange mail using SSL certificates? Any ideas on how to fix this? Or is this a bug in the iPad software?

    IM having the same problem. iPhone works fine on exchange atvwork but iPad with same settings says cannot connect to exchange server. Have you figured anything out yet?
    Tom

  • Exchange 2010 and iOS 7

    I am having multiple problems across multiple devices in Exchange 2010 SP2 and devices that upgraded to iOS 7.  I have reset all the settings and re-added the accounts. Any other solutuons for this issue that apple swears is not a bug in the iOS?

    I am running Exchange 2010 and have iOS7 on my phone, and have not seen any problems. My phone is not managed by configuratior.
    What problems are you having?

  • Exchange 2010 and 2003 Co-Existence Help

    Hi All,
    Hopefully someone out there can help me out.
    As the subject says i have exchange 2010 and 2003 in a co-existence mode. I have configured public folder replications and plan to use the following guide to move the public folders:
    http://careexchange.in/moving-public-folders-from-exchange-2003-to-exchange-2010/
    I was about the use the MoveAllReplicas.ps1 powershell script when I had the idea to dismount the legacy (2003) public folder mail store as a test to ensure the public folders had replicated. I noticed under the 'Queues' of the legacy exchange emails were queuing
    up withing 'Messages awaiting directory lookup'.
    All other mail stores were dismounted, as a test I mounted a database (non public folder), did a force connection and refresh. All the emails disappeared from this list.
    So my questions are:
    1. Why would my exchange 2010 sever still be routing emails via the legacy server?
    2. Why would the legacy exchange require a mailstore to be mounted for mail flow to work coming from the 2010 server?
    Thanks

    Thanks for the feedback.
    The issue I am facing is that the emails I am seeing queued are not related to the public folder replications. Emails for the public folder replications normally have a subject line of: 'Backfill' or 'Folder Content'.
    When all mail stores are dismounted on the legacy server some of the outbound emails sent by users who reside on the primary server (2010) are being sent to the legacy server. I can then see these emails queued and they will not be sent until a remount at
    least one mail store.
    E.g. All mailbox stores are dismounted on the legacy exchagn, John Smith's account is located on primary exchange (2010). John sends an email and I see it stuck in the queue on the legacy server  'Messages
    awaiting directory lookup'. 
    NOTE: This does not happen for all users, It seems to happen at Random.
    I also attempted to fix the issue by creating a new 'Send Connector' with a lower cost and defining the 'Source server as the primary server (2010)
    So the question still remains why are some outbound emails still being sent out via the legacy server even though these users are on the primary exchange?
    With regards to the public folders, I used the following to add the replicas between the legacy and primary exchange:
    .\AddReplicaToPFRecursive.ps1 -TopPublicFolder “\” -ServerToAdd “Exchange2010″
    When i dismount the public folders all the public folders are accisable via the 2010 server so it seems the replications have worked.
    Would the above command not have added the replicas to all the public folders including the system public folders?

  • Exchange 2010 and RMS

    Hello Team,
    We are running Exchange 2010 and RMS with Autonomy app which archives older than 30 day emails.
    Parent company is in Tokyo, all incoming email goes through them and then via a hub transport service delivers email to North America.  For some reason, emails are encrypted and the Archive app cant get to them.
    I just want to find how to proceed further and what to do to exclude emails to North America from it.
    Any suggestions would be appreciated !
    Binu Kumar - MCP, MCITP, MCTS , MBA - IT , Director Aarbin Technology Pvt Ltd - Please remember to mark the replies as answers if they help and unmark them if they provide no help.

    Hi Binu 
    I have written one for Exchange 2013 
    http://exchangequery.com/2014/08/12/steps-to-configure-irms-in-exchange-2013/
    Its the same for Exchange 2010 as well 
    Also you can follow the below article for references
    https://technet.microsoft.com/en-us/library/dd351035%28v=exchg.141%29.aspx?f=255&MSPPError=-2147217396
    http://www.msexchange.org/articles-tutorials/exchange-server-2010/compliance-policies-archiving/rights-management-server-exchange-2010-part5.html
    Remember to mark as helpful if you find my contribution useful or as an answer if it does answer your question.That will encourage me - and others - to take time out to help you Check out my latest blog posts on http://exchangequery.com Thanks Sathish
    (MVP)

  • Primary mailbox (on Exchange 2010) and Personal Archive (on Exchange 2013), possible?

    Current environment is Exchange 2010 SP3 RU5 supporting 4,000 Users. Client estate is Outlook 2010 SP1 going on SP2.
    We're pulling our Archiving solution away from 3rd party and back into Exchange. Implementing a new set of Exchange 2010 Servers (old DAG or in a new Archive DAG) would be easy. But is there Exchange 2013 stepping stone potential?
    Can the Archive DAG / Archive mailboxes be on 2013? i.e. for any given User, leave their primary mailbox on Exchange 2010 and create new Archive mailbox on 2013.
    I want to avoid implementing 2010 Archive Servers and then go 2013 Archive 6 months or a year later.
    This article suggests 'no':
    http://technet.microsoft.com/en-gb/library/dd979800(v=exchg.150).aspx
    "Locating a user’s mailbox and archive on different versions of Exchange Server is not supported."
    I've found little info but the odd statement here / there.
    Is this the latest position? Is it that cut & dry? Anyone tried it? Why won't it work (or will it but it's not supported)?
    Thanks!

    <I had a response from MS>
    Below is a summary of the case for your records:
    Symptom:
    =============
    Is it possible to implement a 2013 environment to host the Archive mailboxes? i.e. for any given User, their primary mailbox is on Exchange 2010 and their Archive
    mailbox is on 2013. 
    Resolution:
    =============
    It’s not supported to have a user’s primary mailbox reside on an older Exchange version than the user’s archive. If the user’s primary mailbox is still on Exchange
    2010, you must move it to Exchange 2013 before or at the same time when you move the archive to Exchange 2013.
    http://technet.microsoft.com/en-us/library/jj651146(v=exchg.150).aspx
    as per the repro in our lab, having the archive mailbox in higher version of exchange would fail with the error above
    <the scenario isn't completely relevant, looks like he's trying to put the Primary on 2013 and not the Archive, no matter, we've established there are problems, question is whether they are looking into this area / to patch, they go on...>
    At this point in time we don’t have a conformation from the product team, if the above would change in the future exchange versions.
    <MS did say on the call that they were not looking at fixing it, naturally this isn't a "never", as per previous statement - they can't commit 100% to the future, but they've provided me the answer - they are not currently looking at resolving/providing
    this as a migration scenario, end.>

  • Mail is Slow between Exchange 2010 and 2013 During Co-Existance Transition

    Hello,
    I recently migrated from a single Exchange 2003 server to a single Exchange 2010 server
    I am now trying to Migrate from Exchange 2010 to Exchange 2013.
    I have a test user on Exchange 2013, and Internet Mail works fine and quickly both inbound and outbound.
    However, when I try and send between a 2010 user to my 2013 user, delivery takes around 10 minutes.
    On the 2013 server I see health check messages, and my 2010 user's message stuck in retry status. The messages eventually clear and the mail is delivered. Any ideas what is causing this delay?
    In terms of connectors I have all the defaults. And I created 1 for internal relays from devices. Which works fine.
    I have two Exchange 2013 servers configured in a DAG, but I don't have a load balance in place as of yet. So only server 1 is being accessed as the CAS.
    Thanks

    Hi,
    According to your description, the mail flow is slow only between Exchange 2010 and Exchange 2013 server. If I misunderstand your meaning, please feel free to let me know.
    If yes, I’d like to confirm if there are multiple NICs on your Exchange servers. And you can refer to the following thread:
    http://social.technet.microsoft.com/Forums/exchange/en-US/66f0629f-21fb-444b-b3f1-99ed8a4f52b2/slow-mail-flow?forum=exchangesvrsecuremessaging
    We have ONLY 1 network adapter, but if we select "All network adapters" instead of Hyper-V, we will get delays.
    Thanks,
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Angela Shi
    TechNet Community Support

  • Exchange 2010, UCC SSL, and the "new" CA/BROWSER Forum not issuing for .local

    I don't know how many people have run into this yet, but the CA/BROSWER Forum, the "standards" authority for SSL issuing, has mandated that CA's can no longer issue a certificate using a FQDN "intranet" name for new or renewal SSL certificates effective
    Nov 1, 2012.  i.e. the Microsoft standard of mydomain.local will no longer be accepted as a SAN on a UCC for Exchange 2010.  I've looked thru the KBs and Social forums, but haven't really found any guidance on how to solve this.  I'm presuming
    that the certs will have to be split and the "external" domain name of server.mydomain.net will just become a single server SSL, and the internal name of server.mydomain.local will become a Self-Signed certificate.  With the increasing prevalence of OA
    and ActiveSync devices, is there any baseline guidance yet on how to make this happen without completely fouling up production servers and killing access to the user community?

    On the same topic, though likely different environment...
    Against recommended deployment, I have a number of clients running all their services on one box.  Windows Server 2008, Active Directoy, DNS, Exchange 2010 ...and so on.  These servers all have .local addresses, which means of course that the SAN
    certificates have .local addresses as one of the SANs.
    I've read alot online about this issue, and am trying to find the most cost effective solution to switch numerous production servers running this configuration.
    The best solution I've come up with so far is...
    1. Virtual AD with new external domain, 2. Migrate Exchange CAS to this domain, 3.  Reconfigure network through the box.
    Obviously these steps will contain alot more details, but this is just the outline atm.  At best, I see me having to take a second box with me to each location to perform these steps, and I can't see it happening without disruption to the work flow
    of employees.
    Thankfully, all of these businesses are relatively smal...under 25 employees.  Still, I'd like to find the smoothest transition solution possible.
    Any suggestions would be greatly appreciated!
    Regards

  • Mail for Exchange and SSL certificate

    I have a little problem with Mail For Exchange and my Nokia N80. I have self-signed certificate for Exchange mailserver and when I am synchronizing e-mails I got always message: "The site has sent an untrusted certificate. Continue anyway ?". I underestand that my certificate isn't verified by any root authority, but if I have synchronization schedule set at 15 minutes it means I have to confirm this message four times when I am not with my mobile one hour. So question is:
    Is possible to import self-signed SSL certificate into Nokia N80 and set it as trusted ? If yes, please describe me how, because I have tried import the certificate as CER (it was opened just as NOTE on Nokia), I tried to convert it via openssl to PEM (the file was not recognized) etc... Thanks for any help in advance.
    Reply With Quote

    Go to your outlook web access website and click on the lock and then view certificate. The details and then you can save it in DER format to your desktop.
    Then go to this site:
    http://www.redelijkheid.com/symcaimport/ and insert through the browse button and then copy the link to your phone.
    Then you should be able to download it
    You can also go to your IIS default site on the exchange server and directory security and export your certificate under edit certificate.
    I have tried everything now. I can download my certificate and the valicert from GoDaddy, but the Nokia phone is still saying "do you trust this certificate" every time the phone syncs.
    Our firm have taken the E-phones away now and went over to windows mobile and all of them worked within 10 minutes without any errors.
    The funny thing is that when you try to call nokia, they wont help you with Mail for Exchange, and it is there program
    I know my GoDaddy certificate works on windows mobile phones, so It must be something with Mail for Exchange.
    Every guy I talked to about symbian phones have told me they always gives problems with SSL. I am a bit **bleep**, but can conclude that Nokia is for the private consumer.
    Best Regards
    Morten @ Denmark
    Message Edited by asp3200 on 02-May-2008 08:37 AM

Maybe you are looking for