Exchange 2010 - Cannot get imap or Outlook Anywhere working for users outside of the organization. Store.exe killing server's performance.
I'm trying to give outside users the ability to use their Exchange account from their remote location using either imap or outlook anywhere. So they can configure both the client's email account and our email account in one profile. Some users are accustomed to Imap. I'd like to just use Outlook Anywhere but would like to have both working. Please help me find what I may be missing in my configuration. IMAP problem: I have IMAP4 enabled and started on the mail server. In EMC, I've set IMAP to use basic authenication. I successfully configure an Outlook profile using IMAP settings. I open the profile and watch all my email copy to my local drive. I send a test message to an outside email account. Outlook tells me the message was successfully sent, however, I do not receive the test message from my IMAP profile. -How can I prevent email from copying to the local computer using IMAP (just a direct connection to the server if possible)? -Why would I not able to sent email from my IMAP profile? No errors in the logs. Tried from 2 different computers on 2 different outside networks. Outlook Anywhere problem: I seem to have this configured correctly. However, the only way I can use it, is if I already have the profile setup. I would like to be able to configure the profile from scratch using Outlook Anywhere. When I've attempted to do so, I get prompted for authentication (as expected), I enter the correct info, and get the error message: "The action cannot be completed. The connection to Microsoft Exchange is unavailable" I have run my server through the testexchangeconnectivity.com site and I do see this error when doing an RPC over HTTP test: The certificate common name *.domain.com doesn't validate against the mutual authentication string that was provided: msstd:webmail.domain.com I'm confused as to why my Outlook Anywhere does work despite this error. Although, I can't configure the profile. Is it because of my wildcard certificate? Store.exe: Sorry to squeeze so much into one thread, but also I have what seems to be a problem with the process store.exe and its memory hungry ways. It's taking 5GB of memory and bogging down the server. Anyway to optimize that? Seems like a little much to me. Total, the memory on the server is always running at around 11GB and I have 12GB allocated to this VM. Do I simply need to bump it up? Thanks for your feedback.
February 21st, 2011 4:13pm

For Outlook Anywhere, if it's only working after you have configured the profile first inside the network it's due to autodiscover. Go back to testexchangeconnectivity.com and run the autodiscover test and post the results. One way that I've circumvented this issue when doing a cross forest migration (shared smtp namespace) and autodiscover support was not working for new forest was to have home users log into OWA first which would then get the client cert downloaded to their client. James Chong MCITP | EA | EMA; MCSE | M+, S+ Security+, Project+, ITIL msexchangetips.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
February 21st, 2011 4:39pm

Exchange and RAM - by design, Exchange will use as much as RAM as is available. You bought the RAM to be used. However if something else wants the RAM, then it should release it. Therefore high RAM use on its own is not a sign of a problem. If you are starting something on the server and the RAM isn't being released, then there is an issue. The most common cause of the problem is AV or antispam software. Thus, if you have allocated 12gb of RAM to the server, do not be surprised if store.exe takes 10-11 gb of it. If you give it more RAM, it will simply use more RAM. Outlook Anywhere in certain configurations will have problems with wildcard certificates. They are not the same as Unified Communications certificates and therefore can cause issues. The MSSTD value must match the certificate exactly. In SSL speak, *.example.com is NOT the same as host.example.com. Therefore you will have to change the value of MSSTD to the wildcard: Set-OutlookProvider expr -CertPrincipalName:"msstd:*.example.com" However personally I would encourage you to switch to a UC certificate which is how Exchange is designed to work. You can get these for less than US$80/year from http://certificatesforexchange.com/ I would encourage your users to ditch IMAP if possible, particularly with Outlook. This will give them the full feature set. I am always suspicious of anyone who wants to use IMAP/POP as it means they may be trying to hide something. It also usually means they end up with "Password Does Not Expire" because they complain about having to change their password in their client/s frequently. For sending, you need to set the client to use authentication, and it needs to be explicit credentials, NOT just enabling the box that says use the same credentials as incoming. SMTP needs it in the format of domain\username. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
February 21st, 2011 4:56pm

In terms of your store.exe taking up all your RAM. that is by design, Exchange 2007/2010 will take as much RAM as it can and release it as other programs need it. That being said, you can take a look at this blog for some information: http://mostlyexchange.blogspot.com/2007/08/restricting-ram-usage-in-exchange-2007.html For your IMAP issue, first the copying to your local machine is by default. The difference is IMAP by default will leave the copy on the server as well, vs. POP that will pull information out of the store unless you specifically tell it not to. For the sending problem, have you tried sending an internal message with the IMAP account? If not I would try that, if it works you probably have an outbound firewall rule blocking IMAP. For the Outlook anywhere problem, the wildcard cert is your problem I believe, it can be tricky to set it up. check out this video and verify your steps against it: http://www.msexchange.org/articles_tutorials/videos/exchange-server-2007/mobility-client-access/video-how-to-configure-outlook-anywhere-work-wildcard-certificate.html Thanks, Jorge R. Diaz, PMP, CCNA, MCSA, MCSE, MCTS Senior Microsoft Consultant Planet Technologies, Inc. Check out My Blog!
Free Windows Admin Tool Kit Click here and download it now
February 21st, 2011 4:58pm

Hi Dlife55, Above gave some good information, any update for your issue? Regards! GavinPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
February 24th, 2011 12:47pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics