Exchange 2013 - The name of the security certificate is invalid or does not match the name of the site

Hi,

I know this question has been asked a ton of times, but I haven't found any instance of this question asked for exchange 2013.  Yes, I've seen Exchange 2010, Exchange 2007, but not Exchange 2013.  The symptoms are all similar.  Here is a description:

1 Exchange 2013 server, all roles installed.

External domain name:  associates.com

Internal AD domain name:  associates.local

Client installed a third party SSL certificate, but did not purchase a SAN or UC certificate, so there is one namespace on the SSL cert, and that represents the external OWA name:  mail.associates.com

Now, when internal OUtlook 2010 clients start, they get the "The name of the security certificate is invalid or does not match the name of the site."

I'm just wondering if http://support.microsoft.com/kb/940726 still applies to Exchange 2013 to fix this issue.  Does this article apply to Exchange 2013?  If so, I will follow the above article.  If not, please direct me to any articles for Exchange 2013 that addresses this.

the autodiscoverserviceuri points to:  https://netbiosnameofmailserver.associates.local/Autodiscover/Autodiscover.xml

Thanks!

A

February 10th, 2013 4:51pm

All virtual directories should be set to mail.associates.com.
Free Windows Admin Tool Kit Click here and download it now
February 11th, 2013 12:56am

Hi,

I've got the same question.

Did you fix it? and how?

thanks

June 21st, 2013 9:30pm

Make sure that the hostnames in all URLs are contained in the certificate.
Free Windows Admin Tool Kit Click here and download it now
June 25th, 2013 1:52am

thanks, but i don't understand what you mean.

can you give me an example?

also getting this error:

there is a problem with the proxy server's security certificate..... error code 10.

my certificate works without problems on Exchange 2007 and 2010.

thanks again

June 27th, 2013 7:44pm

What is the CN of the certificate and what SANs are in it?  What is the URL you are using to reach the server?  Is the hostname in the URL the CN or one of the SANs?

Free Windows Admin Tool Kit Click here and download it now
July 12th, 2013 1:29am

Yes, the http://support.microsoft.com/kb/940726 still applies to Exchange2013.

As per my understanding on this post;

- Poster's Exchange2013 has no SAN certificate.. (usually used for local address like; NETBIOS.Domain.lan).  Be reminded that SSL providers will no longer accepts .LAN or .LOCAL in very near future.

- By default it uses local url for EWS, Autodiscover, etc.. (if you don't have SAN certificate installed in your CAS server, you would see the certi warning)

Anyway, I just want to share my case after applying the said work around long time ago (maybe some of you might encounter it as well): my Outlook still showed the certificate warning (I was just keep clicking the YES button).. I was wondering that time what was wrong with my virtual directory settings.. until I decided to click "NO" for an answer to that certificate warning message, then voila! it didn't bug me anymore.  Oh by the way, the certificate warning usually give you a hint what triggers it like; "autodiscover.Domain.lan" on the first line of message, but in my case it just "NETBIOS.Domain.lan" (didn't make any sense, did it?).. Well, unfortunately I didn't have the chance to figure out what triggered that event.. 

July 15th, 2013 1:58pm

http://technet.microsoft.com/en-US/exdeploy2013/Checklist?state=2419-W-EgBEAgIAQAAAAUEHAQAAAAg~

Just in case someone else comes across this with similar issues, I had forgotten to run the EMS command to set the autodiscover URL on one server to match the certificate.

Free Windows Admin Tool Kit Click here and download it now
May 13th, 2014 2:10am

thanks, but i don't understand what you mean.

can you give me an example?

also getting this error:

there is a problem with the proxy server's security certificate..... error code 10.

my certificate works without problems on Exchange 2007 and 2010.

thanks again

If you are using MIcrosoft CA.  Follow this article to request for certificate with custom SAN 

https://technet.microsoft.com/en-us/library/ff625722(v=ws.10).aspx

June 5th, 2015 1:58am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics