Exchange 2013 CU8 broke my ADFS 3.0 / WAP published OWA & ECP internal and external access

Now suppose I want to go back to a plain vanilla OWA internally for test purposes. How do I do that. I have multiple interpretations of the settings required on the virtual directories, but do I have to do something in set-organizationconfig?

June 17th, 2015 4:37am

The SANs are all there:

CertificateDomains : {owa.mydomain.com, www.owa.mydomain.com, autodiscover.mydomain.com, edge.mydomain.com,
                     enterpriseregistration.mydomain.com, mydomain.com, sip.mydomain.com, mail.mydomain.com,
                     fs.mydomain.com, adfs.mydomain.com}

Thumbprint         : 5169E1D598829E6B74315F27F5F7A4543C78DC17

This is the certificate that is bound to the default website.

get-owavirtualdirectory returns

InternalUrl                                         : https://owa.mydomain.com/owa
ExternalUrl                                         : https://owa.mydomain.com/owa

Free Windows Admin Tool Kit Click here and download it now
June 17th, 2015 8:18am

Can someone point me to where to look to get them working again?

I get the ADFS login screen and then "something went wrong"

https://owa.mydomain.com/owa/auth/errorfe.aspx?msg=WrongAudienceUriOrBadSigningCert

somting went wrong

June 17th, 2015 9:26am

How as this deployed? Are all of the support requirements on this page met?

https://technet.microsoft.com/en-us/library/dn635116(v=exchg.150).aspx

Free Windows Admin Tool Kit Click here and download it now
June 17th, 2015 11:19am

It was working until I applied CU8 (it was on CU7)

June 17th, 2015 11:28am

Understood :)  But need to confirm all of the support prerequisites are in place.   Go back through the list step by step and ensure all the items are still present please.
Free Windows Admin Tool Kit Click here and download it now
June 17th, 2015 12:09pm

OK done that and they are all there as far as I can tell...

recycled my app pools, reset IIS, restarted the servers

Still the same. I get to the ADFS login screen but no further.

ActiveSync is working fine (passthrough in WAP)

June 17th, 2015 12:32pm

Now suppose I want to go back to a plain vanilla OWA internally for test purposes. How do I do that. I have multiple interpretations of the settings required on the virtual directories, but do I have to do something in set-organizationconfig?

Free Windows Admin Tool Kit Click here and download it now
June 17th, 2015 1:49pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics