Only connect to proxy servers that have this principal name in their certificate issue
Hello everyone, I am having problems with our external users using RPC that are running MS Office 2007. When their machines are configured with RPC for the first time, they are able to connect without an issue. After the are using Outlook over RPC, their connection settings change and the box is checked where it states: "Only connect to proxy servers that have this principal name in their certificate." and it enters this address : msstd:"servername.domain.net" and Outlook will continuously keep asking the user for their credentials until this address is removed from the RPC connection settings. I have looked at other forums and so far this one is the closest one I have found that is related to the same issue I am having with external users using RPC (http://social.technet.microsoft.com/Forums/en-US/exchangesvrgeneral/thread/ffea8c99-f206-49f9-98e9-122efcf828f0/) It seems this is only happening on client machines that are running MS Office 2007, because the machines that are running MS Office 2003 do not have an issue connecting through RPC. Any help would be appreciated.
April 8th, 2009 1:02am

Hi,Please understand that the certificate principal name mismatch will cause being repeatedly prompted for credentials when attempting to connect to Exchange Server.The certificate principal name which inputted inOutlook UI must bematched the Subjectvalue with the certificate. How to check it:Open IIS, right click Default Web Site, click Properties, in the Directory Security tab, click View Certificate button, in the Details tab, check the value of the Subject.Is it the same as the value in the Outlook UI? If not, please change it on the Outlook UI.Additionally, please run get-outlookprovider -identity EXPR|fl command in EMS, then post it on the forum.ThanksAllen
Free Windows Admin Tool Kit Click here and download it now
April 13th, 2009 7:58am

OK, I checked the principal name on the cert and I changed it on the Outlook UI. I will keep an eye on it to see if it changes and I will post exactly what it changes the address to. Below are the results from thefrom EMS.*************************************************************************[PS] C:\Documents and Settings\administrator.1AMLLC\Desktop>get-outlookprovider-identity EXPR |fl CertPrincipalName :Server :TTL : 1AdminDisplayName :ExchangeVersion: 0.1 (8.0.535.0)Name : EXPRDistinguishedName : CN=EXPR,CN=Outlook,CN=AutoDiscover,CN=Client Access,CN=Firs t Organization,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=1amllc,DC=netIdentity : EXPRGuid : 337eea07-1e15-4788-b7f0-7cd730848d20ObjectCategory : 1amllc.net/Configuration/Schema/ms-Exch-Auto-Discover-ConfigObjectClass : {top, msExchAutoDiscoverConfig}WhenChanged : 5/3/2008 8:28:41 PMWhenCreated : 5/3/2008 8:31:30 PMOriginatingServer : dc02.1amllc.netIsValid : True
May 21st, 2009 10:44pm

I am having the same issue as alex, but when I went into our exchange server to view the certificate, I saw that there was no certificate to view. What is the purpose of the Certificate? Sorry for the dumb question, but I am relatively new to this type of IT work.
Free Windows Admin Tool Kit Click here and download it now
June 5th, 2009 6:09pm

Hi there, I am back. We are still having problems with the security cert. The issue has not gone away. Any more help with this will be great.
June 18th, 2009 6:02pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics