I have been spending the past few days attempting to figure this one out. The MAIL server was issuing a certificate through ISA and it wasn't valid outside of the internal network (because the ISA server was named PROXY external to the network). I was able to change the Certificate Authority to issue certificates as PROXY (in an attempt to curb this dilemma). Now, when I attempt to get Exchange Active Sync working I am still getting a certificate error because the ISA is still issuing the original MAIL certificate over OWA. I have imported the new certificate onto the ISA server but it is not showing up in the Listener SSL Certificate window. Does anyone have any suggestions? I've imported into Personal certificates on ISA as well as Trusted Root certificates.
March 3rd, 2008 6:05pm

When you imported the certificates to the ISA server, did you import it to the local computer store or one of the user's stores?
March 3rd, 2008 7:45pm

It has been added to the Local Computer certificates. When I go into the ISA OWA configuration for the listener, the only certificate that shows up is the one that is applied. There was an additional one there before, but I removed it when applying the new certificate.
March 3rd, 2008 9:09pm

I have seen similar behavior before and, sadly, the thing that fixed the problem was to clear the certificates out of the local stores, and then re-create the rules and listeners
March 4th, 2008 5:59am

John, How are you installing the certificate on ISA, thru certreq or via the certificates snap-in? Cheers, Mylo
March 11th, 2008 11:26pm

