Re: SMTP and IMAP SSL Certificates

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Most likely the CA you installed is not an Enterprise CA (gets published in
AD).

Add the CA as a trusted CA on the client side. Can be done from AD as well.

This may help:
http://support.microsoft.com/default.aspx?scid=kb;en-us;q313197&sd=tech
--
Bharat Suneja
MVP - Exchange
www.zenprise.com
NEW blog location:
www.exchangepedia.com/blog
----------------------------------------------


"omgitsmit" <OMGITSmit@xxxxxxxxx> wrote in message
news:1155827881.783378.139320@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I created a SSL certificate locally with a local CA on the domain
controller. I applied this certificate to my IMAP and SMTP virtual
servers in Exchange 2003, which is also located on the very same
server.

Whenever my clients or i connect to check our mail, i get a "Internet
Security Warning" window that states "The server you are connected to
is using a security certificate that could not be verified. A
certificate chain processed, but terminated in a root certificate which
is not trusted by the trust provider. Do you want to continue using
this server?"

In order to initiate the SSL connection for email, you would have to
accept this message every time you open up Outlook 2003.

Is there anyway to get the CA server to trust this certificate? It
sounds like it's the client side that doesn't trust the certificate,
now that i really think about it.

Any help would be greatly appreciated!



.



Relevant Pages

  • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle
    ... SSL only validates you are talking to a SSL certified server; ... They can simply edit the URL the client program ... can be done by using a X.509 certificate on both ends, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: LDP client authentication fails
    ... I got the LDP working with LDAP server under server client authentication ... I did not installed the certificate in pfx format .. ... Client cert auth won't work without that. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SSL & Man In the Middle Attack
    ... >> it possible for the middle man to intercept all messages from server to me ... > server sends client a signed message along with a digital certificate. ... > client generates a random secret key, ...
    (comp.security.misc)
  • Re: activesync issue
    ... On the SBS 2003 Server open the Server Management console. ... On the "Web Server Certificate" page, choose to create a new Web server ... Install the new certificate which created in above step on mobile device: ... Access to browse the Exchange Server 2003 client after you install ...
    (microsoft.public.windows.server.sbs)
  • [Full-disclosure] VMSA-2006-0010 - SSL sessions not authenticated by VC Clients
    ... X.509 certificate when creating an SSL session, ... Both the client and server need certificates from a mutually-trusted ... VirtualCenter 2.0.1 Patch 1 and VirtualCenter 1.4.1 Patch ...
    (Full-Disclosure)