RE: StartTLS problem

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Problem solved. I don't know exacly why this happended. When I reissued the
certificate it was also linked to the default SMTP virtual server as well as
the OWA. This I believe was advertising TLS even though I hasd not set it to
require TLS. When I removed the Certificate from the SMTP VS then the e-mails
started to come through.

"Joe S." wrote:

I have a Exchange 2003 SP2 on Win Srv 2003 SP2 in a Win Srv 2003 Domain.
This is my only Exchange server and I have issued a SSL cert to for use with
OWA from a CA i have set up internally on one of my servers. This was working
fine until I had to renew the cert because it was expiring. Now access OWA
still works fine, but I can't recieve e-mails from certain external e-mail
servers. I get the following in my SMTPSVC1 logs


2007-09-12 21:15:58 64.213.134.27 mailp2.yardi.com SMTPSVC1 CADUCEUS
192.168.1.5 0 EHLO - +mailp2.yardi.com 250 0 246 21 -
2007-09-12 21:15:58 64.213.134.27 mailp2.yardi.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - - 220 0 0 8 -
2007-09-12 21:15:58 64.213.134.27 mailp2.yardi.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - - 220 0 29 8 -
2007-09-12 21:15:58 64.213.134.27 mailp2.yardi.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - mailp2.yardi.com 503 997 29 8 -
2007-09-12 21:15:58 64.213.134.27 mailp2.yardi.com SMTPSVC1 CADUCEUS
192.168.1.5 0 QUIT - mailp2.yardi.com 240 266 29 8 -
2007-09-12 21:16:02 198.187.200.42 mail2.insight.com SMTPSVC1 CADUCEUS
192.168.1.5 0 EHLO - +mail2.insight.com 250 0 247 22 -
2007-09-12 21:16:02 198.187.200.42 mail2.insight.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - - 220 0 0 8 -
2007-09-12 21:16:02 198.187.200.42 mail2.insight.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - - 220 0 29 8 -
2007-09-12 21:16:02 198.187.200.42 mail2.insight.com SMTPSVC1 CADUCEUS
192.168.1.5 0 STARTTLS - mail2.insight.com 503 997 29 8 -
2007-09-12 21:16:02 198.187.200.42 mail2.insight.com SMTPSVC1 CADUCEUS
192.168.1.5 0 QUIT - mail2.insight.com 240 343 29 8 -


I can send them e-mails, but I never recieve there e-mails. When I restart
my IIS6.0 on the exchange server I get the following error:

Event Type: Warning
Event Source: smtpsvc
Event Category: None
Event ID: 2002
Date: 9/12/2007
Time: 1:22:18 PM
User: N/A
Computer: CADUCEUS
Description:
The server certificate for instance '1' could not be retrieved because it
could not be found in a certificate store; the error encountered was
'0x80092004'

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

When I view the certificate certificate properties installed on the Exchange
server they all are fine.

Any ideas?
.



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: TLS for secure mail
    ... Is there a reason you don't want to accept TLS sessions from other ... You need a certificate of your own for your server. ... "Access" tab on the SMTP Virtual Server and add the certificate to the ...
    (microsoft.public.exchange.admin)