Re: RPC over HTTP Certificate Issue




Re-run the CEICW and make your certificate name the same as your external server name. These must match to avoid security warnings.

You can use abc.dyndns.org directly, or if you have your own registered domain name create a CNAME record in DNS (e.g. server.abc.com IN CNAME abc.dyndns.org) and use server.abc.com as the cert name and the name you use in Outlook and IE to connect to the server. This name will always return your current IP and will look a bit more professional than using a dyndns name directly. (Caveat, never use a CNAME in your MX record, just use the dyndns name there).

-- stephen

freakrz@xxxxxxxxxxx wrote:
Hi,

I enabled RPC over HTTP on SBS 2003 Sp1 server, and followed the
instructions to configure exchange as in here

http://technet.microsoft.com/en-us/library/aa995729.aspx


But now on the client side ,Outllok can't connect. When it starts -
comes up
with a message:

"'The connection to the Microsoft Exchange server is
unavailable.Outlook must
be online or connected to complete this action.'

'Unable to open your default email folders. The information store
could be
opened' "

I tried to connect https://FQDN/Remote from the client and i get a
security certificate
I installed the certificate in trused certificates,
even after that i am getting a security alert

"The name on the security certificate is invalid or does not match the
name of the site.

we use dyndns to access our server,since we do not have a static
ip,and the certificate has our server name on
it"servername.domain.local" but our web address is "abc.dyndns.org"

Is this a possible reason for outlook not connecting over http.

i have checked it internally within our LAN and it worked.but over the
internet i could not get it to work.
the server side config seems to be all set and working,

since all the diagnosis tests to check rpc over http showed positive
results.

I have checked all the below and everything is configured.

http://technet.microsoft.com/en-us/library/bb124649.aspx

o How to Verify That RPC over HTTP Support Is Installed
o How to Verify That World Wide Web Publishing Service Is
Running
o How to Verify That SSL Certificate Is Installed on RPC
Proxy Server
o How to Verify RPC Virtual Directory Configuration
o How to Verify That RPC Proxy Server Extension Is Loading
Properly
o How to Verify Client Computer Configuration
o How to Verify Exchange Server 2003 Port Configuration

could someone please clarify if there would be a problem related to
the certificate,as i have stumbled across some websties pointing that
outlook would not connect if a security alert relating to the
certificate pop's

How should i go about this issue,since we use dyndns...!

Thank You

Frk.

.



Relevant Pages

  • Re: AD and SSL
    ... I'm trying something similar, with a java client, but can't seem to ... I'm trying to connect to an active directory (W2K server) using ssl (with ... verify return:1 ... Server certificate ...
    (microsoft.public.win2000.active_directory)
  • Re: Unable to use stunnel with tin...
    ... Looks like you got an odd version of stunnel. ... was getting the certificate written correctly. ... Next verify you can connect to the server. ...
    (comp.os.linux.setup)
  • RE: Autoenrollment error with Win2K3 servers - Event IDs 13 and 17
    ... After rebuilding the server from scratch and carefully ... In the Local Security Policy, ... Computer certificate from certificate authority %CA NAME% on %CA FQDN% ...
    (microsoft.public.windows.server.general)
  • Re: NPS RADIUS with Cisco wlc
    ... There is no layer 3 security assigned. ... And you must issue a certificate to the NPS server that is based on the IAS ... Connection request policy (ran through the wireless 802.1x wizard) ...
    (microsoft.public.internet.radius)
  • RE: [Full-Disclosure] Openssl proof of concept code? / Neoteris
    ... its own built-in cert and offers it up without solicitation. ... SSL connection with the server with a corrupt cert like that. ... modify a copy of openssl such that it sends a client certificate ... verify error:num=20:unable to get local issuer certificate ...
    (Full-Disclosure)