Re: Exchange Activesync and Internal / External Domain on SBS 2003

Tech-Archive recommends: Fix windows errors by optimizing your registry



If you are using SBS 2003 PREMIUM (with ISA 2004) then this is what I
suggest as I have also faced problems setting up SBS2003 with win mobile 6
device:

1. You need two certs:
Cert A- for "publishing.internal.local"
Cert B- for "gate.external.de"

2. You should Install certificate A on IIS.

3. Then open the ISA Server manager and open the web publishing rule
(tipically SBS Web Listener).
Open the "To" tab, and type "publishing.internal.local" as the server name.
Click to check "Forward original host header" and also click to choose
"requests appear to come from the ISA server computer".

4. You should install certificate B on the publishing rule on the ISA
server. Tipically the rule will be named "SBS Web Listener". Open that rule,
open the "Listener" tab, and then click Properties.
On the new window, open the tab "Preferences" and install certificate B
there. This is the certifcate that establishes the comunication between the
Device and the Server (certificate facing the EXTERIOR).

A good tip for troubleshooting ActiveSync issues is opening up Mobile
Internet Explorer on the Windows Mobile 6 device and open the website:
https://gate.external.de/OMA
This will spill out relevant troubleshooting information. As a general rule
if you can sucessfully connect to this site from the mobile device then
mobile sync will be working.

PS: You don't need to add the A-record for gate.external.de in your internal
DNS servers.


"Werner Pertl" <wernerp@xxxxxxxxxxxxxxxx> escreveu na mensagem
news:OiYKqE1RIHA.4476@xxxxxxxxxxxxxxxxxxxxxxx
Hello,



I've got a problem and hope someone here has a solution for me :-)



SBS 2003 Premium



A smartphone (HTC Touch) with Windows Mobile 6 should get synchronised
with Exchange using Activesync.



For conntecing to the server a WLAN connection should be used on the local
workplace and GPRS connection when working outside.



My first problem was that the server is reachable from external under
"gate.external.de" but from internal "servername.internal.local" had to be
used.



Switching the addresses everytime manually on the mobile device was really
anoying, so i created a new dns zone on the the server with an "a-record"
pointing to the sbs ip.



That works well so far, you can use the address "gate.external.de" now
from the internal network, but there's a problem with the ssl certificate:



When "gate.external.de" is used from internal network, the ssl certificate
from "servername.internal.local" (publishing.internal.local) shows up, and
therefore the synchronisation does not work, cause Activesync see the
certificate as invalid (cause the certificate does not fit to the domain).



Hope somebody can help me, and sorry for my bad english :-)



Thank you very much!



Werner




.



Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange in iPod touch with SBS 2003 R2
    ... I am planning to by a new mobile phone and I was thinking on have a iphone ... I think I may be missing something at the server end. ... The certificate I think is the issue. ...
    (microsoft.public.windows.server.sbs)