Re: Mismatched Address

Tech-Archive recommends: Fix windows errors by optimizing your registry



You need to have your public DNS record point to remote.mydomain.com. This is NOT the DNS that you host in Active Directory for mydomain.local. It is the DNS that either your ISP or your DNS provider hosts for you. That DNS A record should resolve to the IP address of the WAN side of your internet router. (Or, in a dual NIC SBS 2k3 that doesn't have a router in front of it, to the IP address of the internet facing NIC on your SBS box.)

--
Charlie.
http://msmvps.com/blogs/xperts64
http://mvp.support.microsoft.com/profile/charlie.russel


"thejamie" <thejamie@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:8DF07D2A-BB16-48B2-8224-BC4FA71A5071@xxxxxxxxxxxxxxxx
Hi,

I attempted in the past to install a goDaddy certificate on my SBS server
back in May of 2009. I spent the full thirty days trying to install and then
when I still had no success, I revoked the certificate and vowed to try again
when I had time.

My error is only on the internet side - internally everything works fine.

The error from the internet side is "Mismatched Address"
The security certificate presented by this server was issued to a different
web site's address.

If I view the certificate it says: (will replace the actual domainname w/
"mydomain")

Certificate Information
This certificate is intended for the following purpose(s):
Ensures the identity of the remote computer

*Refer to the certification authority's statement for details.

Issued to remote.mydomain.com
Issued by Go Daddy Secure Certification Authority
Valid from xx/xx/2009 to xx/xx/2011

_____________________________________________

I followed the directions at
http://www.smallbizserver.net/Articles/tabid/266/articleType/ArticleView/ArticleID/283/PageID/470/Default.aspx

In these directions, the certificate common name is "remote.company.com".
In an effort to follow the instructions as is, I varied from my attempt three
months ago and used the remote.mydomain.com rather than www.mydomain.com.

Apparently this has nothing to do with the error as it is the same for both
of the issues of the certificate.

Go Daddy experts have explained to me that I need to have a site called
remote.mydomain.com. We even made an attempt to create a Host(A) record
called remote, but it will only resolve to remote.mydomain.local.

Also tried to create a CNAME(alias) of remote and allow it to resolve to the
domain server name:

universe.mydomain.local

(Universe is the server name that houses the pdc).

Is there another set of directions somewhere that will work? I am running
SBS2003 Premium. It has been running without incident since 2006 up until
IE7 came out and started telling my users that the certificate was
self-signed and could not be trusted.

Please help.

(I have started a new thread and made a comment as such in the previous
thread.)
--
Regards,
Jamie

.



Relevant Pages

  • Re: Outlook via Internet with different internal and external domains
    ... If you do not have an A record in DNS for mail.abc-external.com, ... to outlook over the Internet and follow them EXACTLY. ... After setup I have a self-signed certificate called ...
    (microsoft.public.windows.server.sbs)
  • Re: Internal / External DNS problem.
    ... "My DNS shows mycompany.local and mycompany.com as two different ... What name did you give the certificate? ... to use Outlook via the Internet" link, ... Verify that the computer trusts the certificate used by the server ...
    (microsoft.public.windows.server.sbs)
  • Re: Mismatched Address
    ... is NOT the DNS that you host in Active Directory for mydomain.local. ... A record should resolve to the IP address of the WAN side of your internet ... I attempted in the past to install a goDaddy certificate on my SBS server ... In these directions, the certificate common name is "remote.company.com". ...
    (microsoft.public.windows.server.sbs)
  • Re: Mismatched Address
    ... That DNS A record should resolve to the IP address of the WAN side of your internet router. ... I attempted in the past to install a goDaddy certificate on my SBS server ... The security certificate presented by this server was issued to a different ... In these directions, the certificate common name is "remote.company.com". ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot request computer certificate.
    ... > request a computer certificate for about 9 months. ... > and verify that you can get a computer/server certificate from it. ... > Kerberos, or dns. ... > List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)