Secure Messaging ForumTopics discussed include: Encryption, peer to peer communication, DRM, Hosted and Services, hardening Exchange© 2009 Microsoft Corporation. All rights reserved.Tue, 01 Dec 2009 16:59:02 Z943be16a-69e9-4cac-9d30-fcbc8da8fc1dhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/23a8bb1d-72c1-47c0-bd24-b99986097c79http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/23a8bb1d-72c1-47c0-bd24-b99986097c79p99373http://social.technet.microsoft.com/Profile/en-US/?user=p99373Choosing email-address from a SAN listI have a MS CA certificate with 3 SAN email addresses for digital signing purposes.  <br/>Each time Outlook display &quot;signed by&quot; 1st email address in the SAN list.<br/>Is there a way to specify which SAN email-address Outlook should choose or display as &quot;signed by&quot;?Fri, 20 Nov 2009 18:38:51 Z2009-12-01T16:59:02Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/2bd9b2bd-6576-4caf-9d87-b396e00d8771http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/2bd9b2bd-6576-4caf-9d87-b396e00d8771techooverhttp://social.technet.microsoft.com/Profile/en-US/?user=techooversecure shared mailbox emailsHello everybody<br/> <br/> Short form of question - is it possible to have certificates and encrypted email for shared mailbox?<br/> <br/> Long form of question.<br/> In our company we use Exchange and outlook with deployed PKI. So everybody has pair of certificates and able to encrypt/decrypt emails.<br/> Apart from this we use shared mailboxes. Some teams has their own shared and sometimes this team might receive encrypted email. As shared mailbox has no certificate this poor people have to ask sender to send the very same email again to personal account. Then is can be decrypted and processed. So, what we need is a ability to create certificate for shared mailbox and publish it in AD. How is it possible?<br/> <br/>Wed, 25 Nov 2009 14:14:22 Z2009-11-28T05:27:22Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/1e0fe172-693e-44d1-9810-b72016f1470bhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/1e0fe172-693e-44d1-9810-b72016f1470bjwmms1http://social.technet.microsoft.com/Profile/en-US/?user=jwmms1SSL Cert and Edge Server Question - Exchange 2007 I have two questions that are closely related:<br/><br/>1. I issued the New-ExchangeCertificate cmdlet on the Exchange Management Shell in order to generate a key. I am to upload this key to Go Daddy's site in order to have them generate a third party cert for our Exchange environment.  After I generated the key I realized that some revisions are necessary.  I am to run the command again in order to get a reissued key. The command executes without an error and drops me back at the command prompt.  Howerver, a text file is not generated.  I would like to have some direction if possible on accomplishing this task.  The template provided by Go Daddy is:<br/><br/>New-ExchangeCertificate -generaterequest -keysize 2048 -subjectname &quot;c=Your Country, l=Your Locality/City, s=Your State, o=Your Corporation Name,cn=YourMainDomain.com&quot; -domainname CAS01,CAS01.exchange.corp.contoso.com,exchange.contoso.com,<br/>autodiscover.contoso.com -PrivateKeyExportable $true -path c:\certrequest.txt<br/><br/>Should the cn= my domain name, FQDN for the Exchange OWA (webmail.domainname.com) or the FQSN (exchangeserver.webmail.domainname.com).  Further, is the -domainname a required entry?<br/><br/>2. I am using an Edge server in our DMZ for message routing.  How should port forwarding be set properly.  I am somewhat of a visual learner.  If there is a diagram that I could see, that would help me quite a bit.<br/><br/>Thanks in advance for any help you will provide.<br/><br/>JesseThu, 19 Nov 2009 22:58:49 Z2009-11-27T01:20:39Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/b38330e8-b5cc-4461-9c35-6d18c08b2447http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/b38330e8-b5cc-4461-9c35-6d18c08b2447Fazal Ur Rehmanhttp://social.technet.microsoft.com/Profile/en-US/?user=Fazal%20Ur%20RehmanSAN CertificateWe are upgrading to Exchange 2007. We are planning to have Exchange 2007 Mailbox CCR. We would have a NLB for CAS/Hub. We are planning to go for public CA but are confused as to how many certificate should be go for. We would have Outlook AnyWhere, ActiveSync, Outlook Web Access configured. We are going to use ISA 2006 for publishing this services. I would be glad iy you could let me know the no. of certificate we should purchase. Tue, 03 Nov 2009 11:31:08 Z2009-11-23T00:03:08Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/af7edc01-6075-4943-8dba-4c52c38bf437http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/af7edc01-6075-4943-8dba-4c52c38bf437Broken_hearthttp://social.technet.microsoft.com/Profile/en-US/?user=Broken_heartCertificate Server digital signatureHi all,<br/>   Is there some certificate authority server which gets integrated with my LDAP server and authenticate the user using that LDAP server, and than taking the attribute for that user from the LDAP server generate an certificate i.e. digital signature *.p12. This not ends my demand, further more the server should also send the certificate (signature) via email to the userWed, 18 Nov 2009 12:56:24 Z2009-11-19T06:21:49Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0628f183-0198-4b08-a054-369a5e040636http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0628f183-0198-4b08-a054-369a5e040636bydabeachhttp://social.technet.microsoft.com/Profile/en-US/?user=bydabeachSharing Encrypted E-mail --sharing S/MIME Certificates?We are a 20 person firm using Microsoft Exchange 2003.  One of our clients requires communication via encryption.  I am the main person who communicates with this client.  Presently, I have a personal S/MIME certificate that must be renewed annually.  The problem is that when encrypted e-mails to me are uploaded to our document management system, no other employees of our firm can read the e-mail.  I understand that I could forward the e-mail and send it unencrypted, but we would rather preserve the original sender and send date in our document management system.<br/> <br/> Can my S/MIME certificate be exported and shared with other employees so that they can encrypt and decrypt e-mails?<br/> <br/> Is there an easier way to handle this situation than using an external certificate?  We want to avoid having to annually purchase external certificates which must be renewed annually.  Can the messages be encrypted/decrypted at the Exchange Server level?<br/> <br/> thank you.Fri, 13 Nov 2009 21:52:57 Z2009-11-18T16:03:24Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/3037f62b-484a-451f-bdeb-eb52ed6ba663http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/3037f62b-484a-451f-bdeb-eb52ed6ba663Sheen1990http://social.technet.microsoft.com/Profile/en-US/?user=Sheen1990Securing attachments in Exchange<span class=value>Hello<br/><br/>We are currently running in Exchange 2003 SP2 and Exchange 2007 SP1 mixed mode. We have several Exchange 2003 Admin/routing groups. All clients are Outlook 2007.<br/><br/>I would like to look into a system where third parties can send us secure attachments (e.g. containing confidential data) but at the same time, I do not want this to affect other third parties sending us attachments, nor have to implement this across the board of our Exchange 2003/2007 org, only one country actually needs to have this.<br/><br/>Does anyone have any recommendations?</span>Tue, 10 Nov 2009 07:03:14 Z2009-11-20T09:33:25Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/53f8338f-16f4-486a-8625-417f18b6f1a0http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/53f8338f-16f4-486a-8625-417f18b6f1a0Robert Farmerhttp://social.technet.microsoft.com/Profile/en-US/?user=Robert%20FarmerOWA Exchange 2007 over HTTPS question<p align=left><font face=Arial size=2></font> </p>How can I set up my server so that the secure certificate is valid?  Do i need to register something?Thu, 20 Sep 2007 21:15:28 Z2009-11-15T13:35:23Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/51a67793-e704-4c15-9bbb-37b78775f703http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/51a67793-e704-4c15-9bbb-37b78775f703Mortorphttp://social.technet.microsoft.com/Profile/en-US/?user=MortorpOutlook anywhere - machine certificates for auth<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="line-height: 115%; font-family: &quot;Verdana&quot;,&quot;sans-serif&quot;; color: black; font-size: 9.5pt;">We have a customer who are looking for a secure way of deploying Outlook anywhere.<br />To be able to connect to Outlook anywhere they will also use machine certificates for auth.</span></p> <span style="line-height: 115%; font-family: &quot;Verdana&quot;,&quot;sans-serif&quot;; color: black; font-size: 9.5pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;">It this possible?<br style="mso-special-character: line-break;" /><br style="mso-special-character: line-break;" /></span><hr class="sig">MortenFri, 16 Oct 2009 13:50:46 Z2009-11-08T02:37:29Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/7b0d60b2-bd36-427d-a39b-80a831637dd8http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/7b0d60b2-bd36-427d-a39b-80a831637dd8YngDiego777http://social.technet.microsoft.com/Profile/en-US/?user=YngDiego777Two-factor authentication for Outlook Anywhere?Are there any two factor authentication options for Outlook anywhere when using Exchange 2003 and Outlook 2007? All users will have their domain username and pasword, but for external access we need a second authentication method.<br/><br/>We can issue certificates to computers or users. However, my Google searches didn't come up with any hits on how to make Outlook Anywhere work with certificates/smart cards. <br/><br/>I know IIS has a many-to-one certificate mapping feature, but it wasn't clear if that would work. For example, it wants you to input an account which the many-to-one mapping uses. <br/><br/>Our requirement is to only accept Outlook Anywhere connections from computers which have corporate issued user certificates. If ISA 2006 helps at all, we can throw that into the mix. But I'd prefer a solution that only relies on IIS configuration changes. <br/><br/>Clients will be Windows XP SP3 or Windows 7 beta. <br/><br/>Thanks!Wed, 15 Apr 2009 20:08:24 Z2009-11-08T02:35:53Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/6d13d209-402e-43d0-aac3-c7f1c6ca23a1http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/6d13d209-402e-43d0-aac3-c7f1c6ca23a1Taylormade58http://social.technet.microsoft.com/Profile/en-US/?user=Taylormade58Encrpyted emailsI have a need to send encrypted emails and attachments. I currently use Exchange 2003 for my domain and I understand the use of public and private keys withing the domain. What I am trying to do is send an encrypted email to clients that currently do not have keys to open the emails. Is there a way to send them a key, without someone intercepting it, so they can then open the email? The client list may vary so I don't want to just send a key to everyone.<br/>ThanksTue, 03 Nov 2009 14:32:09 Z2009-11-07T13:50:22Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/bab24d5f-7531-4cf5-a8e4-ce962b6b3c17http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/bab24d5f-7531-4cf5-a8e4-ce962b6b3c17john3dhttp://social.technet.microsoft.com/Profile/en-US/?user=john3dAvoid fake email accounts<p>Hello, I have configured MS Exchange 2007. I have just noticed that by doint telnet my.mail.server.com 25, anybody can connects to my mail server and send emails from fake accounts (say EMAIL GONE) to real accounts of my organization. <br /><br />The question is, how can avoid this? does it have to do with Anonymous connection? <br /><br />Thanks in advance,<br /><br />John</p>Wed, 14 Oct 2009 17:05:56 Z2009-11-06T17:50:26Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/216379db-fcf1-44d4-9af6-aeea8bcd87cdhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/216379db-fcf1-44d4-9af6-aeea8bcd87cdCyber Gangstahttp://social.technet.microsoft.com/Profile/en-US/?user=Cyber%20GangstaReceiving Encrypted EmailHello,<br /> I have a friend that runs a business and runs Exchange Server 2003.&nbsp; When his accountant sends him email it is unencrypted, which concerns him.&nbsp; What solution exists that will enable the business owner to receive encrypted emails from his accountant?&nbsp; As the accountant does not run exchange server, I am unsure as to how to approach this problem.<br /> <br /> Thank YouWed, 14 Oct 2009 06:16:17 Z2009-11-06T23:27:19Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/8bed8b94-7c20-4e3e-a0ca-4483ebca41dehttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/8bed8b94-7c20-4e3e-a0ca-4483ebca41deWin HighTechLAhttp://social.technet.microsoft.com/Profile/en-US/?user=Win%20HighTechLAConfused with SSL and Certificate AuthorityI am vague about how SSL and certificate authority works. Windows Server 2003 has a built in CA it looks like, but people are saying to buy a 3rd party CA. <br/> <br/> Will the built in CA only work for internal users of the network?<br/> <br/> I've been trying to get SSL to work for our OWA, but it seems like SSL will only work for our internal users and not our external users. I've enabled our sonicwall all WAN to specifically the ip address of the LAN exchange server. Could this be a certificate problem? When connected from outside, the website just displays:<br/> <br/> Unable to connect<br/> <br/> Firefox can't establish a connection to the server at email.domain.com<br/> <br/>         <br/>     *   The site could be temporarily unavailable or too busy. Try again in a few<br/>           moments.<br/> <br/>     *   If you are unable to load any pages, check your computer's network<br/>           connection.<br/> <br/>     *   If your computer or network is protected by a firewall or proxy, make sure<br/>           that Firefox is permitted to access the Web.<br/>Mon, 02 Nov 2009 02:37:12 Z2009-11-13T08:57:11Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/c25990f8-e926-46ad-a8c6-411f17a12590http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/c25990f8-e926-46ad-a8c6-411f17a12590Win HighTechLAhttp://social.technet.microsoft.com/Profile/en-US/?user=Win%20HighTechLAConfiguring SSL for OWA<p>I am trying to configure SSL for OWA.<br/><br/>I am able to access my OWA within my network (intranet)<br/>How ever when I am on another ISP I cannot access the secure website.<br/><br/>What could be the cause of this? <br/>Please help,<br/><br/>Thank you</p>Mon, 19 Oct 2009 21:58:38 Z2009-11-02T02:18:16Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/e8546bff-872f-4ff3-9c36-ab2e55dd7d9chttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/e8546bff-872f-4ff3-9c36-ab2e55dd7d9ccsr itslnhttp://social.technet.microsoft.com/Profile/en-US/?user=csr%20itslnE-mail block Internet <div dir=ltr>Hi<br/><br/>help, I have the following issue: <br/><br/>I want to block some users, not send mail outside and just do it internally. <br/>On the other Part, I have send  mail users that if they internally and externally. <br/><br/>Greetings <br/><br/>Thanks</div>Tue, 27 Oct 2009 05:02:45 Z2009-10-27T08:07:47Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/eec8b235-ed23-4311-bf92-294bb3d40049http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/eec8b235-ed23-4311-bf92-294bb3d40049Futurist71http://social.technet.microsoft.com/Profile/en-US/?user=Futurist71Encryption Email Outlook 2007 Hi! <br/><br/>I want to know if i am doing something wrong. <br/><br/>I'm creating a free certificate in <br/><a href="http://www.trustcenter.de/en/products/tc_internet_id.htm"><span style="color:#b05215">http://www.trustcenter.de/en/products/tc_internet_id.htm</span></a> <br/>Configuring the MIME certificate on Microsoft Outlook 2007, I try to send an <br/>email encrypted no signed and the client can open the email even if i havend <br/>sent the messager with the sign. Why is this happening? Am I missing <br/>something? <br/><br/>I'm following theses steps: <br/><br/><a href="http://www.globalsign.com/support/personal-certificate/per_outlook07.html"><span style="color:#b05215">http://www.globalsign.com/support/personal-certificate/per_outlook07.html</span></a> <br/><br/>Best regards, <br/><br/>Futurist Tue, 20 Oct 2009 16:28:50 Z2009-10-30T09:02:56Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/095f0ab6-619c-4bd4-8b67-58d5feda142bhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/095f0ab6-619c-4bd4-8b67-58d5feda142bdavemac327http://social.technet.microsoft.com/Profile/en-US/?user=davemac327Is it possible to off-load security to separate appliance (DataPower) and implement last-mile security to EWS?The scenario is as follows: company policy says all web services get secured via DataPower appliance (XML accelerator that can manage certificates, Basic auth, logging, auditing, XSLT, etc). Would like to use EWS with certain system mailboxes (not regular users) to process emails programmatically. My client program therefore would need to send SOAP message to DataPower, which then sends to EWS. Exchange server must reject direct EWS requests not coming from DataPower. Can this be done? Specific instructions would be most appreciated.<br/> <br/> - dave<br/>Thu, 22 Oct 2009 19:38:06 Z2009-10-22T19:38:08Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/215ac403-b8f8-4d95-b51d-2767d61c00dbhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/215ac403-b8f8-4d95-b51d-2767d61c00dbNbembyhttp://social.technet.microsoft.com/Profile/en-US/?user=NbembyTLSHi, I need to implement TLS for a specific client. We already SSL implemented on our Exchange 2007 Frond End Servers. Will there be any clash between these two certificates and how can I implement TLS if there is no problem implementing that.<br/><br/>Thanks in advance..<br/><br/>NavneetMon, 19 Oct 2009 16:15:05 Z2009-10-23T02:25:10Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0cb055a4-298c-4d2f-be39-0956c4019e1dhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0cb055a4-298c-4d2f-be39-0956c4019e1dScottG14http://social.technet.microsoft.com/Profile/en-US/?user=ScottG14Windows 2003 R2 Certificate Template Hi,<br />I want to make a certificate template that will give me the option Type of Certificate Needed and from there I can select Client or server certificate.&nbsp; I created a duplicate certificate but it doesn't show me that option.&nbsp; Is there an additional step I need to add this option to my current Template?<br />Thanks<br />Scott<br /><br /><span style="font-size: 10pt; color: navy; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;">&nbsp;</span><hr class="sig">SkierTue, 06 Oct 2009 19:06:45 Z2009-10-16T12:23:43Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/8119eba6-7496-40e5-b09e-08b29616dae4http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/8119eba6-7496-40e5-b09e-08b29616dae4Albert Widjajahttp://social.technet.microsoft.com/Profile/en-US/?user=Albert%20%20WidjajaSecuring Activesynch mobile devices on Exchange Server 2007Hi All,<br/> <br/> Here's my configuration, MS Exchange Server 2007 SP1 on my Windows Server 2003 box, I've deployed<br/> <br/> CAS Client Access Server role<br/> MBX Mailbox Role<br/> HT Hub Transport Role<br/> <br/> all into single box and have successfully enabled the OWA feature + UCC SSL Certificate, Activesynch going fine on both Windows Mobile PDA and iPhone too.<br/> <br/> However, I begin to concerns regarding the security of the email that is downloaded into the mobile devices, is there any way to make it more secure ?<br/> <br/> Any suggestion and comments will be greatly appreciated.<br/> <br/> Thanks.<hr class="sig">/* Windows Infrastructure Support Engineer */Mon, 28 Sep 2009 08:18:43 Z2009-10-07T11:47:23Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/2ded84c4-0a4a-42bb-8ddc-5f7278bbc925http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/2ded84c4-0a4a-42bb-8ddc-5f7278bbc925flaeryhttp://social.technet.microsoft.com/Profile/en-US/?user=flaerySolution for encryptionHello,<br/><br/>we would like to encrypt all local/intern emails on our Echange Server 2007. At the moment i have only found S/Mime as solution. Is there another solution beside S/Mime?<br/><br/><br/>Best Regards<br/>FlorianMon, 28 Sep 2009 19:19:12 Z2009-10-06T10:01:53Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0b2614ac-4ffb-43cc-ad3b-2c82e54a4909http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/0b2614ac-4ffb-43cc-ad3b-2c82e54a4909Khalidrazakhanhttp://social.technet.microsoft.com/Profile/en-US/?user=KhalidrazakhanUnable to delete e-mails from OWA, Access denied message appearsI am unable to delete e-mails from my outlook web Access. I gives Access denied message when i try to delete the message.<br/> i am using Exchange 2003 with windows 2003 and outlook 2003 client.<br/> Can any body help me???Mon, 28 Sep 2009 05:45:14 Z2009-09-30T08:40:44Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/5503e17e-c7c0-49fe-94d9-fadff505071bhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/5503e17e-c7c0-49fe-94d9-fadff505071bJaiDDJaihttp://social.technet.microsoft.com/Profile/en-US/?user=JaiDDJaiOutlook 2007 Sending reported error 0x800CCC801. Outlook Express 6.0: setting require authentication for outgoing SMTP. IMSS (Trend micro) can accept and relay to another mail sever. working OK.<br/><br/>2. Outlook 2007: setting require authentication for outgoing SMTP. IMSS (Trend micro) can not accept. <br/>    Error message: Sending reported error 0x800CCC80 'None of the authentication methods supported by this client are supported by your server.'<br/><br/>Please help.<br/><br/>Best Regards,<br/>JaiDDJaiFri, 25 Sep 2009 10:53:13 Z2009-09-30T02:37:31Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/c246b6d9-1cb0-49de-b23a-731828e61839http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/c246b6d9-1cb0-49de-b23a-731828e61839MTLER1http://social.technet.microsoft.com/Profile/en-US/?user=MTLER1RPC over HTTPSRPC over HTTPS is not working. My setup is a s follows: ISA ver 2006 in DMZ, one Exchange 2003 back end server and one Exchange 2003 front end server, both version 6.5 (build 7638.2 Service Pack 2. I believe RPC over HTTPS works internally since when I run outlook.exe /rpcdiag, it shows https protocol rather than TCP at least for most of the items displayed there. Also, OWA and active sync for Mobile phones work fine externally. I think there is something missing/misconfigured on the ISA server but I'm not sure what.<br/>Thank you.Mon, 31 Aug 2009 19:43:56 Z2009-09-29T03:44:39Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/fc64d189-3578-4409-8593-4fdb37b507ffhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/fc64d189-3578-4409-8593-4fdb37b507ffTreKronorMatshttp://social.technet.microsoft.com/Profile/en-US/?user=TreKronorMatsExchange 2007 Outlook Anywhere problem Optionen <div><a name="msg_d2d57472dd4aa6a9"></a>Hy folks, <br/>our Outlook Anywhere suddenly stopped working last night. <br/>If I start Outlook I get the credentials dialog as normal, but <br/>everytime I enter (the correct) credentials it just pops up again and <br/>Outlook doesn't connect. OWA works fine though. <br/> <p>Here is our configuration: <br/>Windows EBS (Essential Business Server) 2008, Exchange 2007 SP2 on <br/>Windows Server 2008, published via TMG MBE (which is, as far as I <br/>know, basically a ISA 2006 with some enhanced features), single AD <br/>domain. <br/>We work with an self signed cert (we already ordered one from EnTrust <br/>but this will take a few days), which worked fine for us until <br/>yesterday (I don't think we have cert issues though).</p> <p>What catches my eye: <br/>If I got that right, I am supposed to see a blank page if I open the <br/>URL &quot;<a rel=nofollow href="https://owa.mydomain.com/rpc">https://owa.mydomain.com/rpc</a>&quot; from a browser, right? Internally <br/>(from our LAN) this works fine, I get a blank page. From the www I <br/>have to enter my credentials and than I get an IE error page saying:</p> <p>Technical Information (for support personnel) <br/>Error Code 64: Host not available <br/>Background: The connection to the Web server was lost.</p> <p>I tried a lot and my eyes are already wet from all the reading in the <br/>newsgroups, maybe one of you can help out.</p> <p>Thanks in advance, <br/>Michael</p> </div>Thu, 24 Sep 2009 18:03:35 Z2009-09-24T20:01:51Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/15c45180-9bfd-4c4e-8967-2829bec531cdhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/15c45180-9bfd-4c4e-8967-2829bec531cdJun Duhttp://social.technet.microsoft.com/Profile/en-US/?user=Jun%20DuHow to request certificates from CA?<p>Hi,<br/><br/>I have a client/server application in which one server (A) supports multiple clients. We need to implement certificate-based authentication. I have installed a CA on another server (B). How do I request/install a certificate for the server and clients? Do I have to send the request from the machine and account where I am going to install them? In other words, how can I request a server/client certificate on behalf of another machine?<br/><br/>Thanks! </p><hr class="sig">jdTue, 22 Sep 2009 22:18:05 Z2009-09-23T14:26:12Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/a78e194b-0dca-443e-90c8-4a5428b85e70http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/a78e194b-0dca-443e-90c8-4a5428b85e70Eric Chathamhttp://social.technet.microsoft.com/Profile/en-US/?user=Eric%20ChathamEvent 12014 MSExchangeTransport errorsHello,<br/><br/>We are seeing tons of these events in the Application Log of our Edge Server.  When I run get-Exchangecertificate | fl, the status says &quot;invalid.&quot;  In conjunction with these events, we also see Warnings for Event ID: 12015 MSExchangeTransport (Transport certificate expired).  Please assist.  Thank you.Tue, 25 Aug 2009 21:44:01 Z2009-09-22T18:15:57Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/05a68d64-d941-4b8c-af0c-19f9aeed9dechttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/05a68d64-d941-4b8c-af0c-19f9aeed9decColin Stewarthttp://social.technet.microsoft.com/Profile/en-US/?user=Colin%20StewartExchange 2007 encryption - outlook anywhere users<div class=container> <div class=body> <p>Hi Frank, <br/><br/>maybe you could provide some input on this. I have been able to set up the CA on one of our DC's. i can request certificates fine and send encrypted emails from the desktops on our LAN. the problem i am having is with the laptops. all the laptops are set to use RPC over HTTPS regardless if they are in the office or are mobile. these users cannot send encrypted emails they get a error stating &quot;Microsoft Office Outlook had problems encrypting this message because the following recipients had missing or invalid certificates, or conflicting or unsupported encryption capabilities&quot;. To me this would suggest a problem with the receiving PC...but the only time this message appears is when sending from a laptop set up to use RPC over HTTPS.<br/><br/>Here is how i have things set up right now:<br/><br/>- exchange server internal FQDN: exchange.internal.local<br/>- all desktops are configured to connect to exchange VIA it's internal FQDN.<br/><br/>- outlook anywhere URL: <a href="https://exchange.external.com/"><span style="color:#0033cc">https://exchange.external.com</span></a> <br/>- all laptops are configured to have outlook connect to <a href="https://exchange.external.com/"><span style="color:#0033cc">https://exchange.external.com</span></a> but have the exchange server name as exchange.internal.local.<br/><br/>- CA server is on the same domain it's FQDN is: CA1.internal.local<br/>- CA server is not accessible externally<br/>- CA server's common name for issuing certificates is CA1<br/><br/>I think i know what the problem is but i'd like to hear what you think.<br/>Thanks<br/>Colin</p> </div> </div> <div class="menu message"> <ul class=menu> <li><a title=Reply rel=nofollow name=reply href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/7bb379dd-be54-4d7b-97de-b4fedfa617d9/reply"><img class="icon reply" title=Reply src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt=Reply><span style="color:#0033cc">Reply</span></a> </li> <li><a title=Quote rel=nofollow name=quote href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/7bb379dd-be54-4d7b-97de-b4fedfa617d9/quote"><img class="icon quote" title=Quote src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt=Quote><span style="color:#0033cc">Quote</span></a> </li> <li><a title="Mark As Answer" rel=nofollow name=setAnswer href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/7bb379dd-be54-4d7b-97de-b4fedfa617d9/setAnswer"><img class="icon answer" title="Mark As Answer" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Mark As Answer"><span style="color:#0033cc">Mark As Answer</span></a> </li> <li><a title=Edit rel=nofollow name=edit href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/7bb379dd-be54-4d7b-97de-b4fedfa617d9/edit"><img class="icon edit" title=Edit src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt=Edit><span style="color:#0033cc">Edit</span></a> </li> <li><a title=Delete rel=nofollow name=delete href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/7bb379dd-be54-4d7b-97de-b4fedfa617d9/delete"><img class="icon delete" title=Delete src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt=Delete><span style="color:#0033cc">Delete</span></a></li> </ul> <div class=clear> </div> </div> <li class="message "> <div class=head><span class=date>4 hours 3 minutes ago</span><a class=author rel=nofollow href="http://social.technet.microsoft.com/Profile/en-US/?user=Frank.Wang&amp;referrer=http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8&amp;rh=96LvvlrjyVaZD7aceataQDjKgtuBkySpyuAkHPUtfW8%3d&amp;sp=forums"><img src="http://i4.social.microsoft.com/Image.avatr?size=Small&amp;user=Frank.Wang&amp;id=00000000-0000-0000-0000-000000000000" alt=""></a><span class=fullbadge><a class=author rel=nofollow href="http://social.technet.microsoft.com/Profile/en-US/?user=Frank.Wang&amp;referrer=http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8&amp;rh=96LvvlrjyVaZD7aceataQDjKgtuBkySpyuAkHPUtfW8%3d&amp;sp=forums"><span class=name><span style="color:#008000;font-size:small">Frank.Wang</span></span></a><span class=affil> </span><span class=medals><img class="icon medalon" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Users Medals"><img class="icon medalon" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Users Medals"><img class="icon medalon" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Users Medals"><img class="icon medaloff" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Users Medals"><img class="icon medaloff" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Users Medals"></span></span> <div class=helpful> </div> </div> <div class=votingouterbox> <div class=voting><a class=voteuphreflink title="Vote As Helpful" name=voteup href="http://social.technet.microsoft.com/Forums/en/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8/ff9d98d3-fe3b-488a-bbc5-50b85087515a/voteHelpful"><img class="icon voteup" title="Vote As Helpful" src="http://i2.social.microsoft.com/Forums/resources/images/trans.gif?cver=2.4.1184.0" alt="Vote As Helpful"> <div class=votecount>0</div> </a></div> <span class="votinglabel type">Vote As Helpful</span></div> <div class=container> <div class=body>Hi Colin,<br/><br/>I'm afraid I don't very understand this one:<br/><em>all laptops are configured to have outlook connect to </em><a href="https://exchange.external.com/"><span style="color:#0033cc"><em>https://exchange.external.com</em></span></a><em> but have the exchange server name as exchange.internal.local.<br/></em><br/>Could you test the Outlook Anywhere in your company's domain? Just choose the &quot;on fast networks,connect using http first..&quot; in  &quot;exchange proxy settings&quot; in Outlook.<br/><br/>By the way , could you ask a new question about Outlook Anywhere in Forus? Just copy last post to the new one. <br/>It can be seen more continuing. Other people also can search forum more efficiently. Thanks.<br/><br/><br/> <hr class=sig> </div> </div> </li>Fri, 18 Sep 2009 13:41:04 Z2009-09-22T19:20:27Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/fa7563a3-19e3-4793-bd74-99d3850b3de8Colin Stewarthttp://social.technet.microsoft.com/Profile/en-US/?user=Colin%20StewartDigital ID's in exchange 2007Hi all,<br/><br/>I have been asked to give our users the ability to digitally sign/encrypt messages when sending to other users in our exchange organization. Every thing im seeing on the net suggests you need to use a 3rd party solution. We already have an SSL cert installed on the exchange server. Is there a way i can use this certificate to create digital ID's???<br/><br/>thanks<br/>ColinTue, 15 Sep 2009 20:52:57 Z2009-09-22T06:00:50Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/f27e727a-a594-411b-937f-daf7abd8bc57http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/f27e727a-a594-411b-937f-daf7abd8bc57Colin Stewarthttp://social.technet.microsoft.com/Profile/en-US/?user=Colin%20StewartOutlook 2003 RPC over HTTPSHi All,<br/><br/>For the past 9 months i have been running RPC over HTTPS on exchange 2007 without any problems (after getting it to work initially which was a severe pain in the...). I have users connecting with both outlook 03 and 07. Just this morning, the outlook 03 users cannot connect to the exchange server VIA RPC over HTTPS. the outlook 07 users are still working fine.<br/><br/>Anyone have any ideas as to why?<br/>Here is a piece of the IIS logs that show on of our users using outlook 03 trying to connect.<br/><br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_IN_DATA /rpc/rpcproxy.dll fqdn.server.local:6002 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 64<br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_OUT_DATA /rpc/rpcproxy.dll fqdn.server.local:6002 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 64<br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_IN_DATA /rpc/rpcproxy.dll fqdn.server.local:6004 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 0<br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_OUT_DATA /rpc/rpcproxy.dll fqdn.server.local:6004 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 0<br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_IN_DATA /rpc/rpcproxy.dll fqdn.server.local:593 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 0<br/>2009-09-16 17:13:40 W3SVC1 10.10.3.3 RPC_OUT_DATA /rpc/rpcproxy.dll fqdn.server.local:593 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 0<br/>2009-09-16 17:13:41 W3SVC1 10.10.3.3 RPC_IN_DATA /rpc/rpcproxy.dll fqdn.server.local:6002 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 64<br/>2009-09-16 17:13:41 W3SVC1 10.10.3.3 RPC_OUT_DATA /rpc/rpcproxy.dll fqdn.server.local:6002 443 domain.local\adminuser 70.49.27.43 MSRPC 200 0 0<br/>2009-09-16 17:13:41 W3SVC1 10.10.3.3 RPC_IN_DATA /rpc/rpcproxy.dll fqdn.server.local:6002 443<br/><br/>Ideas??<br/><br/>Thanks<br/>Colin<br/><br/><br/>UPDATE: turns out the 2007 clients are having the same issue now.Wed, 16 Sep 2009 17:34:32 Z2009-09-16T20:14:45Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/822c171c-9541-4532-86c7-3a936ba26026http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/822c171c-9541-4532-86c7-3a936ba26026Hijinxxhttp://social.technet.microsoft.com/Profile/en-US/?user=HijinxxExcange 2007 Event ID 12014 Error after instlling 2nd Hub Transport server. I installed a second Exchanger Server in our orginization with the Hub, Client Access and Mailbox roles. Since I installed the second sever, I have been getting the following error :- <div><br/></div> <div><span style="font-family:-webkit-sans-serif;font-size:small"><span style="font-size:13px;line-height:19px">Event ID 12014</span></span></div> <div><span style="font-family:-webkit-sans-serif;font-size:small"><span style="font-size:13px;line-height:19px"><br/></span></span></div> <div><span style="font-family:-webkit-sans-serif;font-size:small"><span style="font-size:13px;line-height:19px">&quot;<span style="font-family:Verdana;font-size:11px;line-height:16px">Microsoft Exchange couldn't find a certificate that contains the domain name &quot;mail.domainname.com&quot;* </span></span></span></div> <span style="line-height:16px">         in the personal store on the local computer. Therefore, it is unable to offer the STARTTLS SMTP<br style="">         verb for any connector with a FQDN parameter of mail.domainname.com.<br style="">         Verify the connector configuration and the installed certificates to make sure that there is<br style="">         a certificate with a domain name for every connector FQDN.&quot;</span> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px">* the value vairy - mail.hijinxx.com  or  exchange.hijinxx.com  </span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px">I ran &quot; get-reciveconnector | FL name, FQDN, ObjectClass &quot;  and got this:-</span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"> <div><br/></div> <div>Name        : Default EXCHANGE</div> <div>Fqdn        : exchange.hijinxx.com</div> <div>ObjectClass : {top, msExchSmtpReceiveConnector}</div> <div><br/></div> <div>Name        : Client EXCHANGE</div> <div>Fqdn        : exchange.iconasset.com</div> <div>ObjectClass : {top, msExchSmtpReceiveConnector}</div> <div><br/></div> <div>Name        : Default EXCH1</div> <div>Fqdn        : exch1.iconasset.com</div> <div>ObjectClass : {top, msExchSmtpReceiveConnector}</div> <div><br/></div> <div>Name        : Client EXCH1</div> <div>Fqdn        : exch1.iconasset.com</div> <div>ObjectClass : {top, msExchSmtpReceiveConnector}</div> <div><br/></div> <div>I Ran &quot; get-sendconnector | FL name, FQDN, ObjectClass&quot; and got this :-</div> <div><br/></div> <div> <div>Name        : Internet Send connector for Hinixx</div> <div>Fqdn        : mail.hijinxx.com</div> <div>ObjectClass : {top, msExchConnector, mailGateway, msExchRoutingSMTPConnector}</div> <div><br/></div> <div><br/></div> <div>I Ran &quot; get-exchangecertificate | FL *&quot; and got this :- </div> <div><br/></div> <div> <div><br/></div> <div>AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, Syst</div> <div>                       em.Security.AccessControl.CryptoKeyAccessRule}</div> <div>CertificateDomains   : {www.hijinxx.com, autodiscover.hijinxx.com, mail.hijinxx</div> <div>                       .com, owa.hijinxx.com}</div> <div>CertificateRequest   :</div> <div>IisServices          : {IIS://exchange/W3SVC/1}</div> <div>IsSelfSigned         : False</div> <div>KeyIdentifier        : 4AE17E5BE79F354050F5C8DBC2225FB8380FB2D6</div> <div>RootCAType           : ThirdParty</div> <div>Services             : IIS</div> <div>Status               : Valid</div> <div>PrivateKeyExportable : True</div> <div>Archived             : False</div> <div>Extensions           : {System.Security.Cryptography.Oid, System.Security.Crypt</div> <div>                       ography.Oid, System.Security.Cryptography.Oid, System.Se</div> <div>                       curity.Cryptography.Oid, System.Security.Cryptography.Oi</div> <div>                       d, System.Security.Cryptography.Oid}</div> <div>FriendlyName         : www.hijinxx.com</div> <div>IssuerName           : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>NotAfter             : 27/11/2009 15:36:49</div> <div>NotBefore            : 26/11/2008 15:36:49</div> <div>HasPrivateKey        : True</div> <div>PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider</div> <div>PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey</div> <div>RawData              : {48, 130, 3, 147, 48, 130, 2, 252, 160, 3, 2, 1, 2, 2, 3</div> <div>                       , 10...}</div> <div>SerialNumber         : 0A3ADF</div> <div>SubjectName          : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>SignatureAlgorithm   : System.Security.Cryptography.Oid</div> <div>Thumbprint           : 033E215D88EDA9FF09708D298ED4800DE5A5EBC2</div> <div>Version              : 3</div> <div>Handle               : 487307936</div> <div>Issuer               : OU=Equifax Secure Certificate Authority, O=Equifax, C=US</div> <div>Subject              : CN=www.hijinxx.com, OU=Domain Control Validated - QuickS</div> <div>                       SL Premium(R), OU=See www.geotrust.com/resources/cps (c)</div> <div>                       08, OU=GT35933476, O=www.hijinxx.com, C=CH</div> <div><br/></div> <div>AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, Syst</div> <div>                       em.Security.AccessControl.CryptoKeyAccessRule, System.Se</div> <div>                       curity.AccessControl.CryptoKeyAccessRule}</div> <div>CertificateDomains   : {exchange, exchange.iconasset.com}</div> <div>CertificateRequest   :</div> <div>IisServices          : {}</div> <div>IsSelfSigned         : True</div> <div>KeyIdentifier        : 09136A25E4BF5B347363D4EDB6CE5DC95D768594</div> <div>RootCAType           : None</div> <div>Services             : IMAP, POP, SMTP</div> <div>Status               : Valid</div> <div>PrivateKeyExportable : False</div> <div>Archived             : False</div> <div>Extensions           : {System.Security.Cryptography.Oid, System.Security.Crypt</div> <div>                       ography.Oid, System.Security.Cryptography.Oid, System.Se</div> <div>                       curity.Cryptography.Oid}</div> <div>FriendlyName         : Microsoft Exchange</div> <div>IssuerName           : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>NotAfter             : 24/11/2009 18:34:48</div> <div>NotBefore            : 24/11/2008 18:34:48</div> <div>HasPrivateKey        : True</div> <div>PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider</div> <div>PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey</div> <div>RawData              : {48, 130, 3, 18, 48, 130, 1, 250, 160, 3, 2, 1, 2, 2, 16</div> <div>                       , 145...}</div> <div>SerialNumber         : 910F43E1C1849EB94EB39EE383F39E9F</div> <div>SubjectName          : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>SignatureAlgorithm   : System.Security.Cryptography.Oid</div> <div>Thumbprint           : FC5E40C751DC96565E6D2DDBD2016DA8AFADEA73</div> <div>Version              : 3</div> <div>Handle               : 487308080</div> <div>Issuer               : CN=exchange</div> <div>Subject              : CN=exchange</div> <div><br/></div> <div>AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, Syst</div> <div>                       em.Security.AccessControl.CryptoKeyAccessRule, System.Se</div> <div>                       curity.AccessControl.CryptoKeyAccessRule}</div> <div>CertificateDomains   : {exchange, exchange.iconasset.com}</div> <div>CertificateRequest   :</div> <div>IisServices          : {}</div> <div>IsSelfSigned         : True</div> <div>KeyIdentifier        : CBC442EACDF41C78558F3D348E2F39B209C0FC99</div> <div>RootCAType           : None</div> <div>Services             : IMAP, POP, SMTP</div> <div>Status               : Valid</div> <div>PrivateKeyExportable : False</div> <div>Archived             : False</div> <div>Extensions           : {System.Security.Cryptography.Oid, System.Security.Crypt</div> <div>                       ography.Oid, System.Security.Cryptography.Oid, System.Se</div> <div>                       curity.Cryptography.Oid}</div> <div>FriendlyName         : Microsoft Exchange</div> <div>IssuerName           : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>NotAfter             : 01/10/2009 20:49:13</div> <div>NotBefore            : 01/10/2008 20:49:13</div> <div>HasPrivateKey        : True</div> <div>PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider</div> <div>PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey</div> <div>RawData              : {48, 130, 3, 18, 48, 130, 1, 250, 160, 3, 2, 1, 2, 2, 16</div> <div>                       , 16...}</div> <div>SerialNumber         : 1028BCB0B51E0FBF49C48802C3D88552</div> <div>SubjectName          : System.Security.Cryptography.X509Certificates.X500Distin</div> <div>                       guishedName</div> <div>SignatureAlgorithm   : System.Security.Cryptography.Oid</div> <div>Thumbprint           : 022336C8CAD4ACB923B7BE9DC6769CBE3F6A6539</div> <div>Version              : 3</div> <div>Handle               : 475214208</div> <div>Issuer               : CN=exchange</div> <div>Subject              : CN=exchange</div> <div><br/></div> <div><br/></div> <div><br/></div> <div><br/></div> <div>What could the problem be? is it comunication between the Hub transport servers, as OWA and Outlook Anywhere work fine?</div> <div><br/></div> <div><br/></div> </div> </div> </span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div> <div><span style="line-height:16px"><br/></span></div>Thu, 10 Sep 2009 10:58:37 Z2009-09-16T18:22:13Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/b3af8bea-e53a-476a-83e8-47703acdb337http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/b3af8bea-e53a-476a-83e8-47703acdb337Anshul_Singlahttp://social.technet.microsoft.com/Profile/en-US/?user=Anshul_SinglaImplementing TLS to decrypt messages on Exchange Server 2007Hi,<br/> <br/> <br/> One of the banks that we deal with sends us emails that are encrypted with TLS. When we recieve the email, the actual email (the subject, body, etc.) comes as an attachment (.html). The subject matter is the same for every email which makes it difficult to identify a particular email. When you open the attachment in a browser, it automatically decrypts and you can see the contents of the mail. <br/> The solution that I am looking at is that allows us to see the contents of the email directly in outlook rather than as an attachment. The Technical staff at the Bank told me to implement TLS on my exchange server to resolve it. When I tried to buy a certificate from Thawte they said that it will not help and instead I should use a certificate for the client computer only. That did not help either.<br/> I would really appreciate any help.<br/> Thanks in advance.<hr class="sig">Regards, AnshulWed, 09 Sep 2009 14:44:40 Z2009-09-14T05:04:09Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/a5d5c6ee-4088-4bef-9a90-1e0fb5fb5dabhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/a5d5c6ee-4088-4bef-9a90-1e0fb5fb5dabArun Khatrihttp://social.technet.microsoft.com/Profile/en-US/?user=Arun%20KhatriExchagne Certificate problemDear All,<br/><br/>I have a exchange server which is using internal CA for certificate. Could anyone help me that how can I import the same certificate if certificate problem is there.<br/><br/>thanks<br/>arunMon, 07 Sep 2009 18:12:32 Z2009-09-10T19:56:33Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/9555f3e5-f60f-4f29-a065-c465a87db74dhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/9555f3e5-f60f-4f29-a065-c465a87db74db1212621http://social.technet.microsoft.com/Profile/en-US/?user=b121262110104 errors on edge server.<p>Hi Everyone,<br/><br/>After re-newing a smpt edge certificate i am getting the folowing errors. This is the process I did on both hub and edge servers.</p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">On EDGE101</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><code><span style="font-size:10pt">New-ExchangeCertificate</span></code></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><code><span style="font-size:10pt"> </span></code></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">Generate new EdgeSubscription on EDGE101</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">New-EdgeSubscription -filename &quot;C:\Edge101_Sep2009.xml&quot; -CreateInternetSendConnector $true -site &quot;Default-First-Site-Name&quot;</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">Copy File c:\edge101_sep2009.xml to HUB103</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">On HUB103</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">remove the edge subscription from HUB101</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">remove-edgesubscription -identity edge101.cosmac.com</span></p> <p class=MsoNormal style="text-indent:36pt;margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">Create Connector for EDGE101</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">New-EdgeSubscription -filename &quot;C:\Edge101_Sep2009.xml&quot; -CreateInternetSendConnector $true -site &quot;Default-First-Site-Name&quot;</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">Start-EdgeSynchronization</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">To Test Edge</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:Calibri;font-size:small">Test-EdgeSynchronization -VerifyRecipient </span><a href="mailto:sysadmin@cosmac.com"><span style="font-family:Calibri;font-size:small">sysadmin@cosmac.com</span></a></p> <p><br/><br/>Event Type: Error<br/>Event Source: MSExchange EdgeSync<br/>Event Category: Synchronization <br/>Event ID: 10104<br/>Date:  9/8/2009<br/>Time:  8:29:08 PM<br/>User:  N/A<br/>Computer: HUB103<br/>Description:<br/>Microsoft Exchange couldn't match certificate when contacting EDGE101.ihostexchange.net. The connection was stopped.</p> <p>Event Type: Error<br/>Event Source: MSExchange EdgeSync<br/>Event Category: Topology <br/>Event ID: 1024<br/>Date:  9/8/2009<br/>Time:  8:34:09 PM<br/>User:  N/A<br/>Computer: HUB103<br/>Description:<br/>The connection to the ADAM instance of the Edge Transport server failed with exception &quot;The LDAP server is unavailable.&quot;. This could be caused by a failure to resolve the Edge Transport server name EDGE101.ihostexchange.net in DNS, a failure when trying to connect to port 50636 on Edge Transport server EDGE101.ihostexchange.net, network connectivity issues, an invalid certificate, or an expired subscription. Verify the configurations of your network and server.</p> <p> </p>Wed, 09 Sep 2009 00:40:44 Z2009-09-18T08:51:26Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/9d144d3f-69fa-45e5-868f-355f0f865a2fhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/9d144d3f-69fa-45e5-868f-355f0f865a2fArun Khatrihttp://social.technet.microsoft.com/Profile/en-US/?user=Arun%20KhatriExchange 2007 Certificate<p>Dear all,</p> <p>I have exchange server 2007 having internal windows server 2003 CA. Somebody replace my exchange certificate by selfsigned certificate so that we have a problem of accessing mail from outside and PDA also. I have checked with CA then there is my certificate with name of mail.example.com with expiry date 2013.</p> <p>Can anyone suggest that how can i again restore that certificate?</p>Tue, 08 Sep 2009 01:54:56 Z2009-09-21T02:20:04Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/11626cf5-b8da-4032-8106-cde22bfdb4fahttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/11626cf5-b8da-4032-8106-cde22bfdb4faGFARKROCKhttp://social.technet.microsoft.com/Profile/en-US/?user=GFARKROCKExchange 2007 TLS - Can the sending server initiate a STARTTLS? (Must issue a STARTTLS command first)Exchange 2007 TLS - Can the sending server initiate a STARTTLS? <br/>We are trying to setup TLS between 2 organizations server to server. We have Exchange 2007 and the receiving party is using a TLS gateway that expects a STARTTLS sent to it.<br/>From what I can see, my Exchange 2007 send connector is expecting to be offered a 250-STARTTLS from the receiving end.  <br/>Is there a way to force my send connector to issue a STARTTLS command first?Fri, 04 Sep 2009 16:45:45 Z2009-09-11T09:11:39Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/6ed53b82-645a-406f-a9ba-0a4c756cd9e7http://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/6ed53b82-645a-406f-a9ba-0a4c756cd9e7laminihttp://social.technet.microsoft.com/Profile/en-US/?user=laminiNo Anonymous Access or Accounts in SSL OWA - Exchange 2003Due to policies, &quot;Anonymous Access&quot; is not an option on the IIS webserver.  The Anonymous Accounts IUSR_servername and IWAM_servername must have real passwords defined.  <br/> <br/> Can i just reset the password for these accounts from AD, and place those same passwords into IIS&gt;ExchWeb (or is this wrong setting for OWA), and assume it will not break Exchange and OWA functionality (and anything else it might hinder)?  <br/> <br/> I will find out soon, but checking if someone has the answer before I spend the time repeating a known process<br/> <br/> Many thanks!Thu, 03 Sep 2009 10:53:01 Z2009-09-03T23:23:30Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/1aabf142-3ed9-4046-b98f-8d2f2980fcdfhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/1aabf142-3ed9-4046-b98f-8d2f2980fcdfcthuhttp://social.technet.microsoft.com/Profile/en-US/?user=cthuHow to disable Exchange 2007 SMTP X-ANONYMOUSTLS encryption?<br>Hi Experts,<br>We are trying to disable Exchange 2007 TLS encryption for the SMTP traffic between Exchanger 2007 servers.<br><br>Based on the step 3 of following document:<br>If the <b>msExchServerInternalTLSCert</b> attribute cannot be read or if the value is <tt>null</tt>, Microsoft Exchange does not advertise X-ANONYMOUSTLS and no certificate is loaded.<br><br>http://technet.microsoft.com/en-us/library/bb430790.aspx<br><br>Don't know if we can disable Exchange 2007 SMTP TLS encryption by changing the <b>msExchServerInternalTLSCert</b> attribute to null on Exchange 2007 servers.<br>Also, don't know the side effects of chaning the <b>msExchServerInternalTLSCert</b> attribute to null on Exchange 2007 servers.<br><br>Appreciate your help!<br><br>Thanks!<br><br>CT<br>chuntaihu@yahoo.com<br><br><tt></tt>Wed, 23 Jan 2008 10:53:03 Z2009-09-03T14:23:10Zhttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/f180b8a7-c98a-4a2d-bb7d-1587fb560b0chttp://social.technet.microsoft.com/Forums/en-US/exchangesvrsecuremessaging/thread/f180b8a7-c98a-4a2d-bb7d-1587fb560b0cRoyroy168http://social.technet.microsoft.com/Profile/en-US/?user=Royroy168Disable TLS<p align=left><font face=Arial size=2>Hi Everyone,</font></p> <p align=left> </p> <p align=left>I would like to disable TLS, as I would like to disable the encryption between Hub Transport server for some reason.</p> <p align=left> </p> <p align=left>1. What is the best approach if I have three Hub Transport servers?</p> <p align=left> </p> <p align=left>Mailbox Server A using Hub Transport Server A</p> <p align=left>Mailbox Server B using Hub Transport Server B</p> <p align=left>Mailbox Server C using Hub Transport Server C</p> <p align=left> </p> <p align=left>2. Do have have to disable both &quot;Send Connector&quot; and &quot;Receive Connector&quot; on all Hub Transport servers?</p> <p align=left>3. What about Mailbox Servers, do I have to disable it on all Mailbox servers as well?</p> <p align=left>4. Is there any security concern?</p> <p align=left>5. Actually the reason I am doing it is because there is a appliance, &quot;riverbed&quot; to save traffic between servers, however, hub transport encrypted all traffic between servers using TLS.  As the result, the appliance cannot decrypt it to save traffic, is there a way to use it with TLS enabled?</p> <p align=left>6. If not, is there another way to use it more securely?</p> <p align=left> </p> <p align=left> </p> <p align=left>Thanks</p>Mon, 31 Mar 2008 17:20:03 Z2009-09-03T14:29:28Z