Unanswered 2003 to 2010 coexist: Outlook Anywhere Connectivity failure

  • Monday, January 09, 2012 8:31 PM
     
     

    At this point based on the 2010 deployment assitant, I have only installed CAS so far.  OWA seems to work fine.  But, the Outlook Anywhere Connectivity fails.

    My company name is contoso123 but we made our internal domain name contoso.com cause it was shorter.  We receive emails for both domains.  In my 2003 environment we had our cert listed as mail.contoso123.com which i know is not 100% standard since our internal domain was contoso.com but it all worked just fine anyway.  I guess 2010 just doesnt like that set up.  

    So, today I just finished updating my cert as:

    mail.contoso123.com

    with SANs:

    mail.contoso.com

    autodiscover.contoso123.com

    autodiscover.contoso.com

    legacy.contoso123.com

    legacy.contoso.com

    contoso123.com

    contoso.com

    And re-ran the connectivity test and it got farther than before but still an error at the end.  Here are the results:


     

All Replies

  • Monday, January 09, 2012 8:36 PM
     
     
    Attempting to test potential Autodiscover URL https://autodiscover.contoso123.com/AutoDiscover/AutoDiscover.xml
      Testing of this potential Autodiscover URL failed.
     
    Test Steps
     
    Attempting to resolve the host name autodiscover.internationalhospital.com in DNS.
      The host name resolved successfully.
     
    Additional Details
      IP addresses returned: x.x.x.x
    Testing TCP port 443 on host autodiscover.internationalhospital.com to ensure it's listening and open.
      The port was opened successfully.
    Testing the SSL certificate to make sure it's valid.
      The certificate passed all validation requirements.
     
    Test Steps
     
    ExRCA is attempting to obtain the SSL certificate from remote server autodiscover.contoso123.com on port 443.
      ExRCA successfully obtained the remote SSL certificate.
     
    Additional Details
      Remote Certificate Subject: CN=mail. contoso123 .com, OU=x, O=x, L=x, S=x, C=US, Issuer: CN=Entrust Certification Authority - L1C, OU="(c) 2009 Entrust, Inc.", OU=www.entrust.net/rpa is incorporated by reference, O="Entrust, Inc.", C=US.
    Validating the certificate name.
      The certificate name was validated successfully.
     
    Additional Details
      Host name autodiscover. contoso123 .com was found in the Certificate Subject Alternative Name entry.
    Certificate trust is being validated.
      The certificate is trusted and all certificates are present in the chain.
     
    Test Steps
     
    ExRCA is attempting to build certificate chains for certificate CN=mail.contoso123 .com, OU=x, O=x, L=x, S=x, C=US.
      One or more certificate chains were constructed successfully.
     
    Additional Details
      A total of 2 chains were built. The highest quality chain ends in root certificate CN=Entrust.net Certification Authority (2048), OU=(c) 1999 Entrust.net Limited, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), O=Entrust.net.
    Analyzing the certificate chains for compatibility problems with versions of Windows.
      Potential compatibility problems were identified with some versions of Windows.
     
    Additional Details
      ExRCA can only validate the certificate chain using the Root Certificate Update functionality from Windows Update. Your certificate may not be trusted on Windows if the "Update Root Certificates" feature isn't enabled.
    Testing the certificate date to confirm the certificate is valid.
      Date validation passed. The certificate hasn't expired.
     
    Additional Details
      The certificate is valid. NotBefore = 1/9/2012 5:40:36 PM, NotAfter = 1/3/2013 8:10:43 AM
    Checking the IIS configuration for client certificate authentication.
      Client certificate authentication wasn't detected.
     
    Additional Details
      Accept/Require Client Certificates isn't configured.
    Attempting to send an Autodiscover POST request to potential Autodiscover URLs.
      Autodiscover settings weren't obtained when the Autodiscover POST request was sent.
     
    Test Steps
     
    ExRCA is attempting to retrieve an XML Autodiscover response from URL https://autodiscover. contoso123 .com/AutoDiscover/AutoDiscover.xml for user user@ contoso123 .com.
      ExRCA failed to obtain an Autodiscover XML response.
       <label for="testSelectWizard_ctl12_ctl06_ctl00_ctl00_ctl01_ctl04_ctl00_tmmArrow">Tell me more about this issue and how to resolve it</label>
     
    Additional Details
      An error message was returned from the Autodiscover service
    XML response:
    <?xml version="1.0"?>
    <Autodiscover xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006">
    <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a">
    <Error Time="12:48:56.4114262" Id="722390025">
    <ErrorCode>503</ErrorCode>
    <Message>Client mailboxes must be on Exchange Server 2010 or later.</Message>
    <DebugData />
    </Error>
    </Response>
    </Autodiscover>
  • Thursday, January 12, 2012 8:14 PM
     
     

    Can you send the entire error at the bottom of the image you attached?  The right hand is cut off.  Your error code is 503 and it's referring to "Client mailboxes must be o" and it cuts off.

    What is the rest of the error message?


    Travis J. Moore Exchange Senior Engineer Planet Technologies | www.Go-Planet.com