none
Invalid Canary error message using ECP

    Question

  • Hi,

    I'm on Exchange 2010 SP1 and my users are receiving an error message, "Invalid Canary", when they click on the Options link from OWA or when they're within ECP, they click on Settings and modify a setting.  

    Does anyone have any pointers?

    Monday, January 03, 2011 8:44 PM

Answers

  • It is a bug. If you take a look at the second link, you'll see Dan Rogers of Microsoft talking about "a  planned fix that is scheduled currently to ship before the end of this calendar year 2010." Now Pedro-SHI says: "I had opened a case with Microsoft on this and apparently it will be fixed in the next rollup. They better, this is flooding the event viewer and it is difficult to see anything legit between these events."

    According to You had me at EHLO, Update Rollup 3 for Exchange Server 2010 Service Pack 3 is currently scheduled to release in February
    http://msexchangeteam.com/archive/2010/12/14/457194.aspx

    The canary was introduced in order to counter cross-site script attacks. It is a string which is used continuously between client and server in order to counter 'man in the middle attacks'. Jaap Wesselius, Exchange MVP, goes more in to detail explaining how it works, albeit in Dutch; however, the screen shots should be clear enough.


    MCTS: Messaging | MCSE: S+M | Small Business Specialist
    • Marked as answer by jimbravo Friday, January 14, 2011 10:41 PM
    Tuesday, January 04, 2011 5:48 PM

All replies

  • I haven't seen it the way you describe. However it is flooding the event logs and has to be disabled when using SCOM 2007 R2 with the Exchange 2010 MP. It's a bug related to the Test-ECPConnectivity cmdlet. Was supposed to be fixed by the end of last year. Still there with Exchange 2010 SP1 RU2. (The last link is in Dutch, but should give an idea.)

    Tuesday, October 26, 2010
    Exchange 2010 SP1: a known issue, a canary and flip flopping…
    http://thoughtsonopsmgr.blogspot.com/2010/10/exchange-2010-sp1-known-issue-canary.html

    Invalid Canary
    http://social.technet.microsoft.com/Forums/en-US/operationsmanagermgmtpacks/thread/209af469-6adc-42db-96fb-4b4afdb69897

    Kanarie (Canary) in Exchange 2010
    http://ucug.nl/blogs/jaapwess/archive/2010/09/01/kanarie-canary-in-exchange-2010.aspx


    MCTS: Messaging | MCSE: S+M | Small Business Specialist
    Monday, January 03, 2011 10:25 PM
  • We don't have SCOM in the environment and I don't know Dutch.  If you know Dutch, could you detail a summary of the resolution?  Or am I better calling MS?
    Tuesday, January 04, 2011 4:59 PM
  • It is a bug. If you take a look at the second link, you'll see Dan Rogers of Microsoft talking about "a  planned fix that is scheduled currently to ship before the end of this calendar year 2010." Now Pedro-SHI says: "I had opened a case with Microsoft on this and apparently it will be fixed in the next rollup. They better, this is flooding the event viewer and it is difficult to see anything legit between these events."

    According to You had me at EHLO, Update Rollup 3 for Exchange Server 2010 Service Pack 3 is currently scheduled to release in February
    http://msexchangeteam.com/archive/2010/12/14/457194.aspx

    The canary was introduced in order to counter cross-site script attacks. It is a string which is used continuously between client and server in order to counter 'man in the middle attacks'. Jaap Wesselius, Exchange MVP, goes more in to detail explaining how it works, albeit in Dutch; however, the screen shots should be clear enough.


    MCTS: Messaging | MCSE: S+M | Small Business Specialist
    • Marked as answer by jimbravo Friday, January 14, 2011 10:41 PM
    Tuesday, January 04, 2011 5:48 PM
  • Hi jimbravo,

    Sure, per my known, it maybe resolved in the new rollup.
    You also could call MS for the exactly informaton.

    Regards!
    Gavin
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Thursday, January 06, 2011 7:47 AM
  • Hi there,

     

    I have rollupdate 2 applied to my exchange 2010 sp1 and I still get this "Invalid canary" error when I try to access my ecp from the internet facing CAS proxy server. When I access the same site from locally just specifing https://<internal server name>/ecp there is no error.


    Ashwani Ram MCSE
    Friday, January 07, 2011 3:03 AM
  • Hi Bulare,

    Sure, I mean the newer than rollup 2. :)

    Regards!
    Gavin
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Friday, January 07, 2011 3:13 AM
  • Called MS Support and they confirmed this is a bug and the fix will be included in the release of Rollup 3.
    Friday, January 14, 2011 10:42 PM
  • Any idea when rollup 3 is coming out?
    Ashwani Ram MCSE
    Saturday, April 09, 2011 2:33 AM
  • Change capital "ECP" to lowercase "ecp" and the issue is resolved. SP1 sometimes changes the case which breaks the link and makes it have a canary.
    • Proposed as answer by Danofre Friday, August 19, 2011 5:53 PM
    Friday, August 19, 2011 2:48 PM
  • Change capital "ECP" to lowercase "ecp" and the issue is resolved. SP1 sometimes changes the case which breaks the link and makes it have a canary.

    I too had the 'invalid canary' message but when attempting as the administrator to manage another users account changing from upper case ECP resolved the issue for me.
    Monday, February 06, 2012 9:07 AM