Warning message when you start Outlook 2007 and then connect to a mailbox that is hosted on an Exchange 2007-based server: "The name of the security certificate is invalid or does not match the name of the site"
SYMPTOMSWhen you start Microsoft Office Outlook 2007 and then connect to a mailbox that is hosted on a mailbox server that is running Microsoft Exchange Server 2007, you receive the following security warning message:
The name of the security certificate is invalid or does not match the name of the site.
Note The scenario that is described in this article only applies to Outlook clients that connect to Exchange from inside the local network. The scenario that is described in this article does not apply to remote Outlook clients that connect to Exchange by using Outlook Anywhere.CAUSEThis issue occurs if the following conditions are true:
https://NetBIOS_name.contoso.com/autodiscover/autodiscover.xml
This may differ from the host name that is used in the FQDN of the replacement certificate. For example, the replacement certificate may have an FQDN that resembles the following FQDN: mail.contoso.com This issue causes a name mismatch error to occur. Therefore, you receive the security warning message when you try to connect Outlook 2007 to the mailbox.
RESOLUTIONTo resolve this issue, modify the URLs for the appropriate Exchange 2007 components. To do this, follow these steps:
MORE INFORMATIONThe URL for the Autodiscover service is stored in the Service Connection Point object. By default, this URL references the internal FQDN of the CAS that is present when Autodiscover is installed. For example, the following URL is set: https://servername.contoso.local/autodiscover/autodiscover.xml
In this example, the FQDN references the internal namespace. Generally, this namespace differs from the externally-accessible namespace, such as mail.contoso.com. If the internal namespace differs from the external namespace, and if you cannot use a certificate that supports Subject Alternative Names, use the Set-ClientAccessServer task in Exchange Management Shell to modify the URL. In this scenario, you must modify the URL to point to the new location for Autodiscover. For example, use the following command to point to the new location for Autodiscover: Set-ClientAccessServer –AutodiscoverServiceInternalUri https://mail.contoso.com/autodiscover/autodiscover.xml
For more information about third-party certification authorities that provide certificates that support Subject Alternative Names, click the following article number to view the article in the Microsoft Knowledge Base:
929395 (http://support.microsoft.com/kb/929395/)
Unified Communications Certificate Partners for Exchange 2007 and for Communications Server 2007
APPLIES TO
| Article Translations
|

Back to the top
