Symptoms
Consider the following scenario:
-
You deploy an on-premises Microsoft Lync Server 2013 environment that uses an internal root certification authority (CA).
-
Active Directory Federation Services (ADFS) servers are deployed on-premises in the environment.
-
A user in the environment has an Exchange mailbox that is enabled for the Exchange Online service.
-
The user signs in to Lync Phone Edition on a telephone that is connected to a computer in the environment by using a USB cable.
In this scenario, the user cannot use the features that are provided by Exchange integration. For example, the user cannot check call logs and voice mails on the telephone.
Cause
This issue occurs because Transport Layer Security (TLS) fails when Lync Phone Edition tries to obtain a token by contacting ADFS to authenticate to the Exchange Online service.
Resolution
To resolve this issue, install one of the following cumulative updates:
-
2918033 Description of the cumulative update for Lync Phone Edition for Aastra 6721ip and Aastra 6725ip: January 2014
-
2918035 Description of the cumulative update for Lync Phone Edition for HP 4110 and HP 4120: January 2014
-
2918038 Description of the cumulative update for Lync Phone Edition for Polycom CX500, Polycom CX600, and Polycom CX3000 telephones: January 2014
-
2918036 Description of the cumulative update for Lync Phone Edition for Polycom CX700 and LG-Nortel IP Phone 8540 telephones: January 2014
After one of the cumulative updates is installed, the following new root CAs will be supported on the telephone that is running Lync Phone Edition:
Vendor |
Certificate name |
Expiry date |
Key length |
---|---|---|---|
DigiCert Inc |
DigiCert Assured ID Root CA |
11/9/2031 |
2048 |
DigiCert Inc |
DigiCert Global Root CA |
11/9/2031 |
2048 |
DigiCert Inc |
DigiCert High Assurance EV Root CA |
11/9/2031 |
2048 |
Entrust |
Entrust Root Certification Authority |
11/27/2026 |
2048 |
Entrust |
Entrust.net Certification Authority (2048) |
7/24/2029 |
2048 |