Error message when you import a third-party certificate into Exchange Server 2010: "The certificate status could not be determined because the revocation check failed"

Article translations Article translations
Article ID: 979694 - View products that this article applies to.
Expand all | Collapse all

SYMPTOMS

A valid third-party certificate is imported into a Microsoft Exchange Server 2010 Client Access server (CAS). Then, the following status message is displayed in the Exchange Management Console:
The certificate status could not be determined because the revocation check failed.
If you run the Get-ExchangeCertificate cmdlet in the Exchange Management Shell, you receive the following status for the third-party certificate:
Status: RevocationCheckFailure
However, if you click the Certificate Revocation List (CRL) link that is specified on the certificate, you can still access the third-party certificate through the Exchange server.

CAUSE

This issue occurs because Exchange Server 2010 uses Microsoft Windows HTTP Services (WinHTTP) to manage all HTTP and HTTPS traffic, and WinHTTP does not use the proxy settings that are configured for the Internet browser.

To view the WinHTTP proxy settings, at a command prompt, run the following command:
netsh winhttp show proxy

RESOLUTION

To resolve this issue, you must configure the WinHTTP proxy setting and the server FQDN in the WinHTTP bypass list.

Note If you do not configure both the proxy setting and the server FQDN in the WinHTTP bypass list, the Exchange Management Shell and the Exchange Management Console cannot contact the Remote PowerShell.

To resolve this issue, open a command prompt, type the following command, and then press ENTER:
netsh winhttp set proxy proxy-server="http=myproxy" bypass-list="*.host_name.com"
The myproxy placeholder represents the proxy server name, and host_name represents the Exchange Server 2010 host name.

REFERENCES

For more information about WinHTTP and about how to set the proxy on the Exchange 2010 server, visit the following Web pages:
Netsh Commands for Windows Hypertext Transfer Protocol (WINHTTP)

Configure Proxy Settings for WinHTTP

WinHttpDetectAutoProxyConfigUrl Function
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
260210 Description of WinSock Proxy Auto Detect support

Properties

Article ID: 979694 - Last Review: September 10, 2011 - Revision: 2.0
APPLIES TO
  • Microsoft Exchange Server 2010 Coexistence
  • Microsoft Exchange Server 2010 Enterprise
  • Microsoft Exchange Server 2010 Standard
Keywords: 
kbdigitalcertificates kbexpertiseinter kbtshoot kbsurveynew kbprb KB979694

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com