<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx</link><description>Update 10/4/2007: Since this post has been published, we've updated the Exchange 2007 Autodiscover Service whitepaper to include this information. Please consult the whitepaper for most up-to-date information. 
 In Exchange 2007, we introduce the idea</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3406192</link><pubDate>Wed, 27 Aug 2008 23:04:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3406192</guid><dc:creator>VOLMan</dc:creator><description>Right On Alessandro Appiani! AutoDiscover is somebody's crack dream. I have been trying to get it to work correctly on my company's domain before I have to set it up for a customer. I have just gotten all of my Exchange customers on board with using an SSL period. I have 1 or 2 that won't spend the money. Many of my Exchange customers run Small Business Server and Exchange 2003. I can see me trying to explain this dual name SSL to mine and Microsoft's customers. I have never seen so many geeks blogging on one topic. Nobody is getting this one! I did not get why it wasn't working until I got into this blog. Now that I get why it is not working, I have got to say this is the same logic that said, &amp;quot;Let's hide file save as from them!&amp;quot; in Office 2007. Anybody developing these products with any business acumen?&lt;br&gt;&lt;br&gt;Whether you are new with Exchange like &amp;quot;Jim - Newbie&amp;quot; or have set up and maintained many Exchange Servers, her are my thoughts:&lt;br&gt;&lt;br&gt;- Many great new features in Exchange 2007&lt;br&gt;- Most companies I work with don't have separate Exchange Administrators. Breaking user management away from AD &amp;amp; going back to the 5.5 model is more complicated and difficult for me to explain to customers who wear Sys Admin caps when I am not on site.&lt;br&gt;- Who decided we all were command line freaks and no longer wanted effective GUI management interfaces?&lt;br&gt;- Like one blogger said, &amp;quot;Stop telling us how way cool Exchange 2007 is&amp;quot; and give us some outstanding straight forward &amp;quot;how to's&amp;quot; on the Knowledge Base.&lt;br&gt;- Fix this abortion called Autodiscover in Service Pack 2.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3406192" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3403141</link><pubDate>Thu, 07 Jun 2007 22:10:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3403141</guid><dc:creator>James Silliman</dc:creator><description>Digicert has one for $300 with a 30-day satisfaction. &amp;nbsp;I don't work for them :)&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3403141" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3403053</link><pubDate>Mon, 28 May 2007 07:53:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3403053</guid><dc:creator>Anonymous Coward</dc:creator><description>Who are some service providers that offer Subject Alternative Name certficiates? &amp;nbsp;Thawte won't do it. &amp;nbsp;The 3 that I'm aware of, Geotrust (which only offers 4 names), is 599/year, Entrust (10 names) is 599/year, and Verisign's Managed PKI services (unknown price). &amp;nbsp;&lt;br&gt;&lt;br&gt;Everything seems extremely costly. &amp;nbsp;&lt;br&gt;&lt;br&gt;From what I gather I need the following names:&lt;br&gt;&lt;br&gt;1) autodiscover.domain.com&lt;br&gt;2) mail.domain.com&lt;br&gt;3) autodiscover.domain.local&lt;br&gt;4) cas.domain.local&lt;br&gt;5) CASnetbiosname??&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3403053" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3403052</link><pubDate>Sun, 27 May 2007 18:15:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3403052</guid><dc:creator>Alessandro Appiani</dc:creator><description>Few comments about &amp;quot;autodiscover&amp;quot; to Exchange Architects and bright minds that did think that:&lt;br&gt;- autodiscover has a clear higher TCO than previous Exchange versions to publish Exchange Services to the Internet&lt;br&gt;- autodiscover architecture make Outlook 2003 a best-choice over Outlook 2007 for Outlook Anywhere (and Outlook 2007 is no more in Exchange CAL)&lt;br&gt;- it's simply unmanageable for a medium company hosting many internet mail domains inside the organization (every domain added requires certificate re-submission &amp;amp; web service reconfiguration)&lt;br&gt;- it's unbelievable that not implementing autodiscovery method (complex, costly, difficult to manage) make simple, robust &amp;amp; consolidated features of Outlook/Exchange like OOF, Calendaring &amp;amp; Meeting scheduling, ... no more usable from outside the company (eg: Outlook anywhere)&lt;br&gt;- it's unbelievable that an &amp;quot;autoconfiguration&amp;quot; method like autodiscover in my opinion is and should be, it's required even if Outlook client is already configured. The result is that without autodiscover in place outlook (anywhere) is working at 50%.&lt;br&gt;- it's unbelievable that &amp;quot;out-of-the-box&amp;quot; e2k7/o2k7 do LESS for the users (outside company) than e2k3/o2k3&lt;br&gt;&lt;br&gt;Information Technology is always getting more complex, and thinking in a complex way doesn't help to get things working. I doesn't understand why my outlook (anywhere) is able to send and receive mail, but not to synchronize GAL, place a meeting, setting Out-of-office, configuring Voice Mail...&lt;br&gt;&lt;br&gt;If I'm able to talk to a CAS to access Mailbox, AND Active Directory (for authentication &amp;amp; c.) why shouldn't I get FROM THAT WAY even configuration info for which Autodiscover is required?&lt;br&gt;Why CAS doesn't do for me the initial simple autodiscovery query getting the XML (in other words proxying autodiscover like it proxies other access request)? It seems so simple to me...someone could answer me? &lt;br&gt;&lt;br&gt;Thanks!&lt;br&gt;Alessandro&lt;br&gt;PS: It seems to me that you (Microsoft people) design a product with no respects for your users, and without historical memory of your products, often reinventing the wheel...am I wrong?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3403052" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3403046</link><pubDate>Fri, 25 May 2007 22:58:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3403046</guid><dc:creator>chuck2000</dc:creator><description>In an environment where you have multiple CAS servers in a site how should you approach installing a certificate. &amp;nbsp;Can you just have one regular 3rd party cert for the CAS server that is accessed from the internet for OWA. &amp;nbsp;Not sure how you would force clients to query a certain CAS in a site for outlook 2007 clients for FB. &amp;nbsp;Can you purchase SAN certificates for more then one server and still have overlapping domains. &amp;nbsp;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3403046" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3402917</link><pubDate>Tue, 22 May 2007 05:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3402917</guid><dc:creator>Jim</dc:creator><description>All set.&lt;br&gt;&lt;br&gt;Thanks&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3402917" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3402775</link><pubDate>Sat, 19 May 2007 15:43:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3402775</guid><dc:creator>Inspector71</dc:creator><description>I run into this problem after applying a cert from godaddy to my CAS box. I run the cmdlet below and all is well from what I can tell. Both OWA and Outlook 2007 clients connect with no certificate errors.&lt;br&gt;&lt;br&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;if you are using a commercial certificate from Verisign or &amp;nbsp;Godaddy &amp;nbsp;to work around it you can use the following CMDLET to update the SCP inside of the AD: Set-WebServicesVirtualDirectory -Identity &amp;quot;EWS*&amp;quot; -ExternalUrl &amp;quot;&lt;a rel="nofollow" target="_new" href="Https://mail.synergyps.com/EWS/Exchange.asmx&amp;quot;"&gt;Https://mail.synergyps.com/EWS/Exchange.asmx&amp;quot;&lt;/a&gt; -InternalUrl &amp;quot;Https:// mail.synergyps.com/EWS/Exchange.asmx&amp;quot;.- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; the previous command will update all of the services (OAB,Free/Busy,OOF,GAL) address, but if you are interested in updating the Autodiscovery SCP only you can use the following CMDLET: Set-ClientAccessServer -Identity CASserver1 -AutoDiscoverServiceInternalUri &lt;a rel="nofollow" target="_new" href="https://mail.synergyps.com"&gt;https://mail.synergyps.com&lt;/a&gt; this will allow you to use a commercial certificate along with your secure deployment of exchange 2007 and avoid the common errors most of the customers complained from when using AutoDiscovery service&lt;br&gt;&lt;br&gt;read more here&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://busbar.maktoobblog.com/?post=271192"&gt;http://busbar.maktoobblog.com/?post=271192&lt;/a&gt;&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3402775" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3402308</link><pubDate>Thu, 10 May 2007 00:01:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3402308</guid><dc:creator>Matthew Byrd</dc:creator><description>&lt;br&gt;Jim:
&lt;br&gt;
&lt;br&gt;I just now realized that some of the links were moved from their position in the document to the bottom of the document. &amp;nbsp;Here are the links to the Exchange 2007 Help file information for each of the sections:
&lt;br&gt;
&lt;br&gt;Multiple names in one certificate
&lt;br&gt;How to Configure SSL Certificates to Use Multiple Client Access Server Host Names
&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/aa995942.aspx"&gt;http://technet.microsoft.com/en-us/library/aa995942.aspx&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;Method 1: Multiple Certificates
&lt;br&gt;Deployment Considerations for the Autodiscover Service : &amp;nbsp;Using Multiple Sites for Internet Access to the Autodiscover Service
&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/aa997633.aspx"&gt;http://technet.microsoft.com/en-us/library/aa997633.aspx&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;Method 2: Http Referral
&lt;br&gt;Deployment Considerations for the Autodiscover Service : &amp;nbsp;Hosted Environments and the Autodiscover Service
&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/aa997633.aspx"&gt;http://technet.microsoft.com/en-us/library/aa997633.aspx&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;Also I will be posting more direct steps per your request at the following link:
&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.exchangeninjas.com/cascertificateconfig"&gt;http://www.exchangeninjas.com/cascertificateconfig&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;BOE:
&lt;br&gt;
&lt;br&gt;In response to your question about Exchange and Certs ... You have to run autodiscover with Certificates. &amp;nbsp;We will not allow it to work otherwise. &amp;nbsp;This is to help ensure the security of your users and your data.
&lt;br&gt;
&lt;br&gt;Jim:
&lt;br&gt;
&lt;br&gt;Is this an internal or External client? &amp;nbsp;Internal clients get their connection point from the SCP and in the log your should see:
&lt;br&gt;Attempting URL &lt;a rel="nofollow" target="_new" href="https://scp.company.com/autodiscover/autodiscover.xml"&gt;https://scp.company.com/autodiscover/autodiscover.xml&lt;/a&gt; found through SCP
&lt;br&gt;
&lt;br&gt;The Key there is:
&lt;br&gt;Found through SCP
&lt;br&gt;
&lt;br&gt;If it is an external client then it will ONLY connect to autodiscover on mydomain.com or autodiscover.mydomain.com ... outlook is Hard Coded to connect using only thoses domains.
&lt;br&gt;
&lt;br&gt;Hope this has addressed everyones questions
&lt;br&gt;-Matt
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3402308" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3402235</link><pubDate>Sun, 06 May 2007 07:59:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3402235</guid><dc:creator>Jim</dc:creator><description>Hello,&lt;br&gt;&lt;br&gt;I tried the wiki script - now for some reason the log from my outlook client shows that it is trying to go to - &lt;br&gt;Autodiscover to &lt;a rel="nofollow" target="_new" href="https://mydomain.com/autodiscover/autodiscover.xml"&gt;https://mydomain.com/autodiscover/autodiscover.xml&lt;/a&gt; starting&lt;br&gt;It needs to go to &lt;a rel="nofollow" target="_new" href="https://exchange.mydomain.com/autodiscover/autodiscover.xml"&gt;https://exchange.mydomain.com/autodiscover/autodiscover.xml&lt;/a&gt; - not sure how to fix it to what it was.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3402235" width="1" height="1"&gt;</description></item><item><title>re: Exchange 2007 Autodiscover and certificates</title><link>http://blogs.technet.com/b/exchange/archive/2007/04/30/exchange-2007-autodiscover-and-certificates.aspx#3402234</link><pubDate>Sun, 06 May 2007 07:48:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3402234</guid><dc:creator>boe</dc:creator><description>Is it possible to just run the server autodiscover without a cert requirement?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3402234" width="1" height="1"&gt;</description></item></channel></rss>