<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Karsten Palmvig's blog : OC</title><link>http://blogs.technet.com/kpalmvig/archive/tags/OC/default.aspx</link><description>Tags: OC</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Troubleshoot: Office Communicator problem verifying certificate</title><link>http://blogs.technet.com/kpalmvig/archive/2009/01/07/troubleshoot-office-communicator-problem-verifying-certificate.aspx</link><pubDate>Wed, 07 Jan 2009 20:38:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3177536</guid><dc:creator>kpalmvig</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/kpalmvig/comments/3177536.aspx</comments><wfw:commentRss>http://blogs.technet.com/kpalmvig/commentrss.aspx?PostID=3177536</wfw:commentRss><description>&lt;p&gt;You encounter the following error when trying to connect to the pool with Office Communicator:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom: 0px; border-left: 0px; border-top: 0px; border-right: 0px" border="0" alt="OC-certificate-error" src="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/TroubleshootOfficeCommunicatorproblemver_10624/OC-certificate-error_fb8fac62-1e9f-4d7b-8bed-a01afbcab2f9.jpg" width="509" height="208" /&gt; &lt;/p&gt;  &lt;p&gt;This is caused by the certificate on the server not matching the host name you are trying to connect to. Typically this is because the _sipinternaltls SRV record in DNS is pointing to a physical OCS server instead of the pool name and the certificate on the server is (rightfully) issued for the pool name.&lt;/p&gt;  &lt;p&gt;Adding Subject Alternate Names in the certificate for the physical server(s) is not the right approach to solve this issue.&lt;/p&gt;  &lt;p&gt;After correcting the SRV record, remember to flush the DNS cache on the client.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3177536" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/OC/default.aspx">OC</category></item></channel></rss>