<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Karsten Palmvig's blog : UM</title><link>http://blogs.technet.com/kpalmvig/archive/tags/UM/default.aspx</link><description>Tags: UM</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Troubleshoot: Why are call notifications and voice mails not showing on my Tanjay?</title><link>http://blogs.technet.com/kpalmvig/archive/2008/01/20/troubleshoot-why-are-call-notifications-and-voice-mails-not-showing-on-my-tanjay.aspx</link><pubDate>Sun, 20 Jan 2008 12:08:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2761952</guid><dc:creator>kpalmvig</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/kpalmvig/comments/2761952.aspx</comments><wfw:commentRss>http://blogs.technet.com/kpalmvig/commentrss.aspx?PostID=2761952</wfw:commentRss><description>&lt;p&gt;If you have a Office Communicator Phone Edition (aka. Tanjay) device, you might be wondering why your incoming, outgoing and missed calls as well as voice mails are not showing up in the lists on the device.&lt;/p&gt;  &lt;p&gt;For the integration to work, the Tanjay needs to access your mailbox and for this to work it needs to be able to resolve the autodiscover.domain.ext for your domain to an internal server.&lt;/p&gt;  &lt;p&gt;So make sure you have published your autodiscover properly in your internal DNS, mapping to your Client Access Server(s).&lt;/p&gt;  &lt;p&gt;The Exchange 2007 Client Access Server(s) hosting the Autodiscover service must have the autodiscover.domain.ext as a SAN (Subject Alternate Name) in the certificate assigned to the web site hosting the Autodiscover service. &lt;/p&gt;  &lt;p&gt;&lt;em&gt;(Refer to my post on voice mails not submitted to HUB Transport to see syntax for requesting a certificate with SAN's)&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Restart the Tanjay for it to pick up the changes faster.&lt;/p&gt;  &lt;p&gt;Bonus information: To play voice mails on your Tanjay; VoIP security on your Exchange 2007 UM Dial Plan must be set to &amp;quot;Secured&amp;quot;.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2761952" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/kpalmvig/archive/tags/UM/default.aspx">UM</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Phone/default.aspx">Phone</category></item><item><title>How To: Build an OCS and UM lab with phone integration</title><link>http://blogs.technet.com/kpalmvig/archive/2008/01/03/how-to-build-an-ocs-and-um-lab-with-phone-integration.aspx</link><pubDate>Thu, 03 Jan 2008 14:56:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2706016</guid><dc:creator>kpalmvig</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/kpalmvig/comments/2706016.aspx</comments><wfw:commentRss>http://blogs.technet.com/kpalmvig/commentrss.aspx?PostID=2706016</wfw:commentRss><description>&lt;p&gt;To quickly set up a lab for testing phone integration you need at least three servers for OCS and Exchange roles. One additional server is needed for Active Directory and Certificate Authority.&lt;/p&gt;  &lt;p&gt;I would recommend using a 64-bit machine installed with Windows Server 2003 x64 and Virtual Server 2005 R2. Virtual Server can then host the Office Communication Server 2007 roles and even the Domain Controller if needed. Exchange Server 2007 will be installed on the host machine (all roles for this setup can co-exist on the same machine).&lt;/p&gt;  &lt;p&gt;Then you need a VOIP/SIP gateway, for this documentation I'll be referring to the Audiocodes MP-114 FXO SIP Gateway but other products with same capabilities exist. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; The Audiocodes MP-114 product is not supported for enterprise deployment of OCS, the setup described here is only for lab use. Virtualization of OCS2007 is not supported in a production environment.&lt;/p&gt;  &lt;p&gt;For this simple lab your existing desk phone will be handled by whatever PBX you have installed and the SIP gateway will &amp;quot;listen in&amp;quot; on a second line that the PBX has been configured to use for the same extension as your desk phone. You can also use a completely different extension for testing.&lt;/p&gt;  &lt;p&gt;A very high level diagram of the communication flow in the lab set up will look like this:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/OCS-UM-flow_2.jpg" target="_blank"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="105" alt="OCS-UM-flow" src="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/OCS-UM-flow_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;h4&gt;Configuring the SIP gateway&lt;/h4&gt;  &lt;p&gt;First you need to download the OCS compatible .ini file from &lt;a href="http://audiocodes.com/content.aspx?voip=2823" target="_blank"&gt;AudioCodes' web site&lt;/a&gt; - you need the &amp;quot;FXO (One-to-One option)&amp;quot; download for this setup.&lt;/p&gt;  &lt;p&gt;Follow the quick guide available on the same page for basic setup of the MP-114. (Default IP address of the device may be 10.1.10.10 - it was in my case).&lt;/p&gt;  &lt;p&gt;When configuring endpoint phone number, use your full phone number.&lt;/p&gt;  &lt;p&gt;I prefer to do as little phone number manipulation as possible in the MP-114 but you need to convert the incoming phone extension into a full E.164 compliant number so it will match your phone number in OCS.&lt;/p&gt;  &lt;p&gt;It is by far the easiest to do all your phone number normalization in OCS and just pass on the &amp;quot;finished&amp;quot; number to the MP-114, more about this in the Mediation Server section.&lt;/p&gt;  &lt;p&gt;Just let the MP-114 route all inbound calls to your number.&lt;/p&gt;  &lt;p&gt;As this is a test setup you may want your desk phone to ring a couple of times before your lab environment kicks in, this can be done by configuring the FXONumberOfRings under http://mp-114/AdminPage to the number of rings you want before the MP-114 reacts.&lt;/p&gt;  &lt;p&gt;A good way to see what happens when inbound calls are made is to monitor the ports on the main page of the administration interface. Click the port (Port 3 in this case as only FXO ports should be connected to a PBX), select port settings and then SIP. This way you can see if inbound calls are translated and routed properly (fields are only populated during a call).&lt;/p&gt;  &lt;p&gt;The MP-114 will allow you to connect an analog phone directly and use that for dialing in but it makes more sense to connect it to a PBX for testing.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;h4&gt;Install Mediation Server&lt;/h4&gt;  &lt;p&gt;Essential reading before starting is the &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=24e72dac-2b26-4f43-bba2-60488f2aca8d&amp;amp;displaylang=en" target="_blank"&gt;Enterprise Voice Planning and Deployment Guide&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;I assume that you already have an OCS2007 front end server running with client connectivity so just install the Mediation Server role on a different server using the OCS2007 Deployment Wizard.&lt;/p&gt;  &lt;p&gt;Configure listening IP address for both Communication Server and Gateway to the servers address. Leave location profile as &amp;quot;(None)&amp;quot; - we'll configure that later.&lt;/p&gt;  &lt;p&gt;Next Hop Connections: FQDN of your front end server and IP address of the SIP gateway (MP-114 in this scenario).&lt;/p&gt;  &lt;p&gt;Create a certificate for the the server from the same CA as you did for the front end server.&lt;/p&gt;  &lt;p&gt;Assign a Line URI telephone number to your users in E.164 format through the OCS2007 console or ADUC; select &amp;quot;Enable Enterprise Voice&amp;quot; and input the full phone number as: &amp;quot;tel:+4544890100&amp;quot; (this is an example number, use one that fits into your numbering scheme).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/UserOptions_2.jpg" target="_blank"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="244" alt="UserOptions" src="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/UserOptions_thumb.jpg" width="195" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;h4&gt;Configuring Exchange UM&lt;/h4&gt;  &lt;p&gt;Under Organization Configuration\Unified Messaging:&lt;/p&gt;  &lt;p&gt;Create a UM Dial Plan (Shell cmdlets are documented in the deployment guide so I'll show the GUI):&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/UM-dial-plan_4.jpg" target="_blank"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="213" alt="UM-dial-plan" src="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/UM-dial-plan_thumb_1.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Give the dial plan a name and use as many digits for extension as you desire.&lt;/p&gt;  &lt;p&gt;Add the dial plan to the UM server object under Server Configuration\Unified Messaging.&lt;/p&gt;  &lt;p&gt;Create a new UM Auto Attendant; simply name it AutoAttendant and select the dial plan you created before. Associate an extension number with your Auto Attendant that doesn't conflict with other numbers. Make sure you enable and speech enable the Auto Attendant by checking the two checkboxes at the bottom.&lt;/p&gt;  &lt;p&gt;Run the ExchUCUtil.ps1 script.&lt;/p&gt;  &lt;p&gt;This will set permissions on the Exchange Org and UM containers and add the OCS front end server as IP gateway for the UM server.&lt;/p&gt;  &lt;p&gt;Don't forget to enable users for UM... ;o)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;h4&gt;Configure Mediation Server&lt;/h4&gt;  &lt;p&gt;Run the Exchange UM Integration Utility (found under: C:\Program Files\Microsoft Office Communications Server 2007\Server\Support\OcsUMUtil.exe on your front end server)&lt;/p&gt;  &lt;p&gt;Press &amp;quot;Load Data&amp;quot;&lt;/p&gt;  &lt;p&gt;If the list shows your Exchange UM dial plan, press &amp;quot;Add&amp;quot; and select phone number defined in Exchange UM under phone number and &amp;quot;Auto-Attendant&amp;quot; under Contact Type.&lt;/p&gt;  &lt;p&gt;Press OK&lt;/p&gt;  &lt;p&gt;The tool will say that no matching location profile exists so lets go ahead and create one now:&lt;/p&gt;  &lt;p&gt;Right click the forest name in the OCS2007 console, select Properties; Voice Properties&lt;/p&gt;  &lt;p&gt;Add a new profile, using the name OcsUMUtil found.&lt;/p&gt;  &lt;p&gt;Add as many Normalization Rules to the profile as you need. This is very well documented in the deployment guide but a fast one to get you going:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Name: Local extension&lt;/p&gt;    &lt;p&gt;Phone pattern regular expression: ^([1-9]\d{3})$&lt;/p&gt;    &lt;p&gt;Translation pattern regular expression: +454489$1&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The pattern regular expression will look for any 4 digit number starting with 1-9 and pass it on to the translation as variable $1 - the translation will prefix it with +454489 (so it conforms to E.164 numbering this way OCS can match a 4 digit local extension to the full number you have configured on your OCS/UM users).&lt;/p&gt;  &lt;p&gt;Phone Usages and Policies are not very important for this small lab setup just assign &amp;quot;Default Usage&amp;quot; to &amp;quot;Default Policy&amp;quot;.&lt;/p&gt;  &lt;p&gt;In Routes, create a new route called &amp;quot;Default Route&amp;quot;, set the Target regular expression to &amp;quot;.*&amp;quot; to let all numbers that does not match an internal user to be routed. (You can set it to &amp;quot;^\+45&amp;quot; to only allow national calls, other country codes will then fail to route).&lt;/p&gt;  &lt;p&gt;Set the gateway address to your Mediation Server and select &amp;quot;Default Usage&amp;quot; under Phone usages.&lt;/p&gt;  &lt;p&gt;Assign the Location Profile to the Mediation Server object in the OCS2007 console.&lt;/p&gt;  &lt;p&gt;A very good tool to verify that your call routing is working is the Enterprise Voice Route Helper available for download in the &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=b9bf4f71-fb0b-4de9-962f-c56b70a8aecd&amp;amp;displaylang=en" target="_blank"&gt;Office Communications Server 2007 Resource Kit Tools&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Your OC client should look like this if phone integration is configured properly:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/OC-VoiceMail_2.jpg" target="_blank"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="188" alt="OC-VoiceMail" src="http://blogs.technet.com/blogfiles/kpalmvig/WindowsLiveWriter/HowToBuildanOCSandUMlabwithphoneintegrat_14926/OC-VoiceMail_thumb.jpg" width="240" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Enjoy...&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2706016" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/kpalmvig/archive/tags/UM/default.aspx">UM</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/How+To/default.aspx">How To</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/SIP/default.aspx">SIP</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/OCS/default.aspx">OCS</category></item><item><title>Troubleshoot: UM voice mails not submitted to Hub Transport</title><link>http://blogs.technet.com/kpalmvig/archive/2007/12/26/troubleshoot-um-voice-mails-not-submitted-to-hub-transport.aspx</link><pubDate>Thu, 27 Dec 2007 01:19:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2682385</guid><dc:creator>kpalmvig</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/kpalmvig/comments/2682385.aspx</comments><wfw:commentRss>http://blogs.technet.com/kpalmvig/commentrss.aspx?PostID=2682385</wfw:commentRss><description>&lt;p&gt;After you have set up the Exchange Server 2007 UM role in a lab or in production and want to test Auto Attendant functionality by leaving voice mails for one or more users, you may experience that the Auto Attendant plays the greeting and asks for your message but the user doesn't receive anything although everything seems fine.&lt;/p&gt;  &lt;p&gt;Voice mails are in fact recorded and will queue up in this directory: C:\Program Files\Microsoft\Exchange Server\UnifiedMessaging\voicemail&lt;/p&gt;  &lt;p&gt;This situation can be identified by the following warning in the Application Event log:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Lucida Console" size="1"&gt;Event Type:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Warning        &lt;br /&gt;Event Source:&amp;#160;&amp;#160;&amp;#160; MSExchange Unified Messaging         &lt;br /&gt;Event Category:&amp;#160; UMCore         &lt;br /&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1185         &lt;br /&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 17-12-2007         &lt;br /&gt;Time:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 16:32:06         &lt;br /&gt;User:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; N/A         &lt;br /&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &amp;lt;Servername&amp;gt;         &lt;br /&gt;Description:         &lt;br /&gt;The Unified Messaging server was unable to submit a message to Hub Transport server &amp;quot;&amp;lt;Servername&amp;gt;&amp;quot; because the following error occurred: The Unified Messaging server failed to authenticate to the SMTP server: The specified target is unknown or unreachable. &lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;There can be multiple reasons for this, some of these are listed below.&lt;/p&gt;  &lt;h4&gt;SPN's&lt;/h4&gt;  &lt;p&gt;If Service Principal Names (SPN) are not registered correctly for your Hub Transport Servers SMTP service, the UM service may fail to identify a usable receive connector and fail to deliver the voice mail.&lt;/p&gt;  &lt;p&gt;One scenario where SPN's are registered incorrectly is if receive connectors have been installed on multiple servers (e.g. if the Exchange Organization used to be Exchange Server 2003 and mailboxes and services were migrated to Exchange Server 2007).&lt;/p&gt;  &lt;p&gt;To verify that local SPN registration is correct, first run:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;setspn -L &amp;lt;Servername&amp;gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This will list the locally registered SPN's, there should be only two &amp;quot;&lt;strong&gt;SmtpSvc&lt;/strong&gt;&amp;quot; SPN's:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;SmtpSvc/SERVER      &lt;br /&gt;SmtpSvc/server.domain.ext&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The more likely situation is that another server that no longer has a receive connector installed still have a &amp;quot;&lt;strong&gt;SmtpSvc&lt;/strong&gt;&amp;quot; SPN registered.&lt;/p&gt;  &lt;p&gt;To search Active Directory for orphan SPN's, use LDP; connect and bind to AD and press Ctrl-S for the search dialog. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Base Dn: DC=domain,DC=ext      &lt;br /&gt;Filter: servicePrincipalName=smtpsvc*&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This will result in a list like this:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Getting 2 entries:      &lt;br /&gt;&amp;gt;&amp;gt; Dn: CN=OLDSERVER,CN=Computers,DC=domain,DC=ext       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 5&amp;gt; objectClass: top; person; organizationalPerson; user; computer;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; cn: OLDSERVER;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; distinguishedName: CN=OLDSERVER,CN=Computers,DC=domain,DC=ext;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; name: OLDSERVER;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; canonicalName: domain.ext/Computers/OLDSERVER;       &lt;br /&gt;&amp;gt;&amp;gt; Dn: CN=NEWSERVER,CN=Computers,DC=domain,DC=ext       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 5&amp;gt; objectClass: top; person; organizationalPerson; user; computer;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; cn: NEWSERVER;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; distinguishedName: CN=NEWSERVER,CN=Computers,DC=domain,DC=ext;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; name: NEWSERVER;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; canonicalName: domain.ext/Computers/NEWSERVER;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Now use ldp or adsiedit to further drill down on the OLDSERVER object, I find using adsiedit easier as it allows for instant editing if required. &lt;font color="#ff0000"&gt;If you're not familiar with editing directly on AD objects, get assistance from someone who is!&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;List the content of &lt;strong&gt;servicePrincipalName&lt;/strong&gt; and verify that no &lt;strong&gt;SmtpSvc&lt;/strong&gt; entry exists if no SMTP service is running on the machine and verify that only the servers' own name is listed for any SPN.&lt;/p&gt;  &lt;p&gt;After removing any faulty SPN registrations; restart the Microsoft Exchange Transport Service on your Hub Transport Server. Then restart Microsoft Exchange Unified Messaging to pick up voice mails in the queue.&lt;/p&gt;  &lt;h4&gt;Certificates&lt;/h4&gt;  &lt;p&gt;Exchange UM submits the mails with voice content by using TLS, therefore UM may be unable to authenticate to the receive connector on the Hub Transport Server if the servers use the self signed certificate that Exchange supplies upon installation.&lt;/p&gt;  &lt;p&gt;Verify what certificates are installed by running:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Get-ExchangeCertificate&lt;/strong&gt; | ft services,thumbprint,isselfsigned -auto&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The result will look somewhat like this:&lt;/p&gt;  &lt;p&gt;&lt;font face="Lucida Console" size="1"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Services Thumbprint&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; IsSelfSigned      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; -------- ----------&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ------------       &lt;br /&gt;IMAP, POP, UM, IIS, SMTP 1234567890ABCDEF1234567890ABCDEF12345678&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; True&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;As you can see the only existing certificate is self signed.&lt;/p&gt;  &lt;p&gt;Create new certificates for all Exchange Servers in the organization by running this cmdlet:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;New-ExchangeCertificate&lt;/strong&gt; -GenerateRequest -domainname &amp;lt;Server FQDN&amp;gt;, &amp;lt;Server NetBIOS name&amp;gt;[, Server Alias] -FriendlyName &amp;lt;Server FQDN&amp;gt; -privatekeyexportable:$true -keysize 1024 -path c:\certreq.txt&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Submit the request file to your internal CA (depending on your Public Key Infrastructure) and save the resulting certificate file as c:\certnew.cer&lt;/p&gt;  &lt;p&gt;Then import the certificate by running this cmdlet:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Import-ExchangeCertificate&lt;/strong&gt; -path c:\certnew.cer | &lt;strong&gt;Enable-ExchangeCertificate&lt;/strong&gt; -services IIS, POP, IMAP, UM, SMTP&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Verify again what certificates are installed with &lt;strong&gt;Get-ExchangeCertificate&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;The result should look like this:&lt;/p&gt;  &lt;p&gt;&lt;font face="Lucida Console" size="1"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Services Thumbprint&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; IsSelfSigned      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; -------- ----------&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ------------       &lt;br /&gt;IMAP, POP, UM, IIS, SMTP ABCDEF1234567890ABCDEF1234567890ABFDEF12&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;font size="1"&gt;&lt;font face="Lucida Console"&gt;&lt;font face="Lucida Console" size="1"&gt;False          &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; IMAP, POP, UM, SMTP 1234567890ABCDEF1234567890ABCDEF12345678&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;font face="Lucida Console" size="1"&gt;True&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;As you can see, you now have a non self signed certificate in the certificate store. Remove the self signed certificate by running:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Remove-ExchangeCertificate&lt;/strong&gt; 1234567890ABCDEF1234567890ABCDEF12345678&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Restart Microsoft Exchange Transport and Microsoft Exchange Unified Messaging services and verify if voice mails are delivered.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2682385" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/kpalmvig/archive/tags/UM/default.aspx">UM</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/SPN/default.aspx">SPN</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/kpalmvig/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item></channel></rss>