Problems with Autodiscover, Out of Office,
Free Busy, OWA and Outlook Anywhere
One of the most common issues I see has to do with certificates, so to start out we need to understand some things about certificates.
Certificates are used to encrypt traffic between exchange servers and clients.
There are 3 things that need to be true for a certificate to be valid.
- The name used to access the resource needs match the certificate exactly.
Example: If I connect to say owa with mail.mydomain.com then the certificate needs to also have mail.mydomain.com on it in either the subject or the subject alternate name field.
- The Certificate time must be valid
- The issuing Certificate Authority must be trusted by the client. (It needs to exist in the “Trusted Root Certificate Authorities)
Now that we have some VERY basic info about certificates.
The issues I see constantly are: Autodiscover, Out of Office, Free Busy and Outlook Anywhere miss-configuration.
- Not using a trusted certificate
- Solution: use a 3rd party cert provider
- The certificate name does not match the DNS name\s
- Solution: create a new cert request containing all the names used to access the server. Minimum of
- <InternalName>.domain.local (if using for internal systems also)
Example of a correct cert request:
- New-ExchangeCertificate -GenerateRequest -SubjectName “C=US, O=Org Name, CN=mail.domain.com” -domainname mail.domain.com, autodiscover.domain.com, servername, servername.domain.local -FriendlyName mail.domain.com -privatekeyexportable:$true -path c:\cert_myserver.txt
Example of Cert import
- Import-ExchangeCertificate –Path “C:\CertificateFile.cer” | Enable-ExchangeCertificate -Services pop, smtp, iis, imap(2007 Example)
- Import-ExchangeCertificate -FileData ([Byte]$(Get-Content -Path c:\certificates\newcert.cer -Encoding Byte -ReadCount 0)) | Enable-ExchangeCertificate -Services SMTP (2010 Example)
- External URLs not defined correctly
- Can’t resolve Fully qualified domain names (FQDN)
SCP Record does not contain the correct value
- Test from outlook:
- Hold CTRL and Click the outlook Icon in the system tray and select “Test Email Auto Configuration”
- Uncheck guess smart and click Test
- check SCP value returned
- If you get info on the results tab then autodiscover is working
- If not look at the Log tab and look at the URL that is returned
- Test the URL (Type it into Internet explorer) if its not change SCP to a valid URL
- Run ADSIEDIT and view the “Service Binding Information” to verify the correct value
2. Set the SCP allong with the internal URL: Set-ClientAccessServer CASServerName -AutoDiscoverServiceInternalUri https://mail.domain.local/Autodiscover/Autodiscover.xml