autodiscover certificate for every domain we own?
Hi Guys, We've got Exchange 2007 with about 12 different email domains coming in, at first we had the autodiscover.mydomain.com security alert coming up, so I purchased a certificate which could hold the following domains: mail.mydomain.co.uk autodiscover.mydomain.co.uk server5.mydomain.local Which sorted the issue for a day, then the "security alert" for "autodiscover.myOTHERdomain.com" started popping up when launching outlook saying "the name on the security certificate does not match the name of the site" I can't add any more names to the certificate so what can I do? As far as I'm aware we don't need the autodiscover so can we just turn it off, or tell it to ignore the certificate? Thanks, Leigh
December 6th, 2010 5:16am

Hi, Please refer to the below articles. http://blogs.technet.com/b/jmayans/archive/2006/09/07/454716.aspx http://www.more2know.nl/2010/05/18/exchange-autodiscover-and-multiple-domains/ The work around which i had done for this same issue is that, I created Autodiscover website for the other domains in a Web Server which was hosted to Internet. I added 'A' in ISP for Autodiscover.otherdomain.com to point to my Web server. In my web server Autodiscover web site I configured it to re -direct to Autodiscover.mydomain.com. When you do this users will get a pop up saying its getting redirect to secure site, so they will have to select ok. Turning off Autodiscovery is not recommended as Out of office, Offline address book services are dependent on Autodiscover. Hope this might help you. Thanks. Nagaraj N
Free Windows Admin Tool Kit Click here and download it now
December 6th, 2010 6:05am

You can't turn autodiscover off, and unless you have Outlook 2003 or lower you cannot do without it. Autodiscover is also used for the availability service, which is what controls free/busy information through Outlook 2007 and higher. You can get certificates that take higher amounts of names - although there would be a cost implication. Microsoft also support the SRV record method of pointing autodiscover in each domain to another host - that would require the external DNS to support SRV records. There is also the redirection site method. However I believe that both of those may well prompt the user that the traffic is being redirected, you would need to communicate that with your users BEFORE the change goes live so that you don't cause panic. I would also ensure that none of the domains that you are supporting have a wildcard in their DNS (so anything.example.com resolves) so that the autodiscover host name doesn't resolve. Outlook tries a number of host names for autodiscover - including example.com and autodiscover.example.com. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources
December 6th, 2010 7:00am

There's a really great whitepaper on the autodiscover function, read it through... a lot of text but it's really good! http://technet.microsoft.com/en-us/library/bb332063%28EXCHG.80%29.aspx Jonas Andersson MCTS: Microsoft Exchange Server 2007/2010 | MCITP: EMA 2007/2010 | MCSE/MCSA Blog: http://www.testlabs.se/blog
Free Windows Admin Tool Kit Click here and download it now
December 6th, 2010 3:55pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics