Mostrando entradas con la etiqueta Certificates. Mostrar todas las entradas
Mostrando entradas con la etiqueta Certificates. Mostrar todas las entradas

sábado, 5 de marzo de 2016

Renew expired Exchange Outlook Web App and Microsoft Outlook Certificate Este certificado ha expirado o no es válido todavía, "La fecha del certificado de seguridad es válida", "El nombre del certificado de seguridad no es válido o no coincide con el nombre del sitio"

Spanish Keywords:
 

Trabaja para Exchange 2010 también en Windows Small Business Server 2011.
 
Si están usando un certificado autofirmado estos pasos no son necesarios pues el mismo servidor de Exchange va a autorenovar los certificados.  Y es más probable qué los errores de certificados sean por qué el nombre del certificado no coincide con el publicado externamente.
 
Por ello es necesario verificar si el certificado expiro o sí el nombre de publicación no coincide.
 
Si usamos entidades certificadoras para verificar si el certificado expiró:  
  • En el sitio de owa, al dar clic en "error de certificado" obtienes algo similar
    • "Este certificado ha expirado o no es válido todavía"
 
  • Cuándo usas Microsoft Outlook para conectar al servidor de Microsoft Exchange obtienes algo similar:  Error junto a "La fecha del certificado de seguridad es válida"
 
Para reparar este error en una sesión del servidor Exchange
  1. Abre la consola de Exchange
  2. Navega en el árbol de la consola y da clic en "Configuración de Servidor" 
  3. En la parte inferior se puede identificar el certificado expirado marcado con una x roja

  • Das botón derecho en el certificado y das clic en "Renovar Certificado"
  • Se da un nombre a la solicitud de certificado 
  • El archivo se creará en la carpeta qué indiquemos después de dar clic en renovar
Una vez qué tengamos el archivo se abre el sitio web de la entidad certificadora y se pega el texto dentro del archivo siguiendo las instrucciones de:
Cuarto Paso: Crear el certificado a partir de la solicitud en la siguiente entrada de este blog
Exchange 2007 and Exchange 2010 Issue a Certificate with a Windows 2008 CA and enable RPC over HTTP

Sin embargo es más sencillo utilizar el siguiente comando de Exchange Management Shell:
  1. (para Windows 2008) Clic en Inicio, "Todos los Programas", "Microsoft Exchange 200x", abre el que dice "Exchange Management Shell"
  2. Cuándo tengas acceso al Shell de Exchange, ejecuta el siguiente comando:
    [PS] C:\Windows\System32> certreq -submit -attrib "CertificateTemplate:WebServer"
inmediatamente se solicita el path del archivo generado cert2016.req o el nombre qué le hayan puesto



A continuación les solicita la entidad certificadora a la cuál se va a renovar el certificado,

 
 
Una vez que seleccionamos la entidad certificadora (mismo Servidor de Exchange o algún servidor dentro del dominio) se genera un archivo nuevo .cer
 
 
Se regresa a la consola de Exchange y aparecerá el nuevo certificado, sin embargo es necesario dar clic derecho en el mismo y asignar los servicios IIS, POP, SMTP e IMAP.

 



Al dar clic en asignar habrá 4 confirmaciones diciendo qué se va a reemplazar el certificado a todas debe responder "sí" reemplazar o "sí a todo"

Una vez terminado los errores de OWA y Outlook desaparecerán.  Reiniciar el caché del navegador o un reinicio del PC permitirá quitar los errores

Si el error es provocado por un error en el nombre, el mensaje será como el que sigue: "El nombre del certificado de seguridad no es válido o no coincide con el nombre del sitio"
 
Para resolverlo hay que ejecutar a partir del "Tercer Paso: Crear el certificado de Exchange para que funcione con un nombre principal y varios alias internos/externos" de la siguiente entrada de este blog Exchange 2007 and Exchange 2010 Issue a Certificate with a Windows 2008 CA and enable RPC over HTTP

Con estos procedimientos evitas los mensajes de error de certificado de Microsoft Outlook cuándo se conecta a un servidor de exchange que también tiene Outlook Web App, Outlook Anywhere y donde el nombre del equipo y el del dominio interno no coincide con el del alias de internet.

Saludos
B.

 

lunes, 6 de abril de 2015

Certificado de federación o autenticación no encontrado / Missing the Microsoft Exchange Server Auth Certificate

Source: http://community.spiceworks.com/topic/512374-missing-the-microsoft-exchange-server-auth-certificate

Error:
Nombre de registro:Application
Origen:        MSExchange Certificate Deployment
Fecha:         06/04/2015 8:19:31
Id. del evento:2005
Categoría de la tarea:General
Nivel:         Advertencia
Palabras clave:Clásico
Usuario:       No disponible
Equipo:        servidor.dominio.com
Descripción:
Certificado de federación o autenticación no encontrado: A65CD35A40A0B21AA53C6EAAED012B184F6201B6. No es posible encontrar el certificado en los sitios locales o vecinos. Confirme que el certificado está disponible en su topología y, si es necesario, restablezca el certificado en la confianza de federación a un certificado válido mediante Set-FederationTrust o Set-AuthConfig.  Es posible que lleve tiempo que el certificado se propague a los sitios locales o vecinos.


Solved:
In fact, I would say that this process not only solved my issue but also got rid of a majority of the little warnings and errors on both my Exchange 2013 and Lync 2013 servers.  they seem to enjoy life more when they can exchange tokens directly with each other.
For a majority of you, you will have the certificate in place, and setting up the integration will be super easy.  If by chance, you do not have the cert, then this is your easy 2 min fix.
1. New-ExchangeCertificate -KeySize 2048 -PrivateKeyExportable $true -SubjectName "cn= Microsoft Exchange Server Auth Certificate" -DomainName "*.yourdomain.com" -FriendlyName "Microsoft Exchange Server Auth Certificate" -Services smtp
Do not accept to replace the SMTP certificate when prompted
2. Note the thumbprint of the new certificate. Let us assume it is 7A39541F8DF58D4821967DD8F899B27410F7C081
3. $a=get-date
4. Set-AuthConfig -NewCertificateThumbprint 7A39541F8DF58D4821967DD8F899B27410F7C081 –NewCertificateEffectiveDate $a
Accept to continue despite the fact that the certificate effective date is not 48 hours into the future
5. Set-AuthConfig –PublishCertificate

6. Make sure to remove any potential reference to the previous certificate (which might not exist anymore) by doing Set-AuthConfig -ClearPreviousCertificate.
you can now get back to finishing up your prereqs:  http://technet.microsoft.com/en-us/library/jj721919.aspx 

jueves, 9 de febrero de 2012

Zimbra 7 stop working if SSL certificate is expired

SOLVED: Zimbra 6.0.1 stop working if SSL certificate is expired
http://www.zimbra.com/forums/administrators/44241-solved-solved-zimbra-6-0-1-stop-working-if-ssl-certificate-expired.html

Entrar con putty o con Vshpere Client a la consola de RedHAT, ingresar como root y el password correspondiente

Para ver la fecha de expiración de tus certificados:
[root@mail ~]# /opt/zimbra/bin/zmcertmgr viewdeployedcrt

Primero que todo revisa la hora y la fecha del servidor para que sea la apropiada, si no es correcta corríjela con el comando:

[root@mail ~]# date
Thu Feb 9 16:06:09 ECT 2012

The date command also can be used to set the time and date. To set the time manually, do this:

# date -s "16:15:00"
Fri Mar 28 16:15:00 CST 2003

If you also need to adjust the date, and not just the time, you can do it like this:
# date -s "16:55:30 July 7, 1986"
Mon Jul 7 16:55:30 PDT 1986

There is also another way to set the date and time, which is not very pretty:
# date 033121422003.55
Mon Mar 31 21:42:55 PST 2003

The above command does not use the -s option, and the fields are arranged like this: MMDDhhmmCCYY.ss
where MM = month, DD = day, hh = hour, mm = minute, CCYY = 4 digit year, and ss = seconds.


Si tu fecha y hora es correcta tienes un problema de la CA (Certification Authority)y los certificados de los servicios expirados

Pasos para la versión 7:

- El mensaje exacto del error se presenta después de intentar iniciar el servicio

[root@mail ~]# su -- zimbra
[zimbra@mail /]$ zmcontrol start
Starting ldap ... Done.
Unable to determine enabled services for ldap. Enabled services read from cache. Service List may be inaccurate.
Starting zmconfigd ... Done.
Starting logger ... Failed
Starting logswatch...ERROR: service failure (system failure: ZimbraLdapContext) (cause: javax.net.ssl.SSLHandshakeException sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: timestamp check failed)
zimbra logger service is not enabled! failed.

Starting mailbox...Done.
Starting antispam...Done.
Starting antivirus...Done.
Starting mta...Done.
Starting stats...Done.

[zimbra@mail /]$ exit
Saca un Backup antes de intentar este procedimiento



[root@mail ~]# /opt/zimbra/bin/zmcertmgr createca -new
[root@mail ~]# /opt/zimbra/bin/zmcertmgr createcrt -new -days 365
[root@mail ~]# /opt/zimbra/bin/zmcertmgr deploycrt self
[root@mail ~]# /opt/zimbra/bin/zmcertmgr deployca
[root@mail ~]# /opt/zimbra/bin/zmcertmgr viewdeployedcrt
[root@mail ~]# /opt/zimbra/java/bin/keytool -delete -alias root -keystore /opt/zimbra/java/jre/lib/security/cacerts -storepass changeit
[root@mail ~]# /opt/zimbra/java/bin/keytool -import -alias root -keystore /opt/zimbra/java/jre/lib/security/cacerts -storepass changeit -file /opt/zimbra/conf/ca/ca.pem

Aquí yo recomiendo reiniciar, caso contrario
[root@mail ~]# su -- zimbra
[zimbra@mail /]$ zmcontrol start

Saludos

BADBOY

viernes, 9 de diciembre de 2011

ZCS Avoiding Browser (IE, Firefox, Outlook) Certificate Error with Zimbra Web Client

1. on Zimbra with Putty or Terminal run:

openssl x509 -in /opt/zimbra/ssl/zimbra/ca/ca.pem -outform DER -out /var/tmp/ca.cer

2. startx
3. browse to https://mail.tudominio.com/
4. attach and sent your self the the ca.cer file from /var/tmp

Use GPEDIT.MSC (workgroup) or GPO to copy certificates to other domain machines
1. Ve a Policy Object Name/Computer Configuration/Windows Settings/Security Settings/Public Key Policies/Trusted Root Certification Authorities
2. Right clic and click on import
3. Select ca.cer downloaded after.
4. close GPO or GPEDIT.MSC
5. Reboot

Voilá, mensaje de error de certificado CHAO!!!









06-25-2009, 07:59 AM





Source: http://www.zimbra.com/forums/administrators/26641-outlook-users-getting-certificate-warning.html

YetiRick
New Member

Posts: 4

I know this is too late to help any of the old posters, but it may help other with the same question...

Assuming the Zimbra devs don't move the file, the command:

openssl x509 -in /opt/zimbra/ssl/zimbra/ca/ca.pem -outform DER -out ca.der

will generate the CA root certificate you need in order for Windows to import it properly. You can then copy the resulting ca.der file to your Windows box and double-click it (or import it using the wizard.) It will install into the "Trusted Root Certification Authorities" section of your certificates window. Outlook and HTTPS webmail will no longer generate those annoying errors.

Please keep in mind that if the Zimbra CA is pre-generated and not generated at the time of installation, this will open you up to misidentified sites that sign their own certs with the same CA. I don't know if this is the case or not, but would recommend building your own CA if you're unsure.

[SOLVED] Rolling Your Own CA and Installing Certificates in Zimbra

will get that done for you. And you won't have to guess at which ca.pem file to use.


Fuente 2: http://technet.microsoft.com/en-us/library/cc738131(WS.10).aspx
Add a trusted root certification authority to a Group Policy object
Updated: January 21, 2005

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2

To add a trusted root certification authority to a Group Policy object

Open the Group Policy object (GPO) that you want to edit.

In the console tree, click Trusted Root Certification Authorities.

Where?

Policy Object Name/Computer Configuration/Windows Settings/Security Settings/Public Key Policies/Trusted Root Certification Authorities

On the Action menu, point to All Tasks, and then click Import.

This starts the Certificate Import Wizard, which guides you through the process of importing a root certificate and installing it as a trusted root certification authority (CA) for this GPO.

Notes

To perform this procedure, you must be a member of the Domain Admins group or the Enterprise Admins group in Active Directory, or you must have been delegated the appropriate authority. As a security best practice, consider using Run as to perform this procedure. For more information, see Default local groups, Default groups, and Using Run as.