<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Confused Amused &#187; exchange</title>
	<atom:link href="http://www.confusedamused.com/tags/exchange/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.confusedamused.com</link>
	<description></description>
	<lastBuildDate>Wed, 01 Feb 2012 02:58:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ExtraTeam is hiring a Microsoft UC Engineer</title>
		<link>http://www.confusedamused.com/notebook/extrateam-is-hiring-a-microsoft-uc-engineer/</link>
		<comments>http://www.confusedamused.com/notebook/extrateam-is-hiring-a-microsoft-uc-engineer/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 15:19:11 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[Lync Server 2010]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[lync]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=1107</guid>
		<description><![CDATA[Sorry for the off topic post, but my company is growing and looking to add another Microsoft UC Consultant to the team. Please reach out to jobs&#8230;at&#8230;extrateam.com if interested. The full job posting is below.

Microsoft Unified Communications Consultant @ ExtraTeam
We tend to assume success, and for good reason. We&#8217;ve built a bleeding edge technology organization [...]]]></description>
			<content:encoded><![CDATA[<p>Sorry for the off topic post, but my company is growing and looking to add another Microsoft UC Consultant to the team. Please reach out to jobs&#8230;at&#8230;extrateam.com if interested. The full job posting is below.</p>

<p><b>Microsoft Unified Communications Consultant @ ExtraTeam</b><br />
We tend to assume success, and for good reason. We&#8217;ve built a bleeding edge technology organization from the ground up. Each and every day we receive validation on our immense value to the world in strategizing and deploying the best of the best technology solutions. Our Microsoft practice has more than doubled over the past year and we continue to expand at a breath-taking pace. You will be joining the top Microsoft consulting team in the Bay Area; our team consists of Microsoft Certified Masters, MVP&#8217;s, and published authors.</p>

<p>This is high-performanceville and we just can&#8217;t wait to have you here.</p>

<p>Standard description to an exceptional opportunity:</p>

<p>This is a fast moving job where you will be working on all the latest technology from Microsoft.</p>

<p>Typical projects you will be working on include designing, deploying and maintaining;</p>

<ul>
<li>Exchange 2010 including Unified Messaging</li>
<li>Lync 2010 with full voice and video integration</li>
</ul>

<p>Job Responsibilities:</p>

<ul>
<li>Designing: Work closely with our customers to assess their needs and design appropriate solutions as well as being an evangelist for ExtraTeam.</li>
<li>Implementing: You will be part of a high level team responsible for meeting our customers&#8217; implementation, configuration, installation and management needs.</li>
<li>Troubleshooting: Work closely with customers to resolve networking problems across a wide range of technologies.</li>
<li>Documenting: Ensure high quality technical documents are produced quickly and accurately.</li>
</ul>

<p>Our customer base is a very diverse mix including many household names, defense contractors, retail giants, leading pharmaceuticals as well as local government and education.</p>

<p>Although technical expertise is key, your attitude and aptitude will be far more important. We&#8217;re looking for someone with a strong desire to learn from the best, as part of our tightly-knit team.</p>

<p>We are a long standing Microsoft Gold Partner as well as a Cisco Gold Partner.</p>

<p>What&#8217;s in it for you:</p>

<ul>
<li>Strong base salary, quarterly bonus, benefits, 401K, and much more.</li>
<li>Stable, fun, and team-oriented work environment.</li>
<li>Opportunity to innovate with the latest tools at your disposal.</li>
<li>Opportunity to work remotely on select projects</li>
<li>Opportunity for growth. This is a full-time, permanent position. We&#8217;re thinking long term.</li>
</ul>

<p>Requirements for you to meet your potential:</p>

<ul>
<li>Microsoft MCITP certification in Exchange 2010 and/or Lync 2010</li>
<li>You will need to be able to handle multiple projects concurrently and drive them to completion (yes, we&#8217;re very busy)</li>
<li>Cisco certification would be desirable</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/extrateam-is-hiring-a-microsoft-uc-engineer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adding Speech Languages to an Existing Exchange UM Dial Plan</title>
		<link>http://www.confusedamused.com/notebook/adding-speech-languages-to-an-existing-exchange-um-dial-plan/</link>
		<comments>http://www.confusedamused.com/notebook/adding-speech-languages-to-an-existing-exchange-um-dial-plan/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 22:52:21 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2007]]></category>
		<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[adsiedit]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[UM]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=1085</guid>
		<description><![CDATA[There have been a few instances lately where I&#8217;ve needed to add a speech language pack to an Exchange Unified Messaging server after a dial plan and auto-attendants have been created. Installing the language pack is no problem, but what you&#8217;ll find is that the new language is only available to new dial plans and [...]]]></description>
			<content:encoded><![CDATA[<p>There have been a few instances lately where I&#8217;ve needed to add a speech language pack to an Exchange Unified Messaging server after a dial plan and auto-attendants have been created. Installing the language pack is no problem, but what you&#8217;ll find is that the new language is only available to new dial plans and any objects tied to them. You cannot simply install the pack and then select the language for an existing user or auto-attendant. </p>

<p>Here is an example case where I&#8217;ve installed the Portuguese language pack on a server:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/09/um2.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/09/um2.png" alt="" title="um2" width="444" height="336" class="alignnone size-full wp-image-1090" /></a></p>

<p>But you can see the pack is not available for a dial plan created prior to the installation:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/09/um5.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/09/um5.png" alt="" title="um5" width="440" height="501" class="alignnone size-full wp-image-1093" /></a></p>

<p>I&#8217;m sure the Microsoft answers are either to A &#8211; make sure you install the language packs up front, or B &#8211; create a new dial plan and auto-attendants, but in my case A was not possible and I had no interest in the effort involved for B. </p>

<p>So, ADSI Edit to the rescue. You can grab the language codes for installed packs from the UM server object properties at CN=&lt;Server Name&gt;, CN=Servers, CN=Exchange Administrative Group (FYDIBOHF23SPDLT), CN=Administrative Groups, CN=&lt;Exchange Org Name&gt;, CN=Microsoft Exchange, CN=Services, CN=Configuration, DC=&lt;Forest&gt;, DC=&lt;TLD&gt;. The msExchUMAvailableLanguages attribute will list the languages installed on the server (1033 is US English):</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/09/um1.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/09/um1.png" alt="" title="um1" width="407" height="444" class="alignnone size-full wp-image-1089" /></a></p>

<p>Now, armed with the language code for Portuguese (1046) you can modify the existing dial plan or auto-attendants objects in the UM AutoAttendant or UM DialPlan containers to support this language. The containers for these objects are found within CN=Exchange Administrative Group (FYDIBOHF23SPDLT), CN=Administrative Groups, CN=&lt;Exchange Org Name&gt;, CN=Microsoft Exchange, CN=Services, CN=Configuration, DC=&lt;Forest&gt;, DC=&lt;TLD&gt;. You can add the language as an option by modifying the msExchUMAvailableLanguages attribute to include the new language code. Here I have added it to an existing plan called Brazil:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/09/um3.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/09/um3.png" alt="" title="um3" width="404" height="285" class="alignnone size-full wp-image-1091" /></a></p>

<p>You can now see this language appear as an option for the dial plan within the Exchange Management Console:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/09/um4.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/09/um4.png" alt="" title="um4" width="437" height="502" class="alignnone size-full wp-image-1092" /></a></p>

<p>You can use this same method for an auto-attendant, but I would add the language first to the dial plan the auto-attendant is associated with. Obviously using ADSI Edit incorrectly has potential for causing some serious issues. Proceed at your own risk.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/adding-speech-languages-to-an-existing-exchange-um-dial-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>File Share Witness and Datacenter Failback</title>
		<link>http://www.confusedamused.com/notebook/file-share-witness-and-datacenter-failback/</link>
		<comments>http://www.confusedamused.com/notebook/file-share-witness-and-datacenter-failback/#comments</comments>
		<pubDate>Thu, 04 Aug 2011 06:12:47 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[dag]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[fsw]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=1032</guid>
		<description><![CDATA[This afternoon we ran across an issue with a fairly new Exchange 2010 Database Availability Group comprised of 3 nodes all running SP1 with Update Rollup 3. The primary datacenter had 2 nodes with a local file share witness while the 3rd node and alternate file share witness were in a DR site.  We [...]]]></description>
			<content:encoded><![CDATA[<p>This afternoon we ran across an issue with a fairly new Exchange 2010 Database Availability Group comprised of 3 nodes all running SP1 with Update Rollup 3. The primary datacenter had 2 nodes with a local file share witness while the 3rd node and alternate file share witness were in a DR site.  We also had recently performed a successfull datacenter failover and failback test that went swimmingly so everything was back up and running in the primary datacenter.</p>

<p>What we noticed today was that the cluster quorum and file share witness settings persisted as a node and file share majority after the failback instead of reverting to a node majority model like a 3-node DAG should be using. The only time Exchange should be using this model is when we have an even number of servers in the DAG. So without reproducing this again I can only see this as a timing issue &#8211; when one of the primary datacenter nodes gets added back to the DAG the quorum settings are flipped, but once the 3rd and final node joins again the quorum settings are not adjusted. This leaves us with a node and file share majority, and the FSW being our alternate FSW.</p>

<p>You can see here if you open the Cluster MMC our DAG is operating as a node and file share majority model even though all 3 nodes are online:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/08/dag1.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/08/dag1.png" alt="" title="dag1" width="546" height="125" class="alignnone size-full wp-image-1034" /></a></p>

<p>The fix for the issue is really easy &#8211; just run the Set-DatabaseAvailabilityGroup with no parameters. This process does not take the databases or cluster offline, but you&#8217;ll see the DAG detect it is using the wrong model for an odd number of nodes and adjust itself accordingly:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/08/dag2.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/08/dag2-e1312438162393.png" alt="" title="dag2" width="547" height="32" class="alignnone size-full wp-image-1035" /></a></p>

<p>After the change you can verify in the cluster MMC that the quorum settings have been corrected to be a node majority:</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/08/dag31.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/08/dag31.png" alt="" title="dag3" width="298" height="125" class="alignnone size-full wp-image-1037" /></a></p>

<p>I&#8217;m sure there&#8217;s a rational reason behind this behavior, but I haven&#8217;t quite nailed down why this happens quite yet. In the meantime it&#8217;s just one more step to add to your DR documentation!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/file-share-witness-and-datacenter-failback/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Lync and Exchange Web Services Over HTTP</title>
		<link>http://www.confusedamused.com/notebook/lync-and-exchange-web-services-over-http/</link>
		<comments>http://www.confusedamused.com/notebook/lync-and-exchange-web-services-over-http/#comments</comments>
		<pubDate>Thu, 31 Mar 2011 03:48:31 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Lync Server 2010]]></category>
		<category><![CDATA[ews]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[lync]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=936</guid>
		<description><![CDATA[Spoiler: It doesn&#8217;t work.

The behavior you&#8217;ll see is that the Lync client will issue the Autodiscover query, receive a successful response, and then never even attempt to contact the EWS URL. No DNS lookup, no HTTP request, nada. Consequently you&#8217;ll see &#8220;EWS not deployed&#8221; in the configuration info or get the red bangs on the [...]]]></description>
			<content:encoded><![CDATA[<p><b>Spoiler</b>: It doesn&#8217;t work.</p>

<p>The behavior you&#8217;ll see is that the Lync client will issue the Autodiscover query, receive a successful response, and then never even attempt to contact the EWS URL. No DNS lookup, no HTTP request, nada. Consequently you&#8217;ll see &#8220;EWS not deployed&#8221; in the configuration info or get the red bangs on the conversation history and phone tabs. </p>

<p>The only fix available is to modify your EWS virtual directory URLs to be HTTPS instead of HTTP, which you probably should be doing anyway, but I have run across deployments where this was not the case. After the change to HTTPS the Lync client will begin contacting the EWS URL correctly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/lync-and-exchange-web-services-over-http/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Lync Claims EWS Not Deployed</title>
		<link>http://www.confusedamused.com/notebook/lync-claims-ews-not-deployed/</link>
		<comments>http://www.confusedamused.com/notebook/lync-claims-ews-not-deployed/#comments</comments>
		<pubDate>Thu, 27 Jan 2011 05:51:12 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[Lync Server 2010]]></category>
		<category><![CDATA[autodiscover]]></category>
		<category><![CDATA[ews]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[lync]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=893</guid>
		<description><![CDATA[In the last few Lync deployments I&#8217;ve done I&#8217;ve run into two different instances where the Lync client was failing to login to Exchange Web Services to retrieve the conversation history and user voicemail. In both cases there wasn&#8217;t actually the red exclamation mark on those two tabs in the UI like you&#8217;d expect if [...]]]></description>
			<content:encoded><![CDATA[<p>In the last few Lync deployments I&#8217;ve done I&#8217;ve run into two different instances where the Lync client was failing to login to Exchange Web Services to retrieve the conversation history and user voicemail. In both cases there wasn&#8217;t actually the red exclamation mark on those two tabs in the UI like you&#8217;d expect if there were an error; the client just hummed along like nothing was wrong. In each scenario if I viewed the configuration information you would see the client report &#8220;EWS Not Deployed&#8221;, which was odd because Exchange 2010 was most definitely deployed at both customer sites.</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/01/ewsnot.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/01/ewsnot.png" alt="" title="ewsnot" width="414" height="249" class="alignnone size-full wp-image-907" /></a></p>

<p>Sidenote: The EWS polling takes roughly 30 seconds to reach this state. If you view the configuration info immediately you&#8217;ll see &#8220;EWS OK&#8221;, which is only because Lync has tried yet. So be careful when testing this and thinking everything is just fine.</p>

<p><b>Solution 1: Verify the InternalURL and ExternalURL for the Web Services virtual directory are entered</b><br />
The first fix was incredibly easy and after some more digging we determined this was only occurring when a client was external and logging in through an Edge server. When we looked at the Exchange Client Access Server we found this customer had not actually entered an ExternalURL parameter for the Web Services virtual directory. This works just fine for Outlook clients, but Lync is expecting this value to be filled out. If it&#8217;s not entered it assumes EWS is not deployed externally and doesn&#8217;t attempt a connection, which is a pretty reasonable action. You might argue the Outlook action is incorrect and it should treat it the same way. But anyway, the fix is to just fill out the ExternalURL and Lync will begin using that value to login to EWS successfully.</p>

<p>Sidenote 2: The information discovered by Lync via Autodiscover is cached in the registry at HKCU\Software\Microsoft\Communicator\&lt;SIP URI&gt;\Autodiscovery (Can you tell a Lync dev wrote the regkey name? Autodiscovery instead of Autodiscover?) You&#8217;ll see entries for the internal and external URLs for the Availability Service, Exchange Control Panel, Exchange Web Services, and Out of Office Assistant. I&#8217;ve been able to delete this entire registry key for quick testing and found it recreated with no issues.</p>

<p><a href="http://www.confusedamused.com/wp-content/pictures/2011/01/lycnreg.png"><img src="http://www.confusedamused.com/wp-content/pictures/2011/01/lycnreg.png" alt="" title="lycnreg" width="334" height="339" class="alignnone size-full wp-image-905" /></a></p>

<p><b>Solution 2: Place https://&lt;Your SMTP domain&gt;/ in the Local Intranet Zone</b><br />
The second instance of this issue was a little more complicated, and still doesn&#8217;t make much sense to me, but I figured I would share. In this case the customer did not have Outlook Anywhere published so we expected it to fail externally, but this error was actually occurring internally. After verifying the InternalURL was filled out correctly we started doing some traces and noticed the Lync client would make a GET request to the /Autodiscover/Autodiscover.xml file on Exchange, Exchange would return a 401 Unauthorized challenging for credentials like we expected, and then the trace died. There were be no more responses from the Lync client IP address sent to Exchange in the logs. We verified this on multiple machines and operating systems and concluded that the Lync client would never respond to the credential request! For what it&#8217;s worth, Autodiscover was working fine for Outlook clients and no special configuration had been done to Exchange. </p>

<p>So we put a call into PSS and they told me Lync will <i>not</i> read the SCP for Autodiscover in AD, even if the Lync client is  internal and that it will do its own Autodiscover lookup (Can anyone confirm/deny this?). Therefore, it will fall back to https://domain.com/Autodiscover/Autodiscover.xml, and if that fails it should move on to https://autodiscover.domain.com/Autodiscover/Autodiscover.xml like an Outlook client. This is where it got weird &#8211; PSS told me from the ETL trace Lync was not falling back to the 2nd option, yet I could clearly see it make a request to IIS and not respond. From what they saw the Lync client was getting stuck on the 1st option which didn&#8217;t really exist. In any event, they had me add http://&lt;domain.com&gt;/ to the Local Intranet Zone on the client. Even though we knew this was not the location of Autodiscover and I really didn&#8217;t think it would make a difference it did solve the problem. After adding entry this we saw clients then try to resolve autodiscover.domain.com and grab the Autodiscover.xml file correctly from https://autodiscover.domain.com/Autodiscover/Autodiscover.xml. At this point the EWS status in the configuration information returned to EWS OK.</p>

<p>Sidenote 3: There is a thread on the <a href="http://social.technet.microsoft.com/Forums/en-US/ocsvoice/thread/283db822-7156-438b-bd2f-0f00f74d00b2/#bb213fe9-72fe-48da-86f4-eb4d03084e2e">Technet forums about this issue</a> which suggests editing your applicationhost.config file on the Exchange server. I have to recommend against this and as you can see in the comments it hasn&#8217;t really fixed the problem for anyone. The solution is more likely one of the ones presented here. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/lync-claims-ews-not-deployed/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Outlook Integration Error in Communicator 2007 R2 when Exchange System Manager is installed</title>
		<link>http://www.confusedamused.com/notebook/outlook-integration-error-in-communicator-2007-r2-when-exchange-system-manager-is-installed/</link>
		<comments>http://www.confusedamused.com/notebook/outlook-integration-error-in-communicator-2007-r2-when-exchange-system-manager-is-installed/#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:59:33 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Office Communications Server 2007 R2]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[communicator]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[mapi]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[R2]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=776</guid>
		<description><![CDATA[Working on an OCS migration project a few weeks ago I ran into everyone&#8217;s favorite error:

There was a problem connecting to Microsoft Office Outlook. Your Outlook profile is not configured correctly. Contact your system administrator with the information.

After double checking the lengthy KB 2373585 article discussing Outlook/Communicator errors and ruling out the usual suspects I [...]]]></description>
			<content:encoded><![CDATA[<p>Working on an OCS migration project a few weeks ago I ran into everyone&#8217;s favorite error:</p>

<p><blockquote>There was a problem connecting to Microsoft Office Outlook. Your Outlook profile is not configured correctly. Contact your system administrator with the information.</blockquote></p>

<p>After double checking the lengthy <a href="http://support.microsoft.com/kb/2373585">KB 2373585 article</a> discussing Outlook/Communicator errors and ruling out the usual suspects I was stumped. After some digging around on the workstation I found the user had the Exchange 2003 System Manager and tools installed on the machine. Since the System Manager uses a slightly different version of MAPI components Communicator would generate this error immediately upon signing in.</p>

<p>The solution is to open a command prompt and just run the command: <b>fixmapi</b>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/outlook-integration-error-in-communicator-2007-r2-when-exchange-system-manager-is-installed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Public Certificates for Exchange 2010 Federation</title>
		<link>http://www.confusedamused.com/notebook/public-certificates-for-exchange-2010-federation/</link>
		<comments>http://www.confusedamused.com/notebook/public-certificates-for-exchange-2010-federation/#comments</comments>
		<pubDate>Thu, 20 May 2010 04:14:21 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[comodo]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[federation]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=746</guid>
		<description><![CDATA[I think that one of the coolest features of Exchange 2010 is the seamless free/busy and calendar federation between organizations. In order to get federation provisioned there are a number of steps you need to take which you can find detailed on Technet. The first step of this setup involves creating a Federation Trust to [...]]]></description>
			<content:encoded><![CDATA[<p><p>I think that one of the coolest features of Exchange 2010 is the seamless free/busy and calendar federation between organizations. In order to get federation provisioned there are a number of steps you need to take which you can find detailed on <a href="http://technet.microsoft.com/en-us/library/dd351109.aspx">Technet</a>.</p> <p>The first step of this setup involves creating a Federation Trust to the Microsoft Federation Gateway (MFG), but in order to create this trust you need to use a public certificate issued by one of the following Certificate Authorities (the haphazard thumbprint formatting is Technet’s, not mine):</p> <table border="0" cellspacing="0" cellpadding="2" width="685"> <tbody> <tr> <td valign="top" width="284"><strong>CA certificate friendly name</strong></td> <td valign="top" width="399"><strong>Thumbprint</strong></td></tr> <tr> <td valign="top" width="284">Comodo</td> <td valign="top" width="399">NA</td></tr> <tr> <td valign="top" width="284">Digicert Global Root CA</td> <td valign="top" width="399">‎083B:E056:9042:46B1:A175:6AC9:5991:C74A</td></tr> <tr> <td valign="top" width="284">Digicert High Assurance EV Root CA</td> <td valign="top" width="399">‎91 8d a5 e4 99 c1 5f 7c 62 75 b1 24 fe de 53 35 7c 34 bd 36</td></tr> <tr> <td valign="top" width="284">Entrust.net CA (2048)</td> <td valign="top" width="399">801D 62D0 7B44 9D5C 5C03 5C98 EA61 FA44 3C2A 58FE</td></tr> <tr> <td valign="top" width="284">Entrust Secure Server CA</td> <td valign="top" width="399">99A6 9BE6 1AFE 886B 4D2B 8200 7CB8 54FC 317E 1539</td></tr> <tr> <td valign="top" width="284">Go Daddy Secure Certification Authority</td> <td valign="top" width="399">‎7c46 56c3 061f 7f4c 0d67 b319 a855 f60e bc11 fc44</td></tr></tbody></table> <p>I recently was involved an Exchange deployment that involved purchasing a SAN certificate from Comodo. One of the certificate authorities Comodo uses to issue SAN certs is the USERTrust Legacy Secure Server CA, which has its own certificate issued by the Entrust.net Secure Server Certification Authority. Bottom line is the certificate you get verifies up to the Entrust certificate you can see below which the Federation Gateway supports.</p> <p><a href="http://www.confusedamused.com/wp-content/pictures/2010/05/image.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.confusedamused.com/wp-content/pictures/2010/05/image_thumb.png" width="363" height="91"></a></p> <p>After trying to create the Federation Trust we were seeing the following error:</p> <p><a href="http://www.confusedamused.com/wp-content/pictures/2010/05/image61.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.confusedamused.com/wp-content/pictures/2010/05/image6_thumb1.png" width="600" height="317"></a></p> <blockquote> <p>An error occurred while attempting to provision Exchange to the Partner STS. Detailed information “An error occurred accessing Windows Live. Detailed information “The request failed with HTTP status 403: Forbidden.”.”</p></blockquote> <p>Basically this is the MFG’s way of saying “I don’t trust this certificate.” It turns out the MFG is geared to only accept certificates issued directly from one of the certificate authorities listed above which is not something I saw in the documentation. So if the Entrust Secure Server Certification Authority had issued our webmail certificate it would have been accepted. But like in our case, if your certificate is issued from a 3rd party intermediate certificate authority it won’t be accepted even if it technically verifies up to a support rooted authority.</p> <p>The good news is a call to PSS resulted in Microsoft making a change on the MFG to accept certificates issued by this particular intermediate CA going forward for everyone. So if ran into this error previously you should be able to try again with the same certificate and see the trust succeed. As of this writing I’ve requested them to also add support for the AAA Certificate Services intermediate CA Comodo also issues certificates from.</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/public-certificates-for-exchange-2010-federation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 SSL Offloading</title>
		<link>http://www.confusedamused.com/notebook/exchange-2010-ssl-offloading/</link>
		<comments>http://www.confusedamused.com/notebook/exchange-2010-ssl-offloading/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 02:32:52 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[bigip]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[f5]]></category>
		<category><![CDATA[offload]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=733</guid>
		<description><![CDATA[One of the deployments I&#8217;ve been working on recently involved using F5 BigIP hardware load balancers to do SSL offloading for a two-node Exchange 2010 design. To give some background here usually you would just pass through port 443 (I&#8217;m skipping over the RPC Client Access piece since it&#8217;s not relevant here) from your load [...]]]></description>
			<content:encoded><![CDATA[<p><p>One of the deployments I&#8217;ve been working on recently involved using F5 BigIP hardware load balancers to do SSL offloading for a two-node Exchange 2010 design. To give some background here usually you would just pass through port 443 (I&#8217;m skipping over the RPC Client Access piece since it&#8217;s not relevant here) from your load balancer straight to the Exchange servers, letting the servers handle the SSL encryption like in this diagram:</p>  <p><a href="http://www.confusedamused.com/wp-content/pictures/2010/03/image.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.confusedamused.com/wp-content/pictures/2010/03/image_thumb.png" width="500" height="78" /></a> </p>  <p>The benefit of that approach is it&#8217;s simple and a very common deployment method. On the flip side, you can benefit from offloading SSL encryption to the BigIPs and gain some more advanced forms of load balancing. In this case the improved load balancing was the goal along with some internal policies forcing this approach. What happens with SSL offloading is the HTTPS traffic ends at the BigIPs which turn around and pass port 80 clear-text traffic back to the Exchange servers so they have a bit less CPU work to do. That strategy looks more like this:</p>  <p><a href="http://www.confusedamused.com/wp-content/pictures/2010/03/image1.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.confusedamused.com/wp-content/pictures/2010/03/image_thumb1.png" width="500" height="78" /></a> </p>  <p>The problem with this configuration is Exchange is really designed to operate with SSL in mind and you have to go out of your way to allow it to operate in clear-text. What you&#8217;ll need to configure on each CAS server is:</p>  <ul>   <li>Set the Outlook Web Access SSLOffloaded registry key: <a href="http://technet.microsoft.com/en-us/library/bb885060(EXCHG.80).aspx">http://technet.microsoft.com/en-us/library/bb885060(EXCHG.80).aspx</a> </li>    <li>Remove the SSL requirement from all Exchange virtual directories via IIS Manager. </li>    <li>Edit the Exchange Web Services web.config file to force HTTP: <a href="http://technet.microsoft.com/en-us/library/ee633481.aspx">http://technet.microsoft.com/en-us/library/ee633481.aspx</a> </li>    <li>Configure Outlook Anywhere SSL Offload: <a href="http://technet.microsoft.com/en-us/library/aa998346.aspx">http://technet.microsoft.com/en-us/library/aa998346.aspx</a> </li> </ul>  <p>The issue I ran into is after following all of these steps Autodiscover was still not functional through the load balancing. I could enter https:&#47;&#47;&lt;CAS Array FQDN&gt;&#47;Autodiscover&#47;Autodiscover.xml into a browser and reach the XML file with no problem, but running the Autodiscover test within Outlook would return a 404 error. Every other service was working just fine:</p>  <p><a href="http://www.confusedamused.com/wp-content/pictures/2010/03/image2.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.confusedamused.com/wp-content/pictures/2010/03/image_thumb2.png" width="500" height="88" /></a> </p>  <p>This threw me for awhile and after a bit of searching I ran across <a href="http://support.microsoft.com/kb/980048">KB 980048</a> where it&#8217;s noted that Autodiscover cannot be used on port 80 with an HTTP POST request, which is what Outlook uses. My attempts at accessing the XML directly succeeded because I was only trying to download the file. Supposedly this is going to be fixed in Service Pack 1.</p>  <p>While the KB provides no immediate solution what I found that works is to use the same methodology Technet recommends for the Exchange Web Services web.config file. Go into your /Autodiscover folder and edit the web.config to replace all instances of httpsTransport with httpTransport (a simple search and replace should work). Be sure to save a copy before you make modifications, restart your server after making the change and you should be able to offload SSL for Autodiscover successfully. Since as far as I know this is undocumented today you can try this at your own risk, but it appears to be working.</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/exchange-2010-ssl-offloading/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Snow Leopard and Exchange 2007 Integration Notes</title>
		<link>http://www.confusedamused.com/notebook/snow-leopard-and-exchange-2007-integration-notes/</link>
		<comments>http://www.confusedamused.com/notebook/snow-leopard-and-exchange-2007-integration-notes/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 22:08:51 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2007]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[10.6]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[activesync]]></category>
		<category><![CDATA[ews]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[leopard]]></category>
		<category><![CDATA[snow]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=502</guid>
		<description><![CDATA[Some notes on my experience so far with Apple’s 10.6 Snow Leopard OS and Microsoft Exchange Server 2007:

Setup

It’s brain-dead. It uses Autodiscover, so e-mail and password is all you need. You get prompted if you’d like it to also configure iCal and your address book. 
I haven’t tried from home yet, but the external server [...]]]></description>
			<content:encoded><![CDATA[<p>Some notes on my experience so far with Apple’s 10.6 Snow Leopard OS and Microsoft Exchange Server 2007:</p>

<p><h4>Setup</h4>
<ul>
<li><p>It’s brain-dead. It uses Autodiscover, so e-mail and password is all you need. You get prompted if you’d like it to also configure iCal and your address book. </p></li>
<li><p>I haven’t tried from home yet, but the external server path is not filled out. Internal picks up EWS/Exchange.asmx URL just fine, but external is blank. I double-checked our Exchange server and this parameter isn’t filled out so that makes sense. The difference here is Outlook assumes the external is the same as internal if this value is blank, but it appears Apple Mail will not. Be sure to set your –ExternalURL parameters on the virtual directories appropriately. </p></li>
</ul>
<h4>Mail</h4>
<ul>
<li><p>Responses to meetings come across as an .ics attachment, no special functionality here. This is especially bad if someone proposes a new time. </p></li>
<li><p>The Exchange RSS Feeds folder does not integrate with the RSS feeds section in Mail. This would have been nice. </p></li>
<li><p>Name suggestions are offered from the GAL and your contacts. </p></li>
<li><p>Rules do not sync. </p></li>
<li><p>UM voice mails have a built in media control. My codec is set to G.711 and I see embedded QuickTime controls in the message for playback. </p></li>
<li><p>The actually listing of your notes is displayed in the Marker Felt font. It’s horrendous and tough to read. </p></li>
<li><p>No out of office assistant. </p></li>
<li><p>You can add multiple Exchange accounts. </p></li>
</ul>
<h4>iCal</h4>
<ul>
<li><p>You can schedule meetings and invite attendees. </p></li>
<li><p>You can view free/busy details for attendees. </p></li>
<li><p>iCal does not differentiate between people and resources as attendees.</p></li>
<li><p>You can view responses for meetings. Accepted, tentative, declined or unknown. </p></li>
<li><p>Tasks sync to iCal “To-Dos”. The default view shows all completed items. Hit the iCal preferences to change this view. </p></li>
<li><p>You can view Delegate calendars and grant access to your calendars and tasks. </p></li>
<li><p>Name suggestions are offered from the GAL and your contacts. </p></li>
</ul>
<h4>Address Book</h4>
<ul>
<li><p>My contacts came across just fine. </p></li>
<li><p>I can’t see the GAL for some reason. The URL in the account settings looks correct, but the GAL is empty. Really strange considering I get GAL-suggestions when typing names in other applications.</p></li>
</ul>
<p>I’m sure there are more to come, but despite some of the caveats this is still a huge improvement over Entourage. I’m looking forward to the Outlook for Mac client coming next year, but until then I’ll be using the native applications.</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/snow-leopard-and-exchange-2007-integration-notes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Domain Controller as File Share Witness for an Exchange 2010 DAG</title>
		<link>http://www.confusedamused.com/notebook/domain-controller-as-file-share-witness-for-an-exchange-2010-dag/</link>
		<comments>http://www.confusedamused.com/notebook/domain-controller-as-file-share-witness-for-an-exchange-2010-dag/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 19:19:46 +0000</pubDate>
		<dc:creator>Tom Pacyk</dc:creator>
				<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[cas]]></category>
		<category><![CDATA[ccr]]></category>
		<category><![CDATA[dag]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[fsw]]></category>
		<category><![CDATA[ht]]></category>
		<category><![CDATA[mbx]]></category>

		<guid isPermaLink="false">http://www.confusedamused.com/?p=497</guid>
		<description><![CDATA[Edit &#8211; post removed!

This post was originally written based on the Exchange 2010 beta bits before the Technet documentation was updated to reflect the actual required permissions for a DAG&#8217;s FSW. Consequently, it had a major error. You&#8217;ll want to visit Devin&#8217;s page for a full explanation and the correct way to set up the [...]]]></description>
			<content:encoded><![CDATA[<p>Edit &#8211; post removed!</p>

<p>This post was originally written based on the Exchange 2010 beta bits before the Technet documentation was updated to reflect the actual required permissions for a DAG&#8217;s FSW. Consequently, it had a major error. You&#8217;ll want to visit <a href="http://www.thecabal.org/2009/12/busting-the-exchange-trusted-subsystem-myth/">Devin&#8217;s page</a> for a full explanation and the correct way to set up the DAG. Always helps when you can read the documentation, right? <img src='http://www.confusedamused.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.confusedamused.com/notebook/domain-controller-as-file-share-witness-for-an-exchange-2010-dag/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

