<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Elan Shudnow's Blog &#187; Office</title>
	<atom:link href="http://www.shudnow.net/tag/office/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Fri, 30 Jul 2010 18:19:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>2007 Office System Administrative Templates (ADM) SP1</title>
		<link>http://www.shudnow.net/2007/10/15/2007-office-system-administrative-templates-adm-sp1/</link>
		<comments>http://www.shudnow.net/2007/10/15/2007-office-system-administrative-templates-adm-sp1/#comments</comments>
		<pubDate>Mon, 15 Oct 2007 15:21:34 +0000</pubDate>
		<dc:creator>Elan Shudnow</dc:creator>
				<category><![CDATA[Office]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[Vista]]></category>

		<guid isPermaLink="false">http://www.shudnow.net/2007/10/15/2007-office-system-administrative-templates-adm-sp1/</guid>
		<description><![CDATA[This download (direct download) includes updated Group Policy Administrative Template files and Office Customization Tool OPA files for use with the 2007 Microsoft Office system programs. It also includes an \Admin folder with an updated Office Customization Tool, and ADMX and ADML versions of the 2007 Microsoft Office system Administrative Template files for Windows Vista [...]]]></description>
			<content:encoded><![CDATA[<p><span><a href="http://www.microsoft.com/downloads/details.aspx?familyid=92d8519a-e143-4aee-8f7a-e4bbaeba13e7">This download</a> (<a href="http://www.microsoft.com/downloads/info.aspx?na=90&amp;p=&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=92d8519a-e143-4aee-8f7a-e4bbaeba13e7&amp;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f8%2f0%2fe%2f80ea55f2-734f-4658-8dd0-14616954e30a%2fAdminTemplates.exe">direct download</a>) includes updated Group Policy Administrative Template files and Office Customization Tool OPA files for use with the 2007 Microsoft Office system programs. It also includes an \Admin folder with an updated Office Customization Tool, and ADMX and ADML versions of the 2007 Microsoft Office system Administrative Template files for Windows Vista and Windows Server 2008. In Windows Vista and Windows Server 2008 operating systems, the ADM files are replaced by ADMX files, which use an XML-based file format to display registry-based policy settings. This download also includes a workbook (Office2007GroupPolicyAndOCTSettings.xls) that provides information about the 2007 Office system Group Policy settings and OPA settings.</span></p>
<p>For more information about ADMX files, see <a href="http://go.microsoft.com/fwlink/?LinkId=75124">Managing Group Policy ADMX Files Step-by-Step Guide on the Microsoft TechNet Web site</a>.</p>
<img src="http://www.shudnow.net/?ak_action=api_record_view&id=52&type=feed" alt="" /><p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.shudnow.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shudnow.net/2007/10/15/2007-office-system-administrative-templates-adm-sp1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outlook 2007 Certificate Error?</title>
		<link>http://www.shudnow.net/2007/08/10/outlook-2007-certificate-error/</link>
		<comments>http://www.shudnow.net/2007/08/10/outlook-2007-certificate-error/#comments</comments>
		<pubDate>Fri, 10 Aug 2007 23:20:48 +0000</pubDate>
		<dc:creator>Elan Shudnow</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Office]]></category>

		<guid isPermaLink="false">http://www.shudnow.net/2007/08/10/outlook-2007-certificate-error/</guid>
		<description><![CDATA[When importing a new certificate into Exchange 2007/2010, you might encounter a certificate error in Outlook 2007/2010. I have included a screenshot of the error I encountered with Outlook 2007 : When you choose the View Certificate button, it brings up another window that shows you what certificate is in error. In this case, the [...]]]></description>
			<content:encoded><![CDATA[<p>When importing a new certificate into Exchange 2007/2010, you might encounter a certificate error in Outlook 2007/2010.  I have included a screenshot of the error I encountered with Outlook 2007 :</p>
<p><img src="http://www.shudnow.net/images/Outlook2007Error1.jpg" alt="" /></p>
<p>When you choose the View Certificate button, it brings up another window that shows you what certificate is in error.  In this case, the certificate name is &#8220;mail.shudnow.net.&#8221;</p>
<p>So the million dollar question?  Why the error?</p>
<p>Well, when we install a new certificate, there are a few tasks we want to do.   Obviously, we install the certificate for a purpose.  This purpose is till allow us to use Exchange services securely.  So how do we enable Exchange to use these services?  If you are planning to do a very simple configuration and do not care about external Autodiscover access, you do not need to use a Unified Communication Certificate.  You can read more about these certificates in one of my other articles <a href="http://www.shudnow.net/2007/07/15/publishing-exchange-2007-autodisover-in-isa-2006/" target="_blank">here</a>.</p>
<p>So let&#8217;s say we have a simple regular common certificate.  A certificate with a Common Name (CN) of mail.shudnow.net  We install this certificate onto our Exchange box with its&#8217; private key.  In our case we were migrating so we did not have to request a certificate via IIS.  We just exported it with its&#8217; private key and imported onto the new box.  We then assigned this certificate to IIS.   Now I went to the Exchange Management Shell and enabled Exchange services to use this certificate.  In order to do this, you must run the following commands:</p>
<p><strong>Get-ExchangeCertificate</strong></p>
<p>Thumbprint                                                                                  Services        Subject<br />
&#8212;&#8212;&#8212;-                                                                                      &#8212;&#8212;&#8211;          &#8212;&#8212;-<br />
BCF9F2C3D245E2588AB5895C37D8D914503D162E9        SIP.W            CN=mail.shudnow.net.com</p>
<p>What I did was go ahead and enable all new services to use every available service by using the following command:</p>
<p><strong>Enable-exchangecertificate</strong> <strong>-services IMAP, POP, UM, IIS, SMTP </strong>-<strong>Thumbprint BCF9F2C3D245E2588AB5895C37D8D914503D162E9</strong></p>
<p>The next step would be to ensure the AutodiscoverInternalURI is pointed to the CAS that will be your primary CAS for Autodiscover servicing.</p>
<p><strong>Get-ClientAccessServer -Identity </strong><strong><em>CASServer</em></strong><strong> | FL </strong></p>
<p>AutoDiscoverServiceInternalUri : https://casnetbiosname/Autodiscover/Autodiscover.xml</p>
<p>See the issue here?  We are not using a UC certificate that contains the names, &#8220;casnetbiosname, casnetbiosname.shudnow.net, mail.shudnow.net, and autodiscover.shudnow.net&#8221;  Since the Autodiscover directory in IIS will be requring SSL encryption, the url specified in the AutoDiscoverServiceInternalURI must match what is specified in your certificate.  You must also ensure there is a DNS record that allows mail.shudnow.net to resolve to your CAS.   We should re-configure the AutoDiscoverServiceInternalURI by using the following command:</p>
<p><strong>Set-ClientAccessServer -Identity </strong><strong><em>CASServer </em>-AutoDiscoverServiceInternalUri</strong><strong> https://mail.shudnow.net/Autodiscover/Autodiscover.xml</strong></p>
<p>We now need to go configure all the InternalURLs for each web distributed service.   If you are going to be utilizing the Autodiscover service from the outside or for non-domain joined clients, you may want to configure an -ExternalURL in addition to your -InternalURL.</p>
<p>Here is the reason why we were receiving the certificate errors.  Your InternalURLs most likely are not using mail.shudnow.net.  Your InternalURLs are most likely pointed to something such as https://casnetbiosname/ServiceURL which will fail since this is not the CN of your simple certificate.</p>
<p>You can run the following commands to fix your internalURLs so your Outlook 2007 client can successfully take advantage of your web distribution services.</p>
<p><strong><em>Set-WebServicesVirtualDirectory -Identity “</em></strong><strong><em>CASServer</em></strong><strong><em>\EWS (Default Web Site)” -InternalURL https://mail.shudnow.net/EWS/Exchange.asmx -BasicAuthentication:$true</em> </strong></p>
<p><strong><em>Set-OABVirtualDirectory -Identity “</em></strong><strong><em>CASServer</em></strong><strong><em>\OAB (Default Web Site)” -InternalURL https://mail.shudnow.net/OAB</em></strong></p>
<p><strong>Note:</strong> You must ensure that you enable SSL on the OAB directory in IIS which is not on by default.<span> </span>The above command will only enable SSL, but will not ensure 128-bit SSL is required.</p>
<p><strong><em>Enable-OutlookAnywhere -Server </em></strong><strong><em>CASServer</em></strong><strong><em> -ExternalHostname “mail.shudnow.net” -ClientAuthenticationMethod “Basic”-SSLOffloading:$False</em></strong></p>
<p><strong>Note:</strong> The above Enable-OutlookAnywhere command works on SP1.  For RTM, substitute -ClientAuthenticationMethod with -ExternalAuthenticationMethod.</p>
<p><strong><em>Set-ActiveSyncVirtualDirectory -Identity “</em></strong><strong><em>CASServer</em></strong><strong><em>\Microsoft-Server-ActiveSync (Default Web Site)” -ExternalURL https://mail.shudnow.net/Microsoft-Server-Activesync</em> </strong></p>
<p class="MsoNormal"><strong><em>Set-UMVirtualDirectory -Identity “CASServer\UnifiedMessaging (Default Web Site)” -</em><em>InternalURL https://mail.shudnow.net/UnifiedMessaging/Service.asmx</em><em> -BasicAuthentication:$true</em></strong></p>
<p class="MsoNormal"><strong>Note:</strong> The above Set-UMVirtualDirectory command is not needed in Exchange 2010.  Exchange 2010 no longer contains a UnifiedMessaging virtual directory and instead uses the Web Services Virtual Directory.</p>
<img src="http://www.shudnow.net/?ak_action=api_record_view&id=20&type=feed" alt="" /><p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.shudnow.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shudnow.net/2007/08/10/outlook-2007-certificate-error/feed/</wfw:commentRss>
		<slash:comments>140</slash:comments>
		</item>
	</channel>
</rss>
