Problem with IMAP after renewing SSL certificate

Anonymous
2021-02-24T09:34:07.107+00:00

Hello Everyone
I have 2 CAS servers and 2 MBX servers , after renewing the expired SSL certificate on both of CAS , i had a problem with users who use protocol IMAP to connect , applications who send mails via IMAP and MAC users .
I found this errors with the following ID in booth of my CAS servers :
Schannel errors with s ID : 36888 , 36874 , 36887

I followed the link bellow and created the messing values :
https://kemptechnologies.com/blog/enabling-tls-1-2-on-exchange-server-2013-2016-part-1/

The problem remains the same ,
Would you help me please identify the problem71533-error.png

I have also found the following error :46 = TLS1_ALERT_CERTIFICATE_UNKNOWN

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,173 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,345 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Xzsssss 8,861 Reputation points Microsoft Vendor
    2021-02-25T06:34:16.873+00:00

    Hi @Anonymous ,

    Good day!

    Sorry but i can't understand the logs, if you could, please translate it into English. And share the General of these three (36888 , 36874 , 36887) events.
    Only users using IMAP got this error? And what's the symptoms, like users couldn't login or something else?
    And the application is a mobile app?
    Forgive me about these stupid questions, and please share more details with me so i can better understand this issue and help you...

    I think you can first check the IMAP settings with:

    Get-ImapSettings | Format-List *ConnectionSettings,*Bindings,X509CertificateName  
    

    Make sure the certificate is right.

    As for the error: 46 = TLS1_ALERT_CERTIFICATE_UNKNOWN
    Since it's saying this error is a Certificate error, you can check the Bindings in IIS. Make sure the Https sites are using the correct cert.

    Regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.