Exchange Hybrid - UntrustedRoot all of a sudden

Federico 25 Reputation points
2023-05-18T06:39:26.46+00:00

Hi,

All of a sudden, mail flow from on-prem to Exchange Online stopped.

The connector shows a "450 4.4.317 Cannot connect to remote server [Message=UntrustedRoot]" error.

It seems that the TLS certificate is not being recognized as trusted from Exchange Online.

However, my public cert is valid and from a CA validated by MS.

Any idea about troubleshooting this? Thanks!

Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,886 questions
0 comments No comments
{count} vote

Accepted answer
  1. Andy David - MVP 141.6K Reputation points MVP
    2023-05-18T10:57:15.7533333+00:00

    Is there any device between the on-prem Exchange Server and 365 that may be interfering with the mail flow?

    https://learn.microsoft.com/en-us/exchange/edge-transport-servers

    User's image

    2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Deepak john 1 Reputation point
    2024-03-28T12:17:57.2133333+00:00

    If there is a mail filter /anti spam gateway device is in between Exchange online and your onprem exchange, You should verify TLS is enabled on the default frontend receive connector. Verify if exchange server is having a valid certificate, also verify if you are seeing show STARTTLS when connected on smtp port 25 using telnet .

    Upload the certificate on the middle device and enable tls on that device as well.

    Finally even if that is failling for some reason whitelist microsoft exchange online network showing port 25 in below link on antispam gateway.

    https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide

    0 comments No comments