Certificate error "A connection couldn't be made to the Exchange server..."

Witor 21 Reputation points
2022-03-19T12:31:30.74+00:00

Hi there, wondering if anyone could help me with an issue that has cropped up during a migration to o365.

The issue is similar, possibly the same as the link below:

https://social.msdn.microsoft.com/Forums/en-US/5f6cb095-fc46-4072-9d0c-de23ec7dee08/certificate-error-quota-connection-couldnt-be-made-to-the-exchange-serverquot?forum=exchangesvrgeneral

So in essence we have 4 Exchange 2013 (full patched to latest CU), 2x CAS servers and 2x MBX servers, as part of the migration to o365 we encountered issues with certificates, leading to us to verify what was going on. However, on both Mailbox servers, simply trying "get-exchangecertificate" leads to the following error: (attached image)

184814-a1.jpg

All other services are up and running INCLUDING the service host, ECP / IIS / OWA all functioning correctly. However certificates tab in ECP is inaccessible, and as explained, also via Command line. Rebooting and patching up to latest CU has not solved the issue.

Any thoughts or advice? Can paste further information if needed.

Exchange | Exchange Server | Management
Exchange | Hybrid management
{count} votes

Accepted answer
  1. KyleXu-MSFT 26,396 Reputation points
    2022-03-21T05:50:56.357+00:00

    @Witor
    I also want to confirm with you whether you could restart this service manually? If you cannot restart this service manually, try to stop it from Task Manager, then restart from Service.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Witor 21 Reputation points
    2022-03-21T11:02:40.56+00:00

    @Andy David - MVP - Both Mailbox Servers reporting all states as "active"

    @KyleXu-MSFT - Previously we could stop/start the service via services with no issue. Today I could not stop the service (on both mailbox servers, CAS servers remained fine), tried your method via Task manager, and successfully restarted from services. This led me to re-test the "get-exchangecertificate" which failed constantly.

    I have now been able to:

    1. View "get-exchangecertificates" from each server - Working fine
    2. View "get-exchangecertificates -server "all of our exchange servers" - Working fine.
    3. Equivalent page via ECP --> Servers --> Certificates = Now viewable.

    I'm sure there's something not quite 100% on our system, but at least (post-boot) - I can now access certificate information, via ECP or Shell. Thank you so much!


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.