{"id":5781,"date":"2015-06-14T11:42:41","date_gmt":"2015-06-14T19:42:41","guid":{"rendered":"https:\/\/www.zubairalexander.com\/stage\/?p=5781"},"modified":"2018-05-23T10:22:10","modified_gmt":"2018-05-23T17:22:10","slug":"dealing-with-a-missing-microsoft-exchange-server-auth-certificate-that-causes-federation-or-auth-certificate-not-found-warnings","status":"publish","type":"post","link":"https:\/\/www.zubairalexander.com\/blog\/dealing-with-a-missing-microsoft-exchange-server-auth-certificate-that-causes-federation-or-auth-certificate-not-found-warnings\/","title":{"rendered":"Dealing with a Missing Microsoft Exchange Server Auth Certificate that Causes &#8220;Federation or Auth certificate not found&#8221; Warnings"},"content":{"rendered":"<p>As part of Exchange Server 2013, a self-signed certificate called <em>Microsoft Exchange Server Auth Certificate<\/em> is created on the server. You can find this certificate in the local computer certificate store. This certificate is used for server-to-server authentication which is required to integrate Microsoft Exchange, Lync and SharePoint. Needless to say, this is an important certificate. If for some reason this certificate is missing on your Exchange Server 2013, you should see the following warning in the Event Viewer on your Exchange Server 2013.<\/p>\n<p><em>Federation or Auth certificate not found: &lt;Certificates_thumbprint&gt;. Unable to find the certificate in the local or neighboring sites. Confirm that the certificate is available in your topology and if necessary, reset the certificate on the Federation Trust to a valid certificate using Set-FederationTrust or Set-AuthConfig.\u00a0 The certificate may take time to propagate to the local or neighboring sites.<\/em><\/p>\n<p><a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-5782\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005.png\" alt=\"\" width=\"853\" height=\"757\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005.png 853w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005-300x266.png 300w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005-768x682.png 768w\" sizes=\"(max-width: 853px) 100vw, 853px\" \/><\/a><\/p>\n<p><strong>SOLUTION<\/strong><\/p>\n<p>To fix the problem of missing certificate, use the following procedure. First you need to create a new Exchange certificate, use the Set-AuthConfig cmdlet to tell Exchange about this new certificate and then publish it.<\/p>\n<ol>\n<li>Start Microsoft Exchange Management Shell on your Exchange Server 2013.<\/li>\n<li>Create a new Exchange certificate using the following command. Replace the command in bold with your domain name, e.g. <strong>*.example.com<\/strong>.<br \/>\n<span style=\"color: #ff0000;\">WARNING!<\/span> <span style=\"color: #ff0000;\">Do not remove the quotes around the domain name and do not overwrite the default SMTP certificate.<\/span><br \/>\n<em>New-ExchangeCertificate -KeySize 2048 -PrivateKeyExportable $true -SubjectName &#8220;cn= Microsoft Exchange Server Auth Certificate&#8221; -DomainName &#8220;*<strong>.yourdomain.com<\/strong>&#8221; -FriendlyName &#8220;Microsoft Exchange Server Auth Certificate&#8221; -Services SMTP<\/em><\/li>\n<li>When prompted to overwrite the existing default SMTP certificate answer No.<\/li>\n<li>Copy the thumbprint of the newly created certificate. You will need that shortly.<\/li>\n<li>Type the following command and press ENTER. You will not see any output.<br \/>\n<em>$a=get-date<\/em><\/li>\n<li>Enter the following command. Replace the words <em>your_certificate&#8217;s_thumbprint_goes_here<\/em> with your certificate&#8217;s thumbprint that you copied int Step 4 above.<br \/>\nSet-AuthConfig -NewCertificateThumbprint <strong>your_certificate&#8217;s_thumbprint_goes_here<\/strong> \u2013NewCertificateEffectiveDate $a<\/li>\n<li>You will see a prompt that the new certificate effective date is not at least &#8220;48&#8221; hours in the future and may not be deployed on all necessary servers. Ignore this prompt and type Yes to continue. Because Yes is the default answer, you can also press ENTER to continue which means you are accepting the default answer.<br \/>\n<a href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-5785\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert.png\" alt=\"\" width=\"1234\" height=\"617\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert.png 1234w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert-300x150.png 300w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert-768x384.png 768w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/ExchangeAuthCert-1024x512.png 1024w\" sizes=\"(max-width: 1234px) 100vw, 1234px\" \/><\/a><\/li>\n<li>Publish the new certificate using the following command:<br \/>\nSet-AuthConfig \u2013PublishCertificate<\/li>\n<li>In case you have a previous certificate, you may want to run the following command to clear the previous certificate.<br \/>\nSet-AuthConfig -ClearPreviousCertificate<\/li>\n<li>The last thing you need to do is run <em>IISRESET<\/em> command. Exchange Server 2013 has two roles: Client Access Server and Mailbox. Run IISRESET on all your CAS and mailbox servers.<\/li>\n<\/ol>\n<p>You should no longer see the warnings in the Event Viewer on your Exchange Server 2013. In fact, it should fix several additional warnings\/errors and hopefully your application log will look very clean.<\/p>\n<hr \/>\n<p><span style=\"font-size: xx-small; font-family: Verdana;\">Copyright \u00a9 2015 SeattlePro Enterprises, LLC. All rights reserved.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of Exchange Server 2013, a self-signed certificate called Microsoft Exchange Server Auth Certificate is created on the server. You can find this certificate in the local computer certificate store. This certificate is used for server-to-server authentication which is required to integrate Microsoft Exchange, Lync and SharePoint. Needless to say, this is an important [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":5782,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[43,3,54,68,11],"tags":[],"class_list":["post-5781","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","category-exchange-outlook","category-sharepoint","category-skype","category-tips-tricks"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2015\/06\/EventID_2005.png","_links":{"self":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/5781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/comments?post=5781"}],"version-history":[{"count":0,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/5781\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media\/5782"}],"wp:attachment":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media?parent=5781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/categories?post=5781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/tags?post=5781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}