<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
	>
<channel>
	<title>Comments on: Entourage Exchange Error &#8211; &#8220;Unable to establish a secure connection to&#8230;&#8221;</title>
	<atom:link href="http://danisrael.scekc.com/pro-audio/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/feed/" rel="self" type="application/rss+xml" />
	<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html</link>
	<description>That&#039;s right...It&#039;s all about me!</description>
	<lastBuildDate>Mon, 06 Feb 2012 07:55:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Marc Morris</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-238</link>
		<dc:creator>Marc Morris</dc:creator>
		<pubDate>Thu, 02 Dec 2010 20:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-238</guid>
		<description>I solved this error
unable to establish a secure connection to  because a certificate on the server&#039;s certificate chain has expired or is not yet vaild 

I chattted with verisign and they gave me the correct intermediate and root certificates , I loaded these into key chain, the next time I opened entourage there was a message to always allow the certificate into my key chain, problem solved.......finally</description>
		<content:encoded><![CDATA[<p>I solved this error<br />
unable to establish a secure connection to  because a certificate on the server&#8217;s certificate chain has expired or is not yet vaild </p>
<p>I chattted with verisign and they gave me the correct intermediate and root certificates , I loaded these into key chain, the next time I opened entourage there was a message to always allow the certificate into my key chain, problem solved&#8230;&#8230;.finally</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danisrael</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-196</link>
		<dc:creator>danisrael</dc:creator>
		<pubDate>Sun, 19 Apr 2009 16:54:20 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-196</guid>
		<description>Christo...that&#039;s good info.

Since you are getting mail, I&#039;m assuming the error pops sometime during Entourage&#039;s being open.  This is almost certainly a directory lookup error.

You can verify this, by opening Entourage and selecting new mail message.  Then in the drop down, select Global Address Book.  If you get the message, than you are defientaly expierncing an LDAP look up issue.

What makes this whole process a pain, is the myriad of combinations that exist and the requirement that your settings match your companies.  They will only communicate with your system if you present to them as expected.  This causes some very misleading error messages.  

For instance, if you uncheck SSL and your system admins have selected &quot;SSL required&quot; on the iis server - then you may be presented with a dialog saying &quot;could not establish a secure connection.&quot;  In reality, the error could be:

a) &quot;Your trying to communicate on a non-secure channel, and SSL security is required to talk to this server.&quot;
b) &quot;Your system does not appear to be a computer this server wants to talk to securely&quot;
c) &quot;The server you are connecting to  cannot talk to this computer securely&quot;
d) &quot;The server (or computer) is not who they say they are&quot;

In your case, I would imagine there is going to be an incompatiblity with your corporate structure and Entourage.  If your system ADMINs have require communiation to the LDAP server to be SSL, and they don&#039;t have an external certificate for  communciating with the LDAP server.  You will not be able to avoid this.

The LDAP server&#039;s certificate must match what you are putting in for a name in the LDAP Server box under the Directory Services&gt;Advanced Tab.

If you can, ask an ADMIN this.

1) Is it possible to contact the Global Address Book/LDAP server external, and if so..
2) Is it standard SSL
3) What is the exact FDQN the machine is certifcated for.

As a work around, you might try removing any server names from the LDAP server box.  That way no attempt is made to contact it.</description>
		<content:encoded><![CDATA[<p>Christo&#8230;that&#8217;s good info.</p>
<p>Since you are getting mail, I&#8217;m assuming the error pops sometime during Entourage&#8217;s being open.  This is almost certainly a directory lookup error.</p>
<p>You can verify this, by opening Entourage and selecting new mail message.  Then in the drop down, select Global Address Book.  If you get the message, than you are defientaly expierncing an LDAP look up issue.</p>
<p>What makes this whole process a pain, is the myriad of combinations that exist and the requirement that your settings match your companies.  They will only communicate with your system if you present to them as expected.  This causes some very misleading error messages.  </p>
<p>For instance, if you uncheck SSL and your system admins have selected &#8220;SSL required&#8221; on the iis server &#8211; then you may be presented with a dialog saying &#8220;could not establish a secure connection.&#8221;  In reality, the error could be:</p>
<p>a) &#8220;Your trying to communicate on a non-secure channel, and SSL security is required to talk to this server.&#8221;<br />
b) &#8220;Your system does not appear to be a computer this server wants to talk to securely&#8221;<br />
c) &#8220;The server you are connecting to  cannot talk to this computer securely&#8221;<br />
d) &#8220;The server (or computer) is not who they say they are&#8221;</p>
<p>In your case, I would imagine there is going to be an incompatiblity with your corporate structure and Entourage.  If your system ADMINs have require communiation to the LDAP server to be SSL, and they don&#8217;t have an external certificate for  communciating with the LDAP server.  You will not be able to avoid this.</p>
<p>The LDAP server&#8217;s certificate must match what you are putting in for a name in the LDAP Server box under the Directory Services>Advanced Tab.</p>
<p>If you can, ask an ADMIN this.</p>
<p>1) Is it possible to contact the Global Address Book/LDAP server external, and if so..<br />
2) Is it standard SSL<br />
3) What is the exact FDQN the machine is certifcated for.</p>
<p>As a work around, you might try removing any server names from the LDAP server box.  That way no attempt is made to contact it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christo Acosta</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-195</link>
		<dc:creator>Christo Acosta</dc:creator>
		<pubDate>Sat, 18 Apr 2009 15:12:26 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-195</guid>
		<description>Hi Daniel,

Thanks for the reply! I have both unchecked SSL settings for the LDAP and Exchange server. The Exchange Server is 2007.

I didn&#039;t make it very clear, &quot;onyx.local&quot; is simply the DNS suffix at work. My connection address is a FQDN, I&#039;ve never used the .local address in Entourage: My connection is set to smtp.XXXX.com (XXXX just for privacy). If I want to use OWA, I can connect to http://smtp.XXXX.com/owa without problems.

Also, I actually get and can send the mail without issue, it&#039;s just the error that&#039;s bothersome :)

Thanks for the help so far!

-C</description>
		<content:encoded><![CDATA[<p>Hi Daniel,</p>
<p>Thanks for the reply! I have both unchecked SSL settings for the LDAP and Exchange server. The Exchange Server is 2007.</p>
<p>I didn&#8217;t make it very clear, &#8220;onyx.local&#8221; is simply the DNS suffix at work. My connection address is a FQDN, I&#8217;ve never used the .local address in Entourage: My connection is set to smtp.XXXX.com (XXXX just for privacy). If I want to use OWA, I can connect to <a href="http://smtp.XXXX.com/owa" rel="nofollow">http://smtp.XXXX.com/owa</a> without problems.</p>
<p>Also, I actually get and can send the mail without issue, it&#8217;s just the error that&#8217;s bothersome <img src='http://danisrael.scekc.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Thanks for the help so far!</p>
<p>-C</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danisrael</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-194</link>
		<dc:creator>danisrael</dc:creator>
		<pubDate>Sat, 18 Apr 2009 01:41:20 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-194</guid>
		<description>Christo,

Couple of questions:

1) Are you unchecking the LDAP SSL or the mail server?
2) What version is your Exchange server 2000, 2003, 2007?

Regardless, you&#039;ll need to obtain an external connection address to use.  The &lt;domain&gt;.local address is what most companies use for machine addresses behind a firewall (or InTRAnet).

For instance, at our office, internally we connect to &quot;xch.domain.local.&quot;  However, when connecting externally through the inTERnet, then the address is &quot;mail.domain.com.&quot;  This is all setup by an Admin.

If you have webmail, try that address.  But it will definetaly require a FQDN (not a .local)

Does that help?</description>
		<content:encoded><![CDATA[<p>Christo,</p>
<p>Couple of questions:</p>
<p>1) Are you unchecking the LDAP SSL or the mail server?<br />
2) What version is your Exchange server 2000, 2003, 2007?</p>
<p>Regardless, you&#8217;ll need to obtain an external connection address to use.  The <domain>.local address is what most companies use for machine addresses behind a firewall (or InTRAnet).</p>
<p>For instance, at our office, internally we connect to &#8220;xch.domain.local.&#8221;  However, when connecting externally through the inTERnet, then the address is &#8220;mail.domain.com.&#8221;  This is all setup by an Admin.</p>
<p>If you have webmail, try that address.  But it will definetaly require a FQDN (not a .local)</p>
<p>Does that help?</domain></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christo Acosta</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-193</link>
		<dc:creator>Christo Acosta</dc:creator>
		<pubDate>Sat, 18 Apr 2009 01:28:07 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-193</guid>
		<description>Same issue here as Gmon3y... maybe?

Regardless if the SSL option is checked, if I am outside my organization, I get the error &quot;Unable to establish a secure connection to rim.onyx.local.CONNECTION because the server name...&quot; where CONNECTION is my connection wherever I am (i.e.: rim.onyx.local.hsd1.ga.comcast.net). Note: onyx.local is my work domain. I have no clue what part RIM plays... I don&#039;t use BlackBerry, and I don&#039;t *think* we have a full-fledged BlackBerry server. I think we just connect to exchange.

If I am in the office, where onyx.local is my connection, there is no problem.

-C</description>
		<content:encoded><![CDATA[<p>Same issue here as Gmon3y&#8230; maybe?</p>
<p>Regardless if the SSL option is checked, if I am outside my organization, I get the error &#8220;Unable to establish a secure connection to rim.onyx.local.CONNECTION because the server name&#8230;&#8221; where CONNECTION is my connection wherever I am (i.e.: rim.onyx.local.hsd1.ga.comcast.net). Note: onyx.local is my work domain. I have no clue what part RIM plays&#8230; I don&#8217;t use BlackBerry, and I don&#8217;t *think* we have a full-fledged BlackBerry server. I think we just connect to exchange.</p>
<p>If I am in the office, where onyx.local is my connection, there is no problem.</p>
<p>-C</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danisrael</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-192</link>
		<dc:creator>danisrael</dc:creator>
		<pubDate>Sun, 12 Apr 2009 18:23:34 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-192</guid>
		<description>Gmon3y, which of the two errors due you get?  Can you publish the exact error?</description>
		<content:encoded><![CDATA[<p>Gmon3y, which of the two errors due you get?  Can you publish the exact error?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gmon3y</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-190</link>
		<dc:creator>Gmon3y</dc:creator>
		<pubDate>Sun, 12 Apr 2009 11:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-190</guid>
		<description>I followed the steps and still get the same error message. what a pain!

all up-to-date
settings corret
selfsigned sbs cert
 
but nada. outlook works so much better.. ms you greedy farts..lol</description>
		<content:encoded><![CDATA[<p>I followed the steps and still get the same error message. what a pain!</p>
<p>all up-to-date<br />
settings corret<br />
selfsigned sbs cert</p>
<p>but nada. outlook works so much better.. ms you greedy farts..lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danisrael</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-183</link>
		<dc:creator>danisrael</dc:creator>
		<pubDate>Wed, 28 Jan 2009 19:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-183</guid>
		<description>Jeff, they HAVE indeed fixed the error.  

Our error was caused by the LDAP lookup on the Exchange GAL (Global Address List) look-up.  The check box for SSL LDAP was enabled.  Unfortunately, the server name did not match the certificate, because the hardware firewall routed LDAP to the domain controller.  So, the solution would be to use a different HOST name for internet DNS resolution to a machine with the correct certificate.  

After correcting this, the above worked.  Entrouage does function without the certificate error now.  You can test this by unchecking secure LDAP function on the tab of your Exchange account.  Passwords and email are still encrypted.

Hope that helps!</description>
		<content:encoded><![CDATA[<p>Jeff, they HAVE indeed fixed the error.  </p>
<p>Our error was caused by the LDAP lookup on the Exchange GAL (Global Address List) look-up.  The check box for SSL LDAP was enabled.  Unfortunately, the server name did not match the certificate, because the hardware firewall routed LDAP to the domain controller.  So, the solution would be to use a different HOST name for internet DNS resolution to a machine with the correct certificate.  </p>
<p>After correcting this, the above worked.  Entrouage does function without the certificate error now.  You can test this by unchecking secure LDAP function on the tab of your Exchange account.  Passwords and email are still encrypted.</p>
<p>Hope that helps!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://danisrael.scekc.com/it/entourage-exchange-error-unable-to-establish-a-secure-connection-to.html/comment-page-1/#comment-182</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Wed, 28 Jan 2009 19:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://danisrael.scekc.com/?p=245#comment-182</guid>
		<description>wait.. Microsoft has, or has not fixed the error?  Just to clarify!</description>
		<content:encoded><![CDATA[<p>wait.. Microsoft has, or has not fixed the error?  Just to clarify!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

