• RSS
  • Twitter
  • FaceBook

Henrik Walther Blog RSS

All Blogs  »  Henrik Walther Blog  »  News  »  Blog article: Getting an error when setting up a federation trust in Exchange 2010?

Getting an error when setting up a federation trust in Exchange 2010?

Then you’re not alone. Although I have setup a couple of Exchange 2010 federation trusts without issues, I for some reason (explained later) got this error in a specific customer environment of mine:

image

As you can see from the above screenshot, the request failed with an HTTP status 403: Forbidden. The warning messaging explains this is because the Window Live metadata document is expired, and the certificate therefore is ignored. So what the hell does that mean?

Well, the explanation to this error was simple. It turned out that the certificate I used was from a 3rd party CA authority, that wasn’t on the list of CAs approved by the Microsoft Federation Gateway (MFG) service. You can find a list of supported CAs at this link: http://msdn.microsoft.com/en-us/library/cc287610.aspx

Thanks to Andrew Ehrensing from MCS for getting me on the right track in regards to this issue.

Cheers,

Henrik Walther
Technology Architect/Writer
MCM: Exchange 2007 | MVP: Exchange Architecture
MCITP: EMA + EA | MCSE: M + S | TechNet Influent

clip_image001

2 Responses to “Getting an error when setting up a federation trust in Exchange 2010?”

  1. Hans Willi Kremer Says:

    July 5th, 2010 at 2:08 am

    Thanks for this explanation. But it is unbelievable that so little CAs are accepted by Microsoft.
    We have a special UC cert by COMODO and trid to install Federeation. No chance. So we should stop using Federation as solution?

  2. Henrik Walther Says:

    July 5th, 2010 at 3:35 am

    Hi Hans,

    IIRC SP1 will allow an org to use a self-signed cert….

Leave a Reply


Receive all the latest articles by email!

Receive Real-Time & Monthly MSExchange.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an MSExchange.org member!

Discuss your Exchange Server issues with thousands of other Exchange experts. Click here to join!