MS Outlook had problems encrypting this message...


problem: working 2 users in test environment, see both can send each other signed email. however:

*

- alan reid can send alex heyne encrypted emails

but

- opposite not true (alex heyne cannot send alan reid encrypted emails).

**

**

environment: domain, windows 2003 ffl

- 1 windows 2008 r2 sp1 domain controller adds , adcs.

- 1 exchange 2010 sp3 mail server

- single ca (it's running on domain controller)

- client machine windows 7 sp1 outlook 2010 sp1

**

**


preliminary notes:

- duplicated "exchange user" template.

- general tab of template: yes, "publish certificate in active directory"is checked.

- request handling tab: purpose: signature , encryption.

*

other configured settings should correct since...

- users automatically obtain certificate via group policy , autoenrollment.

- certificate appear in user certificate store.

- can used sign email messages. resulting message has "seal" or "medal" or "ribbon" icon indicates signed.

*

*

besides verifying preceeds:

- in adsiedit, "usercertificate" attribute of both sender , recipient populated sequence of 2 digit numbers , slashes.

this result of certutil command ran after reading post:

http://social.technet.microsoft.com/forums/windowsserver/en-us/531d8e81-f2c8-4b48-9b6f-0318ea204ed1/office-outlook-had-problems-encrypting-this-message-because-the-following-recipients-had-missing-or

c:\>certutil -verify -urlfetch certificatefile.crt
decodefile returned system cannot find file specified. 0x80070002 (win32
: 2)
loadcert(cert) returned system cannot find file specified. 0x80070002 (w
in32: 2)
certutil: -verify command failed: 0x80070002 (win32: 2)
certutil: system cannot find file specified.

*

that's result either user, when run admin.

i'm going try other users right now.

otherwise, how can troubleshoot beyond have done?


please mark helpful if find contribution useful or answer if answer question. encourage me - , others - take time out you.

moreover, it's normal signed email can viewed others, because signature ensures email sent user claims he/she a, rather user b. encrypted email visible recipient recipient owns private key of certificate.

to encrypt emails, users certificate should published active directory, adsiedit can view how certificate stored, should check certificate in active directory users , computer.

1. open active directory users , computers console, click view -> advanced features.

2. find user object, click on published certificates, verify certificate has been published properly.

3. make sure certificate user owns works well.

regards,

diana


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group