<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate Authority)</title>
	<atom:link href="http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/</link>
	<description>Microsoft Office Communications Server - Tips, Tricks, and Insight</description>
	<lastBuildDate>Thu, 26 Jan 2012 18:22:01 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Shakti Moudgil</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-9134</link>
		<dc:creator>Shakti Moudgil</dc:creator>
		<pubDate>Tue, 27 Sep 2011 23:29:58 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-9134</guid>
		<description>Hi Curtis,

There is a user in our company server team give him Audio Video access on OCS, but while using his system user unable to use these features, then i recreate user profile on same system it not works. So i check on local admin on same system using his id it works. So, we check on other system using his id this feature works on his id. So will you suggest me what&#039;s the issue with his profile and need your suggestion on this. Please mail me on ershaktimoudgil@hotmail.com.</description>
		<content:encoded><![CDATA[<p>Hi Curtis,</p>
<p>There is a user in our company server team give him Audio Video access on OCS, but while using his system user unable to use these features, then i recreate user profile on same system it not works. So i check on local admin on same system using his id it works. So, we check on other system using his id this feature works on his id. So will you suggest me what&#8217;s the issue with his profile and need your suggestion on this. Please mail me on <a href="mailto:ershaktimoudgil@hotmail.com">ershaktimoudgil@hotmail.com</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn Harry</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-5414</link>
		<dc:creator>Shawn Harry</dc:creator>
		<pubDate>Sun, 30 Jan 2011 21:44:36 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-5414</guid>
		<description>Although not supported you can get OCS to work happily with a self signed certificate. The premise of the cert being trusted is no different than using Microsoft CA or any private CA. As long as the certificate is present in the Trusted Root of the &quot;Computer&quot; account it will work. For lab environments this is fine. Naturally though in production you would not want this scenario unless using auto enrolment. For the price of a certificate these days (which is cheap) it wouldn&#039;t be worth the hassle and of course it would be unsupported.</description>
		<content:encoded><![CDATA[<p>Although not supported you can get OCS to work happily with a self signed certificate. The premise of the cert being trusted is no different than using Microsoft CA or any private CA. As long as the certificate is present in the Trusted Root of the &#8220;Computer&#8221; account it will work. For lab environments this is fine. Naturally though in production you would not want this scenario unless using auto enrolment. For the price of a certificate these days (which is cheap) it wouldn&#8217;t be worth the hassle and of course it would be unsupported.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Communicator Sign-In Problems After OCS Certificate Renewal &#171; Inside OCS</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-3269</link>
		<dc:creator>Communicator Sign-In Problems After OCS Certificate Renewal &#171; Inside OCS</dc:creator>
		<pubDate>Wed, 18 Aug 2010 15:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-3269</guid>
		<description>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate... [...]</description>
		<content:encoded><![CDATA[<p>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Curtis Johnstone</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-2771</link>
		<dc:creator>Curtis Johnstone</dc:creator>
		<pubDate>Sat, 12 Jun 2010 02:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-2771</guid>
		<description>Certificates can be frustrating. Once you get them working it&#039;s all worth it :-).  I&#039;ll send you an email and see if we can get it working.</description>
		<content:encoded><![CDATA[<p>Certificates can be frustrating. Once you get them working it&#8217;s all worth it <img src='http://blog.insideocs.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .  I&#8217;ll send you an email and see if we can get it working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pslager</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-2765</link>
		<dc:creator>pslager</dc:creator>
		<pubDate>Fri, 11 Jun 2010 17:23:08 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-2765</guid>
		<description>My Computer is the only one that will automatically sign into OCS 2007 R2.  Every other computer gets a certificate error:  Error Viewing the Certificate.  I tried taking the OCS pool certificate and exporting it, and installing it on all of the clients and it says it installs but I cant find the certificate in the MMC console after I do it.  I am starting to hate OCS and all of these certificates.</description>
		<content:encoded><![CDATA[<p>My Computer is the only one that will automatically sign into OCS 2007 R2.  Every other computer gets a certificate error:  Error Viewing the Certificate.  I tried taking the OCS pool certificate and exporting it, and installing it on all of the clients and it says it installs but I cant find the certificate in the MMC console after I do it.  I am starting to hate OCS and all of these certificates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The OCS 2007 Automatic Sign-In Troubleshooting Tool V1.0 &#171; Inside OCS</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-120</link>
		<dc:creator>The OCS 2007 Automatic Sign-In Troubleshooting Tool V1.0 &#171; Inside OCS</dc:creator>
		<pubDate>Wed, 29 Jul 2009 16:24:58 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-120</guid>
		<description>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate...  Possibly related posts: (automatically generated)Automatic Office Communicator Sign-In (Part 1 – The Correct DNS Service L&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate&#8230;  Possibly related posts: (automatically generated)Automatic Office Communicator Sign-In (Part 1 – The Correct DNS Service L&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Automatic Office Communicator Sign-In (Part 1 &#8211; The Correct DNS Service Location (SRV) Record) &#171; Inside OCS</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-115</link>
		<dc:creator>Automatic Office Communicator Sign-In (Part 1 &#8211; The Correct DNS Service Location (SRV) Record) &#171; Inside OCS</dc:creator>
		<pubDate>Fri, 24 Jul 2009 21:36:51 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-115</guid>
		<description>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate... [...]</description>
		<content:encoded><![CDATA[<p>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DNS Records and Office Communicator Automatic Client Sign-In &#171; Inside OCS</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-114</link>
		<dc:creator>DNS Records and Office Communicator Automatic Client Sign-In &#171; Inside OCS</dc:creator>
		<pubDate>Fri, 24 Jul 2009 21:33:33 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-114</guid>
		<description>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate... [...]</description>
		<content:encoded><![CDATA[<p>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Automatic Office Communicator Sign-In (Part 2 – ensuring the correct Subject Name on the Certificate) &#171; Inside OCS</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-122</link>
		<dc:creator>Automatic Office Communicator Sign-In (Part 2 – ensuring the correct Subject Name on the Certificate) &#171; Inside OCS</dc:creator>
		<pubDate>Fri, 24 Jul 2009 21:16:58 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-122</guid>
		<description>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate... [...]</description>
		<content:encoded><![CDATA[<p>[...] Automatic Office Communicator Sign-In (Part 3 – ensuring the client trusts the issuing Certificate&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Curtis Johnstone</title>
		<link>http://blog.insideocs.com/2008/09/23/making-automatic-office-communicator-sign-in-work-part-3-%e2%80%93-ensuring-the-client-trusts-the-issuing-certificate-authority/comment-page-1/#comment-124</link>
		<dc:creator>Curtis Johnstone</dc:creator>
		<pubDate>Tue, 30 Jun 2009 15:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://ocsbuzz.wordpress.com/?p=92#comment-124</guid>
		<description>I don&#039;t know the details of the $30 certificate you mention, but $30 sounds too good to be true in my experience. I would be surprised if it met all the requirements of a UCC certificate. Generally speaking, to use a certificate on an OCS 2007 Front-End, the certificate should be a Web certificate with Enhanced Key Usage for server authentication.

If you submit the certificate request to your CA (GoDaddy) by generating a Certificate Signing Request (CSR) using the OCS 2007 Certificate Wizard, the necessary requirements should be included in that request. I have first-hand experience, and have heard from others, that DigiCert offers a cost effective UCC certificate (that is not an endorsement plug for &lt;a href=&quot;http://www.digicert.com/unified-communications-ssl-tls.htm&quot; rel=&quot;nofollow&quot;&gt;DigiCert&lt;/a&gt;; just relaying my experience).

Also, Microsoft has a list of CA&#039;s that issue UCC certificates for Exchange and OCS in this Knowledge Base Article: &lt;a href=&quot;http://support.microsoft.com/kb/929395&quot; rel=&quot;nofollow&quot;&gt;Unified Communications Certificate Partners for Exchange 2007 and for Communications Server 2007&lt;/a&gt;.

Note: for the Web Components Server, you should use the IIS certificate wizard. See Section 3.7 (Configure the Web Components Server IIS Certificate) in the &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyId=53F65DC9-09DC-4748-81F7-48457469E550&quot; rel=&quot;nofollow&quot;&gt;OCS 2007 Deployment Guide &lt;/a&gt;for more information.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know the details of the $30 certificate you mention, but $30 sounds too good to be true in my experience. I would be surprised if it met all the requirements of a UCC certificate. Generally speaking, to use a certificate on an OCS 2007 Front-End, the certificate should be a Web certificate with Enhanced Key Usage for server authentication.</p>
<p>If you submit the certificate request to your CA (GoDaddy) by generating a Certificate Signing Request (CSR) using the OCS 2007 Certificate Wizard, the necessary requirements should be included in that request. I have first-hand experience, and have heard from others, that DigiCert offers a cost effective UCC certificate (that is not an endorsement plug for <a href="http://www.digicert.com/unified-communications-ssl-tls.htm" rel="nofollow">DigiCert</a>; just relaying my experience).</p>
<p>Also, Microsoft has a list of CA&#8217;s that issue UCC certificates for Exchange and OCS in this Knowledge Base Article: <a href="http://support.microsoft.com/kb/929395" rel="nofollow">Unified Communications Certificate Partners for Exchange 2007 and for Communications Server 2007</a>.</p>
<p>Note: for the Web Components Server, you should use the IIS certificate wizard. See Section 3.7 (Configure the Web Components Server IIS Certificate) in the <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=53F65DC9-09DC-4748-81F7-48457469E550" rel="nofollow">OCS 2007 Deployment Guide </a>for more information.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

