Question regarding the CAS server names on the certificate. Although several sources state that the server names do not need to be included on the certificate, this does not seem to be correct. I just had an embarrasing experience at the customer site. Exchange 2013 SP1 deployed into an existing Exchange 2007 organisation. With the certificate that does not include CAS FQDNs, Outlook 2013 client connects via Windows Load Balancing towards the load balancing cluster name mail.company.com and pops up: "I can't connect to "CASnodename". On the CAS both internal and external URLs are set to mail.company.com as per Exchange Server Deployment Assistant. Including the CAS FQDNs on the certificate solved the issue. Or there might be something forgotten in the Deployment Assistant ? Or any special setting in Windows Load Balancing that needs to be set?