SOLVED

Exchange OAuth different certificate(s) have been found

%3CLINGO-SUB%20id%3D%22lingo-sub-1450541%22%20slang%3D%22en-US%22%3EExchange%20OAuth%20different%20certificate(s)%20have%20been%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1450541%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%2C%3C%2FP%3E%3CP%3Esince%20yesterday%20I%20get%20the%20following%20warning%20every%20hour%20in%20application%20log.%20We%20have%20a%20hybrid%20exchange%20connection%20running%20fine%20for%20a%20month.%20Besides%20this%20warning%20in%20the%20on-prem%20exchange%20everythings%20seems%20to%20be%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eevent%20id%202008%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMSExchange%20OAuth%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20retrieving%20metadata%20from%20the%20url%20'%3CA%20href%3D%22https%3A%2F%2Faccounts.accesscontrol.windows.net%2F...%2Fmetadata%2Fjson%2F1%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faccounts.accesscontrol.windows.net%2F...%2Fmetadata%2Fjson%2F1%3C%2FA%3E'%2C%20different%20certificate(s)%20have%20been%20found.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3Eand%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20retrieving%20metadata%20from%20the%20url%20'%3CA%20href%3D%22https%3A%2F%2Flogin.windows.net%2Fxxx.onmicrosoft.com%2Ffederationmetadata%2F2007-06%2Ffederationmetadata.xml%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Flogin.windows.net%2Fxxx.onmicrosoft.com%2Ffederationmetadata%2F2007-06%2Ffederationmetadata.xml%3C%2FA%3E'%2C%20different%20certificate(s)%20have%20been%20found.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EIt%20startet%20yesterday%20after%20this%20daily%20event%3A%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EMSExchange%20Certificate%20Notification%3CBR%20%2F%3EA%20round%20of%20expiration%20check%20has%20finished.%20The%20next%20round%20is%20scheduled%20at%20%2209.06.2020%2020%3A37%3A18%22.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EI%20check%20oauth%20connection%20this%20way%20and%20both%20sides%20were%20successfull%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%23how-do-you-know-this-worked%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%23how-do-you-know-this-worked%3C%2FA%3E)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1450541%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1450562%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20OAuth%20different%20certificate(s)%20have%20been%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1450562%22%20slang%3D%22en-US%22%3E%3CP%3Ea%20few%20seconds%20before%20the%20first%20warning%20I%20see%20the%20following%20info%20message%20in%20application%20log%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eevent%3A%202013%3C%2FP%3E%3CP%3EThe%20authentication%20configuration%20information%20for%20trusted%20issuer%20EvoSts%20has%20been%20updated.%3C%2FP%3E%3CP%3EThe%20authentication%20configuration%20information%20for%20trusted%20issuer%20ACS%20has%20been%20updated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1452947%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20OAuth%20different%20certificate(s)%20have%20been%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1452947%22%20slang%3D%22en-US%22%3E%3CP%3EWarning%20is%20gone.%20Stopped%20yesterday%20in%20the%20evening%20without%20any%20changes%20from%20my%20side.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi everyone,

since yesterday I get the following warning every hour in application log. We have a hybrid exchange connection running fine for a month. Besides this warning in the on-prem exchange everythings seems to be fine.

 

event id 2008:

 

MSExchange OAuth

When retrieving metadata from the url 'https://accounts.accesscontrol.windows.net/.../metadata/json/1', different certificate(s) have been found.

and 

 

When retrieving metadata from the url 'https://login.windows.net/xxx.onmicrosoft.com/federationmetadata/2007-06/federationmetadata.xml', different certificate(s) have been found.

It startet yesterday after this daily event:


MSExchange Certificate Notification
A round of expiration check has finished. The next round is scheduled at "09.06.2020 20:37:18".

I check oauth connection this way and both sides were successfull (https://docs.microsoft.com/en-us/exchange/configure-oauth-authentication-between-exchange-and-exchan...)

 

2 Replies
Highlighted

a few seconds before the first warning I see the following info message in application log:

 

event: 2013

The authentication configuration information for trusted issuer EvoSts has been updated.

The authentication configuration information for trusted issuer ACS has been updated.

 

 

Highlighted
Best Response confirmed by bc1000 (Occasional Contributor)
Solution

Warning is gone. Stopped yesterday in the evening without any changes from my side.