Exchange Server 2013 on prem OWA blank screen after logging in

%3CLINGO-SUB%20id%3D%22lingo-sub-1520091%22%20slang%3D%22en-US%22%3EExchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1520091%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20an%20Exchange%20Server%202013%20Standard%20running%20on%20prem%20and%20has%20been%20working%20great%20for%20a%20few%20years.%26nbsp%3B%20Recently%20I%20updated%20the%20SSL%20certificate%20and%20everything%20seemed%20ok%20after%20the%20renewal.%26nbsp%3B%20I%20only%20noticed%20when%20a%20user%20asked%20to%20login%20to%20their%20mailbox%20via%20the%20web%20client%20that%20OWA%20was%20not%20functioning.%26nbsp%3B%20After%20entering%20the%20users%20credentials%2C%20the%20webpage%20turns%20white%20and%20nothing%20appears%20on%20the%20screen.%26nbsp%3B%20I%20have%20tried%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20Different%20web%20browsers.%26nbsp%3B%20Tried%20Microsoft%20Edge%20and%20Google%20Chrome.%3C%2FP%3E%3CP%3E2)%20Different%20computers%20and%20accounts%3C%2FP%3E%3CP%3E3)%20Accessing%20from%20the%20LAN%20and%20from%20the%20WAN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESame%20results%20from%20each%20test%20that%20there%20is%20a%20blank%20screen%20after%20logging%20in.%26nbsp%3B%20I%20am%20able%20to%20log%20in%20successfully%20into%20ECP%20and%20can%20view%20the%20Exchange%20Admin%20Centre.%26nbsp%3B%20I%20have%20tried%20researching%20the%20issue%20and%20there%20have%20been%20mentions%20that%20the%20SSL%20certificate%20is%20not%20installed%20correctly.%26nbsp%3B%20I%20have%20revoked%20and%20renewed%20the%20certificate%20and%20still%20am%20getting%20the%20same%20result.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20be%20grateful%20for%20any%20advice%20on%20what%20else%20to%20try%20and%20if%20anyone%20else%20has%20had%20a%20similar%20issue%20and%20has%20been%20able%20to%20resolve%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1520091%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1520244%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1520244%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F727551%22%20target%3D%22_blank%22%3E%40mark_fad%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3EThe%20issue%20you%20found%20is%20a%20common%20issue%20pops%20up%20after%20certificate%20renewal.%20The%20major%20root%20cause%20found%20was%20related%20to%20the%20certificate%20assignment%20to%20the%20exchange%20backend%20ssl%20bindings%20for%20port%20443.%20So%2C%20check%20this%20at%20IIS%20console%20and%20make%20sure%20that%20certificate%20is%20not%20missing%20or%20assigned%20correctly.%20After%20the%20fix%2C%20just%20refresh%20owa%20and%20you%20should%20be%20fine%20there%20on%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522369%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522369%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20manuphilip%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20reply.%26nbsp%3B%20I%20checked%20my%20certificates%20and%20they%20seem%20ok.%26nbsp%3B%20I%20have%20attached%20some%20images%20of%20the%20Default%20Web%20Site%20bindings%20and%20the%20Exchange%20Back%20End%20bindings%20if%20you%20could%20please%20have%20a%20look%20to%20see%20if%20they%20are%20correct%3F%26nbsp%3B%20The%20strange%20part%20is%20that%20ecp%20opens%20successfully%20but%20owa%20does%20not.%26nbsp%3B%20This%20is%20what%20is%20confusing%20me.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522604%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522604%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F727551%22%20target%3D%22_blank%22%3E%40mark_fad%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EImage%26nbsp%3BDefault_Site_Bindings.png%20shows%20a%20443%20binding%20for%20the%20local%20host%20also.%20Please%20check%20if%20certificate%20is%20assigned%20there%20too.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522690%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522690%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F669559%22%20target%3D%22_blank%22%3E%40manuphilip%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20just%20attached%20the%20local%20host%20bindings.%26nbsp%3B%20Same%20certificate%20mail.afgroup247.com.au_2019.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522767%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522767%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F727551%22%20target%3D%22_blank%22%3E%40mark_fad%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3ECertificate%20assignments%20looks%20okay.%20Now%2C%20it's%20some%20error%20you%20can%20try%20fixing%20by%20a%20built-%20in%20tool%20provided%20by%20Microsoft%20in%20your%20exchange%20server.%20Open%20a%20command%20prompt%20and%20perform%20the%20following%20steps%3C%2FP%3E%3CP%3E1.%20CD%20%22C%3A%5CProgram%20Files%5CMicrosoft%5CExchange%20Server%5CV15%5CBin%22%20and%20then%20press%20%3CENTER%3E%3CBR%20%2F%3E2.%20Subdirectory%20will%20change%20to%20the%20above.%3CBR%20%2F%3E3.%20Updatecas.ps1%2C%20then%20press%20%3CENTER%3E%3C%2FENTER%3E%3C%2FENTER%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETry%20access%20OWA%20again%20after%20fixing%20the%20cas%20server%20as%20above%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522787%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522787%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F669559%22%20target%3D%22_blank%22%3E%40manuphilip%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20continued%20support.%26nbsp%3B%20I%20am%20trying%20the%20script%20as%20suggested%20and%20still%20getting%20the%20white%20screen%20when%20opening%20OWA.%26nbsp%3B%20I%20have%20attached%20a%20screen%20shot%20of%20the%20powershell%20screen%20and%20the%20browser%20screen%20trying%20to%20open%20owa.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1522825%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1522825%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F727551%22%20target%3D%22_blank%22%3E%40mark_fad%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20is%20taking%20bit%20more%20time%2C%20as%20the%20usual%20troubleshooting%20steps%20didn't%20help%20so%20far.%20As%20the%20certificate%20swap%20has%20introduced%20this%20issue%2C%20we%20will%20check%20that%20direction%20again.%3C%2FP%3E%3CP%3E1.%26nbsp%3B%20Check%20eventlog%20in%20exchange%20server%20and%20see%20if%20you%20have%20errors%20like%20%22An%20error%20occurred%20while%20using%20SSL%20configuration%20for%20endpoint%200.0.0.0%3A444%22.%20This%20will%20popup%20immediately%20after%20you%20try%20to%20login%3C%2FP%3E%3CP%3E2.%20If%20this%20is%20the%20case%2C%20you%20have%20to%20delete%20this%20association%20by%20following%20the%20steps%20below%20in%20exchange%20server%3C%2FP%3E%3CUL%3E%3CLI%3EOpen%20command%20prompt%20as%20administrator%3C%2FLI%3E%3CLI%3EType%20%3CEM%3Enetsh%3C%2FEM%3E%20and%20enter%3C%2FLI%3E%3CLI%3EType%20%3CEM%3Ehttp%3C%2FEM%3E%20and%20enter%3C%2FLI%3E%3CLI%3EAgain%20type%20%3CEM%3Eshow%26nbsp%3Bsslcert%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%20and%20enter%3C%2FSPAN%3E%3C%2FLI%3E%3CLI%3E%3CSPAN%3EYou%20will%20see%20two%20entries%20for%20443%20and%20444.%20We%20know%20that%20444%20is%20incorrect%20and%20to%20be%20deleted%3C%2FSPAN%3E%3C%2FLI%3E%3CLI%3E%3CSPAN%3EDelete%20by%20running%20the%20command%26nbsp%3B%3CEM%3Edelete%20sslcert%20ipport%3D0.0.0.0%3A444%3C%2FEM%3E%3C%2FSPAN%3E%3C%2FLI%3E%3CLI%3E%3CSPAN%3EAdd%20the%20correct%20entry%26nbsp%3Badd%20%3CEM%3Esslcert%20ipport%3D0.0.0.0%3A444%20certhash%3Dxxxxxx%20appid%3D%22%7Byyyyyy%7D%22%3C%2FEM%3E%3C%2FSPAN%3E%3C%2FLI%3E%3CLI%3Etype%20%3CEM%3Eshow%26nbsp%3Bsslcert%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%20and%20check%20if%20you%20see%20the%20entries%20as%20correct%3C%2FSPAN%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CSPAN%3E3.%20The%20above%20steps%20should%20fix%20the%20issue.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E4.%20Suppose%20the%20above%20steps%20are%20not%20applicable%2C%20forward%20us%20the%20error%20message%20from%20event%20viewer%20so%20that%20we%20will%20further%20bring%20up%20troubleshooting%20steps%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1525664%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1525664%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F669559%22%20target%3D%22_blank%22%3E%40manuphilip%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20continued%20support.%26nbsp%3B%20I%20went%20through%20windows%20event%20log%20and%20exchange%20event%20logs%20but%20can%20not%20see%20any%20errors%20with%20SSL%20in%20them.%26nbsp%3B%20I%20am%20not%20sure%20if%20these%20errors%20are%20relevant%20but%20i%20can%20see%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMSExchange%20Management%20Logs%3C%2FP%3E%3CP%3ECmdlet%20failed.%20Cmdlet%20Get-UserPhoto%2C%20parameters%20%7BIdentity%3DJordan.Yap%40afgroup247.com.au%7D.%3C%2FP%3E%3CP%3ECmdlet%20failed.%20Cmdlet%20Get-MailboxDatabaseCopyStatus%2C%20parameters%20%7BIdentity%3DMailbox%20Database%201063958844%5C*%2C%20DomainController%3DAFSERVER.anytime.local%7D.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EActive%20Directory%20Webservice%20Logs%3C%2FP%3E%3CP%3EActive%20Directory%20Web%20Services%20could%20not%20find%20a%20server%20certificate%20with%20the%20specified%20certificate%20name.%20A%20certificate%20is%20required%20to%20use%20SSL%2FTLS%20connections.%20To%20use%20SSL%2FTLS%20connections%2C%20verify%20that%20a%20valid%20server%20authentication%20certificate%20from%20a%20trusted%20Certificate%20Authority%20(CA)%20is%20installed%20on%20the%20machine.%3CBR%20%2F%3E%3CBR%20%2F%3ECertificate%20name%3A%20AFSERVER.anytime.local%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20particular%20log%20file%20i%20should%20be%20checking%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1525675%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Server%202013%20on%20prem%20OWA%20blank%20screen%20after%20logging%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1525675%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F727551%22%20target%3D%22_blank%22%3E%40mark_fad%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3EThe%20interested%20logs%20are%20under%20Application%2FSystem.%20Try%20OWA%20login%20and%20check%20the%20entries%20there%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi,

 

I have an Exchange Server 2013 Standard running on prem and has been working great for a few years.  Recently I updated the SSL certificate and everything seemed ok after the renewal.  I only noticed when a user asked to login to their mailbox via the web client that OWA was not functioning.  After entering the users credentials, the webpage turns white and nothing appears on the screen.  I have tried the following:

 

1) Different web browsers.  Tried Microsoft Edge and Google Chrome.

2) Different computers and accounts

3) Accessing from the LAN and from the WAN.

 

Same results from each test that there is a blank screen after logging in.  I am able to log in successfully into ECP and can view the Exchange Admin Centre.  I have tried researching the issue and there have been mentions that the SSL certificate is not installed correctly.  I have revoked and renewed the certificate and still am getting the same result.

 

I would be grateful for any advice on what else to try and if anyone else has had a similar issue and has been able to resolve it.

 

Regards,

 

Mark

9 Replies
Highlighted

Hello @mark_fad ,

The issue you found is a common issue pops up after certificate renewal. The major root cause found was related to the certificate assignment to the exchange backend ssl bindings for port 443. So, check this at IIS console and make sure that certificate is not missing or assigned correctly. After the fix, just refresh owa and you should be fine there on

Highlighted

Hi manuphilip,

 

Thank you for your reply.  I checked my certificates and they seem ok.  I have attached some images of the Default Web Site bindings and the Exchange Back End bindings if you could please have a look to see if they are correct?  The strange part is that ecp opens successfully but owa does not.  This is what is confusing me.

 

Regards,

 

Mark 

Highlighted

Hi @mark_fad 

Image Default_Site_Bindings.png shows a 443 binding for the local host also. Please check if certificate is assigned there too. 

Highlighted

Hi @manuphilip ,

 

I just attached the local host bindings.  Same certificate mail.afgroup247.com.au_2019.

 

Regards,

 

Mark

Highlighted

Hi @mark_fad ,

Certificate assignments looks okay. Now, it's some error you can try fixing by a built- in tool provided by Microsoft in your exchange server. Open a command prompt and perform the following steps

1. CD "C:\Program Files\Microsoft\Exchange Server\V15\Bin" and then press <ENTER>
2. Subdirectory will change to the above.
3. Updatecas.ps1, then press <ENTER>

 

Try access OWA again after fixing the cas server as above

Highlighted

Hi @manuphilip ,

 

Thank you for your continued support.  I am trying the script as suggested and still getting the white screen when opening OWA.  I have attached a screen shot of the powershell screen and the browser screen trying to open owa.

 

Regards,

 

Mark

Highlighted

Hi @mark_fad 

It is taking bit more time, as the usual troubleshooting steps didn't help so far. As the certificate swap has introduced this issue, we will check that direction again.

1.  Check eventlog in exchange server and see if you have errors like "An error occurred while using SSL configuration for endpoint 0.0.0.0:444". This will popup immediately after you try to login

2. If this is the case, you have to delete this association by following the steps below in exchange server

  • Open command prompt as administrator
  • Type netsh and enter
  • Type http and enter
  • Again type show sslcert  and enter
  • You will see two entries for 443 and 444. We know that 444 is incorrect and to be deleted
  • Delete by running the command delete sslcert ipport=0.0.0.0:444
  • Add the correct entry add sslcert ipport=0.0.0.0:444 certhash=xxxxxx appid="{yyyyyy}"
  • type show sslcert  and check if you see the entries as correct

3. The above steps should fix the issue.

4. Suppose the above steps are not applicable, forward us the error message from event viewer so that we will further bring up troubleshooting steps

Highlighted

Hi @manuphilip ,

 

Thanks for your continued support.  I went through windows event log and exchange event logs but can not see any errors with SSL in them.  I am not sure if these errors are relevant but i can see the following:

 

MSExchange Management Logs

Cmdlet failed. Cmdlet Get-UserPhoto, parameters {Identity=Jordan.Yap@afgroup247.com.au}.

Cmdlet failed. Cmdlet Get-MailboxDatabaseCopyStatus, parameters {Identity=Mailbox Database 1063958844\*, DomainController=AFSERVER.anytime.local}.

 

Active Directory Webservice Logs

Active Directory Web Services could not find a server certificate with the specified certificate name. A certificate is required to use SSL/TLS connections. To use SSL/TLS connections, verify that a valid server authentication certificate from a trusted Certificate Authority (CA) is installed on the machine.

Certificate name: AFSERVER.anytime.local

 

Is there any particular log file i should be checking?

 

Regards,

 

Mark

 

Highlighted

Hi @mark_fad ,

The interested logs are under Application/System. Try OWA login and check the entries there