SOLVED

HCW - Test-MigrationServerAvailability fails with SSL / TLS error

%3CLINGO-SUB%20id%3D%22lingo-sub-1719951%22%20slang%3D%22en-US%22%3EHCW%20-%20Test-MigrationServerAvailability%20fails%20with%20SSL%20%2F%20TLS%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1719951%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20I'm%20trying%20to%20set%20up%20exchange%202016%20coexisting%20with%20exchange%202010%20environment%20and%20get%20rid%20of%20exchange%202010.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BI%20have%20followed%20all%20the%20guides%20online%20and%20setup%20everything%20except%20HCW.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BI'm%20using%20Exchange%202010%20Selfsign%20certificate%20with%20new%20exchange%20server.%20This%20certificate%20got%20the%20public%20name%20as%20SAN%3A%20webmail.mydomain.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewebmail.mydomain.com----%26gt%3B%20210.22.123.48%20------%26gt%3B%20FW------443-----%26gt%3BExchange2016%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EError%3A%3C%2FP%3E%3CPRE%3EMicrosoft.Exchange.Migration.MigrationServerConnectionFailedException%3A%20The%20connection%20to%20the%20server'hybrid.contoso.com'%20could%20not%20be%20completed.%20---%26gt%3B%0AMicrosoft.Exchange.MailboxReplicationService.MRSRemotePermanentException%3A%20The%20Mailbox%20Replication%20Service%20could%20not%20connect%20to%20the%20remote%20server%20because%20the%20certificate%20is%20invalid.%20The%20call%20to%20'https%3A%2F%2Fhybrid.contoso.com%2FEWS%2Fmrsproxy.svc'%20failed.%20Error%20details%3A%20Could%20not%20establish%20trust%20relationship%20for%20the%20SSL%2FTLS%20secure%20channel%20with%20authority%20'hybrid.contoso.com'.%20--%26gt%3BThe%20underlying%20connection%20was%20closed%3A%20Could%20not%20establish%20trust%20relationship%20for%20the%20SSL%2FTLS%20secure%20channel.%20--%26gt%3B%20The%20remote%20certificate%20is%20invalid%20according%20to%20the%20validation%20procedure.%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20i%20really%20need%20the%20endpoint%20creation%3F%20All%20our%20mailboxes%20are%20on%20o365%20and%20required%20by%20this%20server%20for%20management%20and%20smtp%20relay%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ecan%20we%20disable%20the%20port%20443%20after%20the%20HCW%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20i%20have%20to%20create%20new%20selfsigh%20cert%20from%20exchange%202016%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETA%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1719951%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EO365%20migration%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1720298%22%20slang%3D%22en-US%22%3ERe%3A%20HCW%20-%20Test-MigrationServerAvailability%20fails%20with%20SSL%20%2F%20TLS%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1720298%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F644958%22%20target%3D%22_blank%22%3E%40aussupport%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnless%20you%20need%20to%20migrate%20users%20you%20don't%20need%20to%20create%20the%20migration%20endpoint.%20Also%20if%20there%20are%20no%20users%20(now%20or%20ever)%20on%20the%20legacy%20system%2C%20you%20don't%20need%20to%20run%20the%20HCW.%20You%20can%20just%20manually%20create%20the%20connectors%20for%20mail%20relay%20etc.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1741419%22%20slang%3D%22en-US%22%3ERe%3A%20HCW%20-%20Test-MigrationServerAvailability%20fails%20with%20SSL%20%2F%20TLS%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1741419%22%20slang%3D%22en-US%22%3EI%20just%20attached%20the%20public%20SSL%20and%20run%20the%20HCW%20to%20successfully%20complete.%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hi All,

 

  I'm trying to set up exchange 2016 coexisting with exchange 2010 environment and get rid of exchange 2010.

 

 I have followed all the guides online and setup everything except HCW.

 

 I'm using Exchange 2010 Selfsign certificate with new exchange server. This certificate got the public name as SAN: webmail.mydomain.com

 

webmail.mydomain.com----> 210.22.123.48 ------> FW------443----->Exchange2016

 

Error:

Microsoft.Exchange.Migration.MigrationServerConnectionFailedException: The connection to the server'hybrid.contoso.com' could not be completed. --->
Microsoft.Exchange.MailboxReplicationService.MRSRemotePermanentException: The Mailbox Replication Service could not connect to the remote server because the certificate is invalid. The call to 'https://hybrid.contoso.com/EWS/mrsproxy.svc' failed. Error details: Could not establish trust relationship for the SSL/TLS secure channel with authority 'hybrid.contoso.com'. -->The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. --> The remote certificate is invalid according to the validation procedure.

 

Do i really need the endpoint creation? All our mailboxes are on o365 and required by this server for management and smtp relay?

 

can we disable the port 443 after the HCW?

 

Do i have to create new selfsigh cert from exchange 2016? 

 

 

 

TA

2 Replies
Highlighted
Best Response confirmed by aussupport (Contributor)
Solution

Hi @aussupport 

Unless you need to migrate users you don't need to create the migration endpoint. Also if there are no users (now or ever) on the legacy system, you don't need to run the HCW. You can just manually create the connectors for mail relay etc.

I just attached the public SSL and run the HCW to successfully complete.