-
🌐 Monitoring Exchange publication through WAP and ADFS: why simple health checks are often insufficient
Monitoring Exchange publication through WAP and ADFS is significantly more complicated than simply checking whether port 443 responds. In this post, we discuss why WAP servers may appear healthy while Exchange publication is already broken, how claims-based authentication complicates health checks, and what should actually be monitored in complex WAP + ADFS publishing scenarios.
-
🔐 Exchange STARTTLS certificate selection: how a new certificate can break SMTP before it is even enabled
During a routine certificate renewal, Exchange may unexpectedly select the new certificate for STARTTLS – even if it hasn’t been assigned to the SMTP service yet. This article explains why it happens and how to avoid TLS negotiation failed with error InvalidHandle.
-
🔐 Exchange STARTTLS certificate selection: why a self-signed certificate may appear unexpectedly
Exchange transport automatically selects certificates for inbound STARTTLS connections — and in some scenarios, a self-signed certificate may be returned unexpectedly instead of a public wildcard certificate. In this post, we discuss how Exchange chooses SMTP certificates, why exact FQDN matches matter, and when explicitly configuring `TlsCertificateName` on Receive Connectors may be the best approach.
-
⚠️ Exchange DAG, dynamic quorum and an unexpected datacenter failover behavior
A missing File Share Witness, dynamic quorum vote recalculation, and a real-world datacenter isolation scenario led to unexpected Exchange DAG behavior during a failover event. In this post, we analyze how dynamic quorum adjusted node votes, why the “wrong” datacenter retained quorum, why previous DR tests did not reveal the issue, and how hidden quorum…
Available categories:
