Jump to content
Welcome to our new Citrix community!

Netscaler VPX - Exchange 2019 "time out during ssl handshake stage" https webservices


Arne Weinmann

Recommended Posts

Hi,

I have a virtual Netscaler (firmware NS12.0 59.9.nc) for securely publishing internal server websites. It was configured after the best practice documentation and works just fine with Exchange 2013 and 2016. However, I can't publish any Exchange 2019 websites. The 2019 server itself works internally and it also works if I publish it via NAT over the firewall. It doesen't work when I add it to the service groups in Netscaler.

The error message is "time out during ssl handshake stage". I suspect it has something to do with Exchange 2019 only accepting TLS 1.2: "We also built Exchange Server 2019 to only use TLS 1.2 out of the box, and to remove legacy ciphers and hashing algorithms." (Source: https://blogs.technet.microsoft.com/exchange/2018/10/22/exchange-server-2019-now-available/).

I tried activating TLS 1.0 and 1.1 on the Exchange 2019 server, but with no success. Does anyone have a idea, how to fix this?

grafik.thumb.png.c315a7aec9bd1dd9284d1df746dc46c6.png

grafik.thumb.png.82a8f00b3a61dc738c64d1109027ce85.png

grafik.thumb.png.34cb2b1f8fb866263d5b8818faea17d1.png

 

Edit: Don't be confused about the first picture, the Exchange 2019 server was only added to OWA and ECP. All other servers (with healthy state) only terminate on the Exchange 2016 server. They would also not work with Exchange 2019, I tested this.

Edited by a.weinmann@werkstattschule.info
Link to comment
Share on other sites

  • 7 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...