I've resolved the issue, but in doing so uncovered another issue.
I learned that in Cached Exchange Mode, Outlook does not query AD for
addresses; but instead looks to the OAB...regardless of whether Outlook is
online or not, it seems. This condition would suggest that in cached mode,
the OAB is not updated, or our OAB is not being updated in general.
Once I cleared the Cached Exchange Mode checkbox in Exchange Server
settings, Outlook picked up the correct cert from AD and the message was
encrypted and decrypted successfully.
Thanks for your help!
--
Jonathan Forbes
"Brian Tillman" wrote:
> Jonathan Forbes <(E-Mail Removed)> wrote:
>
> > My local store had the current certificates listed. I removed them
> > anyway, suspecting the missing cert would prompt Outlook to query AD
> > for it. I sent a test email to the user in question. The CRL software
> > confirmed that the old cert was still used to encrypt the message.
>
> Is that person in your Contacts folder as well as the GAL? If so, try
> deleting the contact record from your Contacts folder.
>
> > What about the .nk2 auto complete cache? Does it cache more than just
> > addresses? It would appear that in spite of deleting the old certs,
> > my local system is still using it from somewhere. Thanks.
>
> Beats me, but it sure can't hurt to delete the name from the cache and try
> again.
> --
> Brian Tillman [MVP-Outlook]
>
>
|