Hello,
i got 4 Exchange Servers here, and this is about Authentication testing.
I wonder, how i can debug why pop3 is not advertising capatability ntlm and gssapi on the exchange 2013 and exchange 2016.
Healthstatus is ok, configuration is as of exchange 2007 and exchange 2010. It just wont advertise those authmechs.
[PS] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Exchange Server 2016>get-popsettings | fl
RunspaceId : b85be684-226c-453e-a76e-f267ee8957e8
Name : 1
ProtocolName : POP3
MaxCommandSize : 512
MessageRetrievalSortOrder : Ascending
UnencryptedOrTLSBindings : {[::]:110, 0.0.0.0:110}
SSLBindings : {[::]:995, 0.0.0.0:995}
InternalConnectionSettings : {hashhack-ex16.hashex2016.lab:995:SSL, hashhack-ex16.hashex2016.lab:110:TLS}
ExternalConnectionSettings : {}
X509CertificateName : hashhack-ex16
Banner : The Microsoft Exchange POP3 service is ready.
LoginType : PlainTextAuthentication
AuthenticatedConnectionTimeout : 00:30:00
PreAuthenticatedConnectionTimeout : 00:01:00
MaxConnections : 2147483647
MaxConnectionFromSingleIP : 2147483647
MaxConnectionsPerUser : 16
MessageRetrievalMimeFormat : BestBodyFormat
ProxyTargetPort : 1995
CalendarItemRetrievalOption : iCalendar
OwaServerUrl :
EnableExactRFC822Size : False
LiveIdBasicAuthReplacement : False
SuppressReadReceipt : False
ProtocolLogEnabled : False
EnforceCertificateErrors : False
LogFileLocation : C:\Program Files\Microsoft\Exchange Server\V15\Logging\Pop3
LogFileRollOverSettings : Daily
LogPerFileSizeQuota : 0 B (0 bytes)
ExtendedProtectionPolicy : None
EnableGSSAPIAndNTLMAuth : True
Server : HASHHACK-EX16
AdminDisplayName :
ExchangeVersion : 0.10 (14.0.100.0)
DistinguishedName : CN=1,CN=POP3,CN=Protocols,CN=HASHHACK-EX16,CN=Servers,CN=Exchange Administrative
Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=hashex2016,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=hashex2016,DC=lab
Identity : HASHHACK-EX16\1
Guid : d635c60c-9d5c-4927-8a94-61b0fc556365
ObjectCategory : hashex2016.lab/Configuration/Schema/ms-Exch-Protocol-Cfg-POP-Server
ObjectClass : {top, protocolCfg, protocolCfgPOP, protocolCfgPOPServer}
WhenChanged : 12.11.2015 11:52:53
WhenCreated : 12.11.2015 11:29:43
WhenChangedUTC : 12.11.2015 10:52:53
WhenCreatedUTC : 12.11.2015 10:29:43
OrganizationId :
Id : HASHHACK-EX16\1
OriginatingServer : hashhack-dc-4.hashex2016.lab
IsValid : True
ObjectState : Unchanged
plaintextauthentication::: CAPA --->>> TOP UIDL STLS
plaintextlogin::: CAPA ---->>> TOP UIDL SASL PLAIN USER STLS
i want:: CAPA --->>> TOP UIDL SASL NTLM GSSAPI STLS
both 2013 and 2016 are cross forest, but i guess the forest difficulties should come after capa and a auth try ?
exchange 2007 is also cross forest, and working, exchange 2010 is not cross forest, and working, all the same settings
any hints here ?
Thanks!
2016-02-02T14:08:15.877Z,0000000000000002,0,10.148.141.84:110,10.148.140.117:51514,,1,0,51,OpenSession,,
2016-02-02T14:08:15.877Z,0000000000000002,1,10.148.141.84:110,10.148.140.117:51514,,1,4,43,capa,,R=ok
2016-02-02T14:08:15.877Z,0000000000000002,2,10.148.141.84:110,10.148.140.117:51514,,10,9,25,auth,NTLM,"R=""-ERR Protocol error. 14"""
servercomponentstate is like all related healthy,
set-eventloglevel for pop3 and pop3be is high, nothing relevant in the eventlog