{"id":114,"date":"2012-12-13T08:43:01","date_gmt":"2012-12-13T14:43:01","guid":{"rendered":"http:\/\/blog.escarra.org\/?p=114"},"modified":"2012-12-13T08:54:24","modified_gmt":"2012-12-13T14:54:24","slug":"lync-edge-replication-broken","status":"publish","type":"post","link":"https:\/\/blog.escarra.org\/?p=114","title":{"rendered":"Lync Edge Replication broken"},"content":{"rendered":"<p>Recently I came across an issue where the Edge server would not replicate the topology. After spending some time looking through firewall ACLs, NAT exemptions, packet captures and the rest of the usual networking stuff, it turns out the problem was WAY more obscure than simple connectivity&#8230;<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11.jpg\"><img data-attachment-id=\"126\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=126\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11.jpg\" data-orig-size=\"747,157\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Gonzalo Escarr\\u00c3\\u00a1&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1355387416&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Shot1\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11-300x63.jpg\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11.jpg\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-126\" title=\"Shot1\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11.jpg\" alt=\"\" width=\"747\" height=\"157\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11.jpg 747w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot11-300x63.jpg 300w\" sizes=\"(max-width: 747px) 100vw, 747px\" \/><\/a><\/p>\n<p>If your Edge server&#8217;s Trusted Root CA store contains over 100 entries, the SChannel security package will truncate this list internally and depending on where your internal Root CA sits in the alphabetical order, it could be truncated and affect the ability to replicate the Lync topology over HTTPS 4443.<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2.jpg\"><img data-attachment-id=\"117\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=117\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2.jpg\" data-orig-size=\"395,92\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Gonzalo Escarr\\u00c3\\u00a1&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1355387511&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Shot2\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2-300x69.jpg\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2.jpg\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-117 alignnone\" title=\"Shot2\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2.jpg\" alt=\"\" width=\"395\" height=\"92\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2.jpg 395w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot2-300x69.jpg 300w\" sizes=\"(max-width: 395px) 100vw, 395px\" \/><\/a><\/p>\n<p>To resolve this issue, there are two options:<\/p>\n<p>1. Delete unnecessary certificates from the Trusted Root CA store of the Edge server. This could potentially affect federated partners depending on which Root CAs you delete, but is a quick and easy way to fix the problem.<\/p>\n<p>2. Edit the registry on the Edge server to add a <strong>DWORD<\/strong> value, <strong>SendTrustedIssuerList<\/strong>, to the <strong>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\u00a0<\/strong>key and assign it a value of 0. \u00a0This will prevent schannell.dll from truncating the Root CA list from the edge server, and allow validation tests to pass.<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3.jpg\"><img data-attachment-id=\"116\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=116\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3.jpg\" data-orig-size=\"684,126\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Gonzalo Escarr\\u00c3\\u00a1&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1355387565&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Shot3\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3-300x55.jpg\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3.jpg\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-116 alignnone\" title=\"Shot3\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3.jpg\" alt=\"\" width=\"684\" height=\"126\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3.jpg 684w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2012\/12\/Shot3-300x55.jpg 300w\" sizes=\"(max-width: 684px) 100vw, 684px\" \/><\/a><\/p>\n<p>This was taken from the Technet&#8217;s Lync Forums <a href=\"http:\/\/social.technet.microsoft.com\/Forums\/en-AU\/ocsedge\/thread\/1cd3be72-1f65-48ae-aa8c-498f79917492\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently I came across an issue where the Edge server would not replicate the topology. After spending some time looking through firewall ACLs, NAT exemptions, packet captures and the rest of the usual networking stuff, it turns out the problem was WAY more obscure than simple connectivity&#8230; If your Edge server&#8217;s Trusted Root CA store [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"footnotes":"","_jetpack_memberships_contains_paid_content":false,"jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[1],"tags":[],"jetpack_publicize_connections":[],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/114"}],"collection":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=114"}],"version-history":[{"count":12,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/114\/revisions"}],"predecessor-version":[{"id":125,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/114\/revisions\/125"}],"wp:attachment":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}