I restarted IIS prior to rebooting the machine. Both had no effect.
Main Topics
Browse All TopicsI just purchased a brand new certificate to replace my current SSL Certificate that expired over a year ago. Here was the process I followed:
1. Deleted the current certificate
2. Issued a new CSR
3. Obtained a new Cert from RapidSSL
4. Installed the new Cert into IIS for the Default Website
However, when I browse to the outlook web access at https://mail.domain.net it still gives me the Old certificate.
I verified that the new Certificate was installed by Viewing the Certificate under Directory Security in IIS.
I verified that the certificate being used matched what was in the IIS Metabase.xml file.
I also deleted the old Certificate from the machine using the Certificates MMC snapin.
I have even rebooted the machine.
Any help troubleshooting this issue would be appreciated. For whatever reason, the old certificate continues to be presented upon accessing the site.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
How exactly did you delete the old certificate?
There was actually no need to do that. You simply go through the wizard to remove the old certificate, then create the new request.
Is there anything between Exchange and the internet? An ISA server? If the certificate has been removed from the server then the certificate is elsewhere, it could be in the browser or something else holding a copy.
Simon.
I deleted the Old expired certificate first by Using the Wizard to remove the certificate from the server. The "View Certificate" button became grayed out as a result. I then used the Wizard again to issue a new CSR request.
Second, I used the Certificates MMC snap-in to delete the Old expired certificate as part of troubleshooting why machines are still receiving the Old certificate when attempting to access the website.
There is no ISA server in place.
When I go into IIS and view the Certificate currently installed for the Default Website, the new certificate is shown. However, for some reason beyond my understanding the old certificate is still presented when users access the site.
I've run the SSL Diag tool from Microsoft and there are no issues.
Everything that you have done is correct. It doesn't matter what account you use, as long as it has permissions.
If the certificate has been removed from the SERVER certificate store then IIS cannot present it to the client. Therefore either the certificate is not coming from the server that you expect, it is being cached somewhere or a copy is stored locally.
Simon.
I've tested accessing the website from machines that are on the network as well as off the network. I've also used different browsers to test it.
Basically, i just type in https://mail.domain.net in the address field and go to the site. I'm immediately presented with a warning stating the Site Certificate has expired. This occurs every time.
As stated earlier you use the certificates mmc snap in to look for old certificates, here you use the local computer option when prompted.
is your configuration for exchange front end back end or single server. do you have more than one front end server?
have you viewed the certificate on the exchange virtual directory rather than the site - I know if it's in one place it should be in all of them.
Have you tried a different client
Yes, used the Certificates MMC Snapin and deleted the old certificate there. This is a single server Exchange.
The certificate shows properly in IIS manager for the Exchange virtual directory.
At this point I'm going to try having RapidSSL reissue the certificate and start the process from the beginning again. I just don't know what else to do.
As it would turn out, someone had setup a secondary exchange server for failover purposes. Obviously I didn't set this environment up originally, just more or less maintaining it. After some digging I discovered this second server, installed the new SSL certificate appropriately, and now the old one is gone.
Going to https://mail.domain.net no longer shows an expired certificate.
Thanks everyone for the insight and assistance.
Business Accounts
Answer for Membership
by: WadskiPosted on 2009-08-07 at 05:21:18ID: 25041892
stop and start IIS.