Solved

Enabling email encryption netween 2 forests, and moving existing CA database from Forest A to Forest B

Posted on 2008-06-10
7
326 Views
Last Modified: 2010-04-18
Hi I wonder if someone has done it and can advise on the best way of doing it.

We are currently in the process of merging two forests into one and 2 Exchange organisations into one. I am using ADMT v3 to move AD objects and that works fine. I am using exmerge to move mail between the Exchange organisations that is fine too.

My question is how do I enable email encryption between the forests during the course of the merge?

Also how do I enable users that have been migrated over to still be able to access their old encrypted emails?

Do I have to transfer the hole CA database once the merge is fully comleted?

I have been looking to find a good document on the web for this, but could not find any.

I am aware of the method when you copy the public certificate between the 2 forests, and then using adsiedit.msc export each user's certificate attribute and copy over to the other forest. To me that beeing the most efficient way sounds difficutlt to believe.

Please help.


0
Comment
Question by:GALYAS
  • 4
  • 3
7 Comments
 
LVL 22

Expert Comment

by:Paka
ID: 21758168
Do you have one or two CAs?  Are these Enterprise CAs or standalone CAs?  If you're trying to merge two Enterprise CAs, I don't think it will work.  You'll have to use the CA of the forest that will remain after the merge is complete and reissue certs to the users that lost the forest.  

To be able to read the encrypted emails after the move, I'd recommend having the users forward their encrypted emails to themselves and disable the encryption before they do then run the exmerge.

Copying the certs might work, but since their issuing CA will be offline, you will get certificate validation issues.
0
 

Author Comment

by:GALYAS
ID: 21758510
Hi Paka,

Thanks a lot for the response.

We have 2 enterprise CA's  one for each forests.

Do you know how I can enable CA encryption between the 2 forest while merging is in progress. The two networks are rather big and it will take months to complete, so I need an interim solution?

Thank you in advance
0
 
LVL 22

Expert Comment

by:Paka
ID: 21758535
I'm unclear as to what you mean by "enable CA encryption between the 2 forests while merging is in progress".  Do you want to:
1) encrypt email between users in the two forests?
2) protect the SMTP links between the Exchange servers using encryption?
3) encrypt all traffic between the two forests?
0
Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

 

Author Comment

by:GALYAS
ID: 21758592
I mean 1) encrypt email between users in the two forests
0
 
LVL 22

Expert Comment

by:Paka
ID: 21760841
If you have both forests up during the migration you should be able to use the existing certs to encrypt email.  When you migrate a user over, delete their old certs, reissue new ones, setup the Outlook profile to use the new ones and you should be good to go.  There are a couple good guides on forest merges on the web to address other potential problems - I'll see if I can dig one up for you.
0
 

Author Comment

by:GALYAS
ID: 21760934
Is there anything that needs to be done on Both CA's in order to accomplish this.
At the moment UserA from ForestA is unable to send encrypted email to usersB in ForestB? We are still talking two different forests, 2 Exchange Organisations, 2 GAL's

Thanks a lot for digging those documents for me and all your help
0
 

Accepted Solution

by:
GALYAS earned 0 total points
ID: 21803499
After I did some research I found out a bit easier way then adsiedit, but still done on individual basis.

For those of you that may be interested here is the solution.

To enable S/MIME encryption between 2 forest take  the following steps as described in the article below.It applies to Exchange 2003  as well.

http://msexchangeteam.com/archive/2008/04/23/448761.aspx

Please keep in mind that you need to send to the contacts, A second Address Book for the external mail enabled contacts will be ideal for this case.

Also once mail is moved across forests you can still view email encrypted with your old CA if you export your certificate as .pfx file(from Forest A) and import it into your Outlook client(on forest B)
0

Featured Post

Swamped with email signature updates?

Have you been given a load of changes to make to your users’ email signatures? Having to manually implement multiple signatures for every department? Let Exclaimer save you from being swamped with email signature updates!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now