Solved

purchased new SSL certificate OWA; imported/installed on exchanged server 2007.  Web-site still refering to expired certificate.

Posted on 2008-09-30
3
477 Views
Last Modified: 2012-05-05
SSL certificate has expired so I purchased a new certificate from another vendor.  So I downloaded and imported to IIS in our domain the i found to find that the website server (owa) was not there.  So I exported the crt files to the exchange 2007 server where our mail and owa server is located using shell command.

then files were imported using the cmdlet  import-exchangecertificate -Path c:\lifestream.crt
However, I left out enabling these certificates (enable-exchangecertificate -services ..).  

I went on to install the other certificate to the computer account's rood and intermediate certificate stores.
Restarted the server and found that the OWA site is still refering to the expired certificate.

So, i tried to enable-exchangecertificate- services IIS but would not accept the thumbprint I provided.  It is showing an error;  "privatekey missing".  So, Pls help.  

I am an amateur; i need your guidance.

0
Comment
Question by:dhidalgo
  • 2
3 Comments
 
LVL 16

Accepted Solution

by:
Carol Chisholm earned 500 total points
ID: 22611753
You will need a certificate with the private key attached.

Exchange 2007 is very fussy about its certificates. You should use the approved MS procedure.
http://technet.microsoft.com/en-us/library/aa998327(EXCHG.80).aspx

Or try this site to generate the appropriate command, but you must run the command line in Exchange!
https://www.digicert.com/easy-csr/exchange2007.htm

0
 

Author Comment

by:dhidalgo
ID: 22615492
how would I erase or disable the expired certificate?  
0
 
LVL 16

Expert Comment

by:Carol Chisholm
ID: 22617991
remove-exchangecertificate - use |fl to get  a list of the old one thumbprints and copy and paste into the command line.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2007 standard - defrag (eseutul /d) 10 39
Exchange 2007 3 29
powershell question need assistance 10 27
Review of a VPN cert policy 4 27
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question