Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

how to install new SSL certificate to exchange 2007

Posted on 2008-10-12
5
Medium Priority
?
5,633 Views
Last Modified: 2012-05-05
My exchange server 2007 is running in windows 2003 ent. i am trying to install verisign  ssl (Trail)certificate for my OWA.

First i have removed the self signed certificate from the exchange server. then as per the document i have generated the CSR (Certificate Signing Request ) upon the request i have received the Certificate and imported using Shell cmdlets. Also  i have install the certificate in the test cleint.( as per verisign for trail ssl certificate we have install a certificate in each browser). Unfortunately now i am getting page cannot display message.
0
Comment
Question by:senmohan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 8

Expert Comment

by:sstone55423
ID: 22698602
http://msexchangeteam.com/archive/2007/02/19/435472.aspx
http://technet.microsoft.com/en-us/library/bb310764(EXCHG.80).aspx
 
In the technet article, look at the section 2 (Configure the URLs for Exchange services ) as that is your next step.  It sounds like you may have step #1 done.
 
0
 
LVL 2

Expert Comment

by:EL-SHIMY
ID: 22698630
Hi dear,

Although this procedure talks about using private SSL-certificates, it is almost identical when using official SSL-certificates.

Here we go:

1)     Start by creating a SSL-certificate request file from your Exchange Server Shell, by issuing the following powershell cmdlet

New-ExchangeCertificate GenerateRequest Path c:\webmail_pdt_be.csr KeySize 1024 SubjectName c=BE, s=East-Flanders, l=Sint-Niklaas, o=PDT IT Services, ou=IT, cn=webmail.pdtit.be PrivateKeyExportable $True

2)     The above cmdlet generated a Certificate Request File (CSR)

3)     Next, we will upload this CSR to our internal Certificate Authority (if it is not installed already, install it to your internal server using the Control Panel Add/Remove Windows Components (2003) or Server Feature Roles (2008)), by using the Certificate Web Enrollment Services. You could also use the regular Certificate Authority MMC, but I love the webinterface for its ease of use J

4)     Browse to https://<servername>/certsrv

5)     Select Request a Certificate

6)     Next, Select Advanced Certificate Request

7)     Next, Choose Submit a certificate request by using a base-64-encoded CMC or PKCS#10 file&

8)     Then, Paste the contents from your CSR into the first field (include the first and list lines as well!!!); Choose Web Server as certificate template.

9)     Click Submit

10)  Select Base 64 Encoded + Save

11)  If you open the CSR-file to check some property fields, you will notice the subject (cn) refers to the URL to be used for your webmail access.

12)  Just for backup reasons, click copy to file to save a copy of the certificate file to disk.

13)  Now the certificate file is saved to disk, we can import it back into Exchange 2007, by using powershell cmdlet again:

Import-ExchangeCertificate path c:\documents and settings\administrator\desktop\webmail.pdtit.be.cer

14)  We can validate the import by using the Certificate MMC (start / run / mmc / add certificate snap-in / select computer account / personal store)

15)  The next step involves activating our newly imported certificate for Exchange Web Services; first, we start by getting a list of the current imported Exchange related certificates, by issuing the following cmdlet:

Get-ExchangeCertificate

The certificate of interest for us is the one with Subject webmail.pdtit.be

16)  Next, we will link this certificate to the Exchange Web Services, by using the following cmdlet:

Enable-ExchangeCertificate Thumbprint 1B19& Services IIS, POP, IMAP

Now, Exchange OWA will be linked to the SSL-certificate webmail.pdtit.be;

If we get the properties of the SSL-certificate in our Exchange OWA logon page (by clicking on the key-lock in the right below corner), the following information is shown:

Which means the OWA-service is indeed listening to the SSL-certificate with common name webmail.pdtit.be
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 22698686
save the cert on the root of your C: drive on the server lets call it c:\petenetlive.cer



1. Import the certificate, Start > All Programs > Microsoft Exchang eServer 2007 > Exchange Management console

 Import-ExchangeCertificate -Path c:\petenetlive.cer {enter}

Note: At this point Copy the thumbprint number to the clipboard (i.e. 9292D650DFFD7E055145E5CA5A29E08DFC07C53C)

Enable the Certificate
 
Enable-ExchangeCertificate -Services "SMTP,POP,IMAP,IIS"

Enter the Thumbprint of your certificate (i.e. 9292D650DFFD7E055145E5CA5A29E08DFC07C53C)

Select Yes To Overwrite


job done
0
 
LVL 1

Author Closing Comment

by:senmohan
ID: 31505482
yes. With your solution i am done with my job. Thank a lot.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22699061
:) No Problem - ThanQ
0

Featured Post

Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Suggested Courses

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question