Easy way to install self signed certificate on users desktops?

Posted on 2009-02-18
Last Modified: 2012-05-06
I am about ready to start moving user's to Exchange 2007 but I wanted to install the self signed certificate on all desktops in my organization.

The company here doesn't own their internal namespace, some guy in the czech republic does, so a UCC certificate is out of the question.  So my solution is to run OWA out of a new website get a single namespace certificate from a trusted CA and run all the other virtual directories with the self signed certificate.

So instead of manually installing the certificate on user's desktops I was wondering if there is a way to push it via GPO, or even create an MSI with Winstall LE or something.  Any and all ideas are appreciated, thanks.
Question by:typicaldude
    LVL 65

    Accepted Solution

    There is no way that I am aware of to push the certificate out.
    You really need to get round the certificate issue, because Outlook Anywhere and Exchange ActiveSync are not supported with a self signed certificate.


    Author Comment

    The only thing I can think of is to manually install the certificate which would allow the device or workstation to fully trust the certificate.

    Unfortunately this company doesn't own their internal namespace so this has caused me a headache.  I don't understand why people create thier internal domains with a .com and not ensure they own the name space.
    LVL 65

    Assisted Solution

    I had a client with the same problem.
    They ended up using Entrust for the certificate, where most of the namespace was the public domain name. As they were an accredited Entrust customer they were able to add the internal domains to their certificate for the SAN names.
    It can be avoided, but it isn't cheap to do. Unfortunately for that client, getting the domain name off the current owner would be more expensive than the certificate.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Do email signature updates give you a headache?

    Constantly trying to correctly format email signatures? Spending all of your time at every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

    Set OWA language and time zone in Exchange for individuals, all users or per database.
    New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
    This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
    The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now