Solved

Installing Basic SSL certificate in IIS for OWA

Posted on 2009-04-14
12
807 Views
Last Modified: 2012-05-06
I was hoping that someone could point me in the right direction on this.  I do not have much background on security certificates, so alot of this is new to me.

I have purchased a Basic SSL certificate for our Exchange 2007 OWA.  The credentials have been verified, and I have received the certificates from the 3rd party authority.  However, I'm not sure what steps I need to go through to successfully install this certificate.  After doing some online research, I have found that I needed to create a CSR beforehand.  However, I never created this CSR because I didn't know that I needed to.  I see that Exchange 2007 has a self-signed cert being used, but how do I go about replacing this with the new cert?  When I open IIS, go to properties of Default WebSite, click Directory Security and Server certificate, I have the 2 options of Renew or Remove certificate.  If I click Remove, and then go back into Server certificate, I see all of the options available now.  If I click "Assign an existing certificate", my only option is the default Exchange 2007 cert.  If I click "Create a new certificate", I go through the steps successfully, but then it asks for the response from the 3rd party (a .cer I believe).  However, the only files that they sent me were .crt files.

Any insight?
0
Comment
Question by:david_greer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 3
  • +1
12 Comments
 
LVL 12

Expert Comment

by:ryan80
ID: 24139366
you have to provide the information to the SSL provider that was used in the CSR.  it is not a big deal if you have to recreate it.  Do a CSR request on the Exchange server.  Use that information to resissue the SSL. Once you get back the certificate, the option to install the SSL that was created from the CSR will be there.  

Once it is installed, you can go to the default website in IIS and select that SSL cert.  make sure that you enable SSL for the OWA virtual directory as well.

You can also check out this website for more in depth directions:

http://www.petri.co.il/configure_ssl_on_owa.htm
0
 

Author Comment

by:david_greer
ID: 24139585
Okay.  I have gone through the wizard of creating the CSR.  Do I email them this file, or do I just go to their website and click "Reissue" on our certificate?
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24140003
As this is Exchange 2007, you do not use IIS to request and process the SSL request. It needs to be done through the Exchange Management Shell.
Furthermore you really need a SAN/UC certificate, not a single name certificate for Exchange to work correctly.
I have outlined everything that you need to do on my blog here:
http://blog.sembee.co.uk/archive/2008/05/30/78.aspx

Simon.
0
Is Your DevOps Pipeline Leaking?

Is your CI/CD pipeline a hodge-podge of randomly connected tools? You’ve likely got a tool to fix one problem & then a different tool to fix another, resulting in a cluster of tools with overlapping functionality. Learn how to optimize your pipeline with Gartner's recommendations

 
LVL 12

Expert Comment

by:ryan80
ID: 24140014
it should probably be reissue.  There should be a place that you can reenter the info.  
0
 
LVL 12

Expert Comment

by:ryan80
ID: 24140025
sorry, I was thinking of Exchange 2003.  Mestha know 1000 times more than me, so listen to him.
0
 

Author Comment

by:david_greer
ID: 24142367
Okay.  Thank you for the replies.  However, we have already purchased the certificate and paid ahead for 4 years.  We can't purchase a SAN/UC certificate since we already have this basic cert.  Also to note; we are not running Server 2008 and do not plan to use Outlook Anywhere.  

Is there anything that I can do since this blog relates to using SAN/UC certificates?
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24142527
Tell the vendor you bought the wrong thing and ask them to refund it.
You will not be the first or the last to buy the wrong certificate type. SSL certificates are the major pain point with Exchange 2007.

It is possible to use Exchange 2007 with a single name SSL certificate but your external DNS host MUST support SRV records. If they do not then you need to change the certificate as they are not compatible.

Simon.
0
 

Author Comment

by:david_greer
ID: 24142624
Okay.........I have just emailed our DNS host provider and asked them if they provide support for these SRV records.  If they DO..........where do I go from there?
0
 
LVL 65

Accepted Solution

by:
Mestha earned 500 total points
ID: 24142944
A lot of DNS providers do not support SRV records.

If they do, then I wrote this guide on making the change.
http://www.amset.info/exchange/singlenamessl.asp

Simon.
0
 

Author Comment

by:david_greer
ID: 24198792
Sorry about the long wait Mestha.  Things have been very hectic here lately.

At any rate, I have confirmed with our DNS provider that they do support SRV records.  I will try to now go through your article and get this setup.
0
 

Author Closing Comment

by:david_greer
ID: 31569958
Thank you for the article
0
 
LVL 24

Expert Comment

by:Rajith Enchiparambil
ID: 24271512
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Today I came across an interesting issue that had me pulling my hair out.  I was troubleshooting a new internal web site which uses integrated security instead of anonymous.  When browsing the site from my laptop, I was able to access it with no iss…
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question