Link to home
Start Free TrialLog in
Avatar of Wildgen
Wildgen

asked on

Expiring Exchange Cert

Im getting the event warning message that STARTTLS cert self signed cert will expire soon. It directs to run the New-ExchangeCertificate cmdlt. I believe this is referring to the initial self signed cert created on installation and expiring in 1 yr.
Questions:  
We have installed a SAN Cert which includes the listed server.  Why is this one not being used? It is not expiring soon.
Will I need to renew the self signed cert every year?
If so Can I run the Clone process to reup the cert for another year?
Get-ExchangeCertificate -Thumbprint c4242***33a4afc | New-ExchangeCertificate
Avatar of Mestha
Mestha
Flag of United Kingdom of Great Britain and Northern Ireland image

If you have a SAN/UC certificate in place, then check it is enabled for SMTP using get-exchangecertificate.
If it is, then simply remove the old self signed certificate completely.

You will notice that multiple certificates can be enabled for SMTP when you view the output of get-exchangecertificate

Simon.
ASKER CERTIFIED SOLUTION
Avatar of Narayan_singh
Narayan_singh
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial