Solved

Get-ExchangeCertificate

Posted on 2010-09-20
11
1,670 Views
Last Modified: 2012-06-21
Hi,


When I run Get-ExchangeCertificate |fl, I receive 2 certificates that have services enabled and status valid. Which of them is the trully owner ?



AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 25/08/2015 10:44:35
NotBefore          : 25/08/2010 10:44:35
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 3B39F4022F97C892419A55452825B1A9
Services           : IMAP, POP, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 61FF19635CCF0567786A551F02507B26302D3A08

AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcc
                     essRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 24/07/2015 18:34:15
NotBefore          : 24/07/2010 18:34:15
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 7BBA4CD6C5038C894B8A92D7D321CC5D
Services           : IMAP, POP, IIS, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0

Thank you

Racy
0
Comment
Question by:decioracy
  • 5
  • 5
11 Comments
 
LVL 32

Expert Comment

by:endital1097
Comment Utility
5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0 is the only certificate servicing IIS

i would remove any certificate not in use
0
 

Author Comment

by:decioracy
Comment Utility
Hi,

IIS for sure ;)

What about  Services  : IMAP, POP, SMTP ??
0
 
LVL 32

Expert Comment

by:endital1097
Comment Utility
you can have multiple for IMAP and POP
it should not allow multiple for SMTP

if you are not getting certificate warnings or errors for OWA, i would remove the cert with thumbprint = 61FF19635CCF0567786A551F02507B26302D3A08
0
 

Author Comment

by:decioracy
Comment Utility
Hi,
Thank you

I need a command to see what certificate is answering for IMAP, POP, SMTP ... because I must be sure before doing anything
0
 
LVL 32

Expert Comment

by:endital1097
Comment Utility
your other cert is per your initial post
0
How does your email signature look on mobiles?

Do your employees use mobile devices to reply to emails? With mobile becoming increasingly important to the business world, it is in your best interest to make sure that your email signature looks great across all types of devices.

 

Author Comment

by:decioracy
Comment Utility
yes, But I didn´t that .... Someone did and He was fired .... I don't know if he changed anything ... so I need to I need a command to see what certificate is answering for IMAP, POP, SMTP
0
 
LVL 32

Expert Comment

by:endital1097
Comment Utility
get-exchangecertificate | fl cert*,services,thumb*
0
 

Author Comment

by:decioracy
Comment Utility
Hi,

Thank you for your reply, but it gave me almost the same information

0
 
LVL 32

Expert Comment

by:endital1097
Comment Utility
that was expected
as i stated, the cert handling iis is the good cert as long as users are not getting cert errors
0
 
LVL 26

Accepted Solution

by:
e_aravind earned 500 total points
Comment Utility
For POP3 and IMAP4:
In power shell type get-popSettings or get-imapSettings and check
X509CertificateName attribute. This will have the FQDN which is listed in Subject
of the Certificate.
0
 

Author Closing Comment

by:decioracy
Comment Utility
This solves all or part of my problem.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now