Solved

Get-ExchangeCertificate

Posted on 2010-09-20
11
1,701 Views
Last Modified: 2012-06-21
Hi,


When I run Get-ExchangeCertificate |fl, I receive 2 certificates that have services enabled and status valid. Which of them is the trully owner ?



AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 25/08/2015 10:44:35
NotBefore          : 25/08/2010 10:44:35
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 3B39F4022F97C892419A55452825B1A9
Services           : IMAP, POP, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 61FF19635CCF0567786A551F02507B26302D3A08

AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcc
                     essRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 24/07/2015 18:34:15
NotBefore          : 24/07/2010 18:34:15
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 7BBA4CD6C5038C894B8A92D7D321CC5D
Services           : IMAP, POP, IIS, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0

Thank you

Racy
0
Comment
Question by:decioracy
  • 5
  • 5
11 Comments
 
LVL 32

Expert Comment

by:endital1097
ID: 33716335
5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0 is the only certificate servicing IIS

i would remove any certificate not in use
0
 

Author Comment

by:decioracy
ID: 33716568
Hi,

IIS for sure ;)

What about  Services  : IMAP, POP, SMTP ??
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716590
you can have multiple for IMAP and POP
it should not allow multiple for SMTP

if you are not getting certificate warnings or errors for OWA, i would remove the cert with thumbprint = 61FF19635CCF0567786A551F02507B26302D3A08
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:decioracy
ID: 33716734
Hi,
Thank you

I need a command to see what certificate is answering for IMAP, POP, SMTP ... because I must be sure before doing anything
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716751
your other cert is per your initial post
0
 

Author Comment

by:decioracy
ID: 33716903
yes, But I didn´t that .... Someone did and He was fired .... I don't know if he changed anything ... so I need to I need a command to see what certificate is answering for IMAP, POP, SMTP
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33717088
get-exchangecertificate | fl cert*,services,thumb*
0
 

Author Comment

by:decioracy
ID: 33718075
Hi,

Thank you for your reply, but it gave me almost the same information

0
 
LVL 32

Expert Comment

by:endital1097
ID: 33718141
that was expected
as i stated, the cert handling iis is the good cert as long as users are not getting cert errors
0
 
LVL 26

Accepted Solution

by:
e_aravind earned 500 total points
ID: 33718460
For POP3 and IMAP4:
In power shell type get-popSettings or get-imapSettings and check
X509CertificateName attribute. This will have the FQDN which is listed in Subject
of the Certificate.
0
 

Author Closing Comment

by:decioracy
ID: 33854579
This solves all or part of my problem.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
In-place Upgrading Dirsync to Azure AD Connect
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question