Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Get-ExchangeCertificate

Posted on 2010-09-20
11
Medium Priority
?
1,732 Views
Last Modified: 2012-06-21
Hi,


When I run Get-ExchangeCertificate |fl, I receive 2 certificates that have services enabled and status valid. Which of them is the trully owner ?



AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 25/08/2015 10:44:35
NotBefore          : 25/08/2010 10:44:35
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 3B39F4022F97C892419A55452825B1A9
Services           : IMAP, POP, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 61FF19635CCF0567786A551F02507B26302D3A08

AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcc
                     essRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 24/07/2015 18:34:15
NotBefore          : 24/07/2010 18:34:15
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 7BBA4CD6C5038C894B8A92D7D321CC5D
Services           : IMAP, POP, IIS, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0

Thank you

Racy
0
Comment
Question by:decioracy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
11 Comments
 
LVL 32

Expert Comment

by:endital1097
ID: 33716335
5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0 is the only certificate servicing IIS

i would remove any certificate not in use
0
 

Author Comment

by:decioracy
ID: 33716568
Hi,

IIS for sure ;)

What about  Services  : IMAP, POP, SMTP ??
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716590
you can have multiple for IMAP and POP
it should not allow multiple for SMTP

if you are not getting certificate warnings or errors for OWA, i would remove the cert with thumbprint = 61FF19635CCF0567786A551F02507B26302D3A08
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:decioracy
ID: 33716734
Hi,
Thank you

I need a command to see what certificate is answering for IMAP, POP, SMTP ... because I must be sure before doing anything
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716751
your other cert is per your initial post
0
 

Author Comment

by:decioracy
ID: 33716903
yes, But I didn´t that .... Someone did and He was fired .... I don't know if he changed anything ... so I need to I need a command to see what certificate is answering for IMAP, POP, SMTP
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33717088
get-exchangecertificate | fl cert*,services,thumb*
0
 

Author Comment

by:decioracy
ID: 33718075
Hi,

Thank you for your reply, but it gave me almost the same information

0
 
LVL 32

Expert Comment

by:endital1097
ID: 33718141
that was expected
as i stated, the cert handling iis is the good cert as long as users are not getting cert errors
0
 
LVL 26

Accepted Solution

by:
e_aravind earned 2000 total points
ID: 33718460
For POP3 and IMAP4:
In power shell type get-popSettings or get-imapSettings and check
X509CertificateName attribute. This will have the FQDN which is listed in Subject
of the Certificate.
0
 

Author Closing Comment

by:decioracy
ID: 33854579
This solves all or part of my problem.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
how to add IIS SMTP to handle application/Scanner relays into office 365.

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question