Improve company productivity with a Business Account.Sign Up

x
?
Solved

Get-ExchangeCertificate

Posted on 2010-09-20
11
Medium Priority
?
1,813 Views
Last Modified: 2012-06-21
Hi,


When I run Get-ExchangeCertificate |fl, I receive 2 certificates that have services enabled and status valid. Which of them is the trully owner ?



AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 25/08/2015 10:44:35
NotBefore          : 25/08/2010 10:44:35
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 3B39F4022F97C892419A55452825B1A9
Services           : IMAP, POP, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 61FF19635CCF0567786A551F02507B26302D3A08

AccessRules        : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAccessR
                     ule, System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcc
                     essRule}
CertificateDomains : {fake_exchange_server, fake_exchange_server.local}
HasPrivateKey      : True
IsSelfSigned       : True
Issuer             : CN=fake_exchange_server
NotAfter           : 24/07/2015 18:34:15
NotBefore          : 24/07/2010 18:34:15
PublicKeySize      : 2048
RootCAType         : None
SerialNumber       : 7BBA4CD6C5038C894B8A92D7D321CC5D
Services           : IMAP, POP, IIS, SMTP
Status             : Valid
Subject            : CN=fake_exchange_server
Thumbprint         : 5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0

Thank you

Racy
0
Comment
Question by:decioracy
  • 5
  • 5
11 Comments
 
LVL 32

Expert Comment

by:endital1097
ID: 33716335
5FD2D929AA9FE7A1B8083AD15A2AED2039A038A0 is the only certificate servicing IIS

i would remove any certificate not in use
0
 

Author Comment

by:decioracy
ID: 33716568
Hi,

IIS for sure ;)

What about  Services  : IMAP, POP, SMTP ??
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716590
you can have multiple for IMAP and POP
it should not allow multiple for SMTP

if you are not getting certificate warnings or errors for OWA, i would remove the cert with thumbprint = 61FF19635CCF0567786A551F02507B26302D3A08
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 

Author Comment

by:decioracy
ID: 33716734
Hi,
Thank you

I need a command to see what certificate is answering for IMAP, POP, SMTP ... because I must be sure before doing anything
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33716751
your other cert is per your initial post
0
 

Author Comment

by:decioracy
ID: 33716903
yes, But I didn´t that .... Someone did and He was fired .... I don't know if he changed anything ... so I need to I need a command to see what certificate is answering for IMAP, POP, SMTP
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33717088
get-exchangecertificate | fl cert*,services,thumb*
0
 

Author Comment

by:decioracy
ID: 33718075
Hi,

Thank you for your reply, but it gave me almost the same information

0
 
LVL 32

Expert Comment

by:endital1097
ID: 33718141
that was expected
as i stated, the cert handling iis is the good cert as long as users are not getting cert errors
0
 
LVL 26

Accepted Solution

by:
e_aravind earned 2000 total points
ID: 33718460
For POP3 and IMAP4:
In power shell type get-popSettings or get-imapSettings and check
X509CertificateName attribute. This will have the FQDN which is listed in Subject
of the Certificate.
0
 

Author Closing Comment

by:decioracy
ID: 33854579
This solves all or part of my problem.
0

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

A method of moving multiple mailboxes (in bulk) to another database in an Exchange 2010/2013/2016 environment...
Configure external lookups on for external mail flow on Exchange 2013 and Exchange 2016.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…

595 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question