Link to home
Start Free TrialLog in
Avatar of c7oi
c7oiFlag for United States of America

asked on

How to make Exchange 2010 to be the the Primary SSL Cert for Outlook Client?

Our Outlook Clients are getting the SSL Certificate from Exchange 2007 Server which just expired a few days ago.  And users are getting a POP-UP Securty Alert stating the security certificate has expired or is not yet valid.  But my OWA is getting the SSL Certificate from Exchange 2010 Server.

How do I make the Exchange 2010 SSL Certificate to be the Primary for our Outlook Clients?  So the Security Alert Pop-Up will disappear.

Thank You

Avatar of Suliman Abu Kharroub
Suliman Abu Kharroub
Flag of Jordan image

"How do I make the Exchange 2010 SSL Certificate to be the Primary for our Outlook Clients?  So the Security Alert Pop-Up will disappear."

It will not solve the issue ... the best way is to renew the certificate.
btw: you can get a public certificate for free...check it in http://startssl.com
Avatar of c7oi

ASKER

My Exchange 2010 Server Certificate is not expired until 2015.  Somehow the Microsoft Outlook Clients is seeing the SSL Certificate on the Exchange 2007 SSL Certificate.  I am planning to decom my Exchange 2007 Server.
what are the names listed in this certificate ?

how many servers do you have? what roles each one holds?

if this certificate work find for clients connected to 2007 CAS server.. just export it ( include the private key) and import it in the 2010 CAS and assign services to it.
Avatar of c7oi

ASKER

I just have one Exchange 2010 Server that holds CAS, HUB & Mailbox and the  Exchange 2007 Server that we migrate from.


The thing is OWA sees the right SSL Cert from Exchange 2010 and the Workstation that has MS Outlook Clients sees the SSL Cert on Exchange 2007.
From EMC, re-assign services to this certificate and restart exchange services as in attached. If that does not solve the issue, please re create the outlook profile and test again.
Capture.JPG
renew the certificate

it should be a san/uc certificate

san names should be correctly listed
Avatar of c7oi

ASKER

Here are the Certificate I have on my Exchange 2010 server.  Will the renew Cert be a self sign cert?
cert.jpg
its not clear if it is a SAN/UC Certificate.

why deploy a self signed certificate and live with the prompts

geotrust, digicert, globalsign, godaddy - so many inexpensive options are there from trusted CAs
Avatar of c7oi

ASKER

Can you give me the steps to create a SAN/UC certificate.
Not all of the above certificates are needed... just keep the one that includes the correct names and delete the rest ( you can take an offilne copy before deletion).
Avatar of c7oi

ASKER

How do I verify that I have the correct SAN/UC Certificate from the main one?
Avatar of c7oi

ASKER

I confirm that my SAN/UC Certification is correct on my Exchange 2010 Server.  OWA is receiving the Exchange 2010 SSL Cert but not on any of my Outlook Clients.  All internal users Outlook Clients are still getting their SSL Cert from Exchange 2007 server.
Cert.png
when you click view certificate, does it show the correct certificate ?

another thing, right click on outlook icon in system tray while hold down ctrl key --> connection status. where does outlook trying to connect ? which server?
Avatar of c7oi

ASKER

Outlook Client is seeing Exchange 2007 SSL Certificate not the Exchange 2010 Certificate

The connecting status is to Exchange 2010 Server.

FYI.
email = Exchange 2010
email2 = Exchange 2007
EmailTest.png
OD you tried to re-create outlook profile ? delete and create again in one of the clients please.
Avatar of c7oi

ASKER

Yes.  Creating a New Profile (manually) still giving me the SSL Cert from Exchange 2007.

Inaddition Info:
If I create the profile with Auto Config, It sees the Exchange 2007 Server and the Security Alert PoP up.

ASKER CERTIFIED SOLUTION
Avatar of Suliman Abu Kharroub
Suliman Abu Kharroub
Flag of Jordan image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of c7oi

ASKER

I already have an A record in my DNS server autodiscover.domain.ca to Exchange 2010.

Before I redirect the autodiscover from exchange 2007 to exchange 2010 as the defualt website, Is there anything else I need to be aware of?  

I have moved all my mailboxes to Exchange 2010, OWA users are on Exchange 2010, the only thing is the emails are going out from exchange 2010 to exchange 2007

When I use the get commands for the autodiscover URL, I can see both Exchange 2007 and Exchange 2010 information listed.
>>Before I redirect the autodiscover from exchange 2007 to exchange 2010 as the defualt website, Is there anything else I need to be aware of?  "

no , nothing
Avatar of c7oi

ASKER

I got an error message trying to run the first cmdlet.
[PS] C:\>Set-ClientAccessServer -Identity "email.
xxx.com" -AutodiscoverServiceInternalUri https://email.xxx.com/autodiscover/autodiscover.xml

Error:

Set-ClientAccessServer : Object 'CN=EMAIL,CN=Servers,CN=Exchange Administrative
 Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=xxx Company
d,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=xxx,DC=com' is read-
only to the current version of Exchange.
Avatar of c7oi

ASKER

This cmdlet was run on the Exchange 2007 Server.