Certification - Server 2008

Here is what needs to be renewed: Issued to sites, Subject is sites, DNS name = sites, Certificate template name – Webserver.

It has expired so from what I hear I need to get a new cert and install.

Thanks in advance!
cspeakerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

David Johnson, CD, MVPOwnerCommented:
do you have a root CA (certificate Authority?) or was your iis webserver certificate self signed or an outside certificate authority?
0
cspeakerAuthor Commented:
How can I tell?
0
David Johnson, CD, MVPOwnerCommented:
examine the certificate



2011-10-05-1444-001.png
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

David Johnson, CD, MVPOwnerCommented:
The real where to look in IIS  What the certificates look like select a certificate and you will see the 'renew' button
0
cspeakerAuthor Commented:
I believe it is self signed.

The issued to and issued by are the same - the domain server.
0
cspeakerAuthor Commented:
The cert in question is not listed but the users get a warning that the cert for "sites" is invalid because it expired. The templat is webserver.

This pop-up appears once Outlook (Exchange) is opened.
0
David Johnson, CD, MVPOwnerCommented:
so it's not your web server but exchange server same rules apply but from your exchange server managment console
0
cspeakerAuthor Commented:
Can you provide the steps to do this please.
0
David Johnson, CD, MVPOwnerCommented:
Enable-ExchangeCertificate -Server 'EXCH-H-868' -Services 'IMAP, POP, IIS, SMTP' -Thumbprint 'AD19B141228C7CF98B5F78DCED978B7C45E15434'

view the full article at http://technet.microsoft.com/en-us/library/ee332322.aspx
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
e_aravindCommented:
I would also recommend to use the command "new-exchangecertificate" to create the certificate\request

a) if you are OK for the "self-signed cert", then you can use the "new-exchangecertificate" without any other parameter...to get the renewed cert.
b) if you got any CA to handle this request, then you can create the request file ...upload it to the CA and wait for the response to get the .cer or .pfx files

0
cspeakerAuthor Commented:
Thanks!!

OK – I followed the procedures above and it did overwrite the cert that keeps popping up but went back to the users station, started Outlook and the pop up came up again.

Is there something else I need to do?
0
e_aravindCommented:
The above steps are the simplest\best way to renew an self-signed exchange certificate.

If the Outlook clients are prompted for authentication....did they had the same issue earlier?
how was that handled earlier?

Do you see any SAN entries @ the old-expiring certificate?

>> concentrate more on the certificate warning
-Click on the "View Certificate" during the "Certificate warning" ...compare the string\URL which Outlook is trying to reach...and what is the certificate actually having.

Note: If needed we may need to go for a SAN certificate
0
cspeakerAuthor Commented:
Ok - restarted the server and its looking good.

I will know for sure at the end of the day.

Thanks for your help and I will award points either latter today or tomorrow am.

0
cspeakerAuthor Commented:
Both helped solve the problem so splitting points.

Thanks guys!!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
ASP

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.