Solved

The Exchange Certificate will expire warning

Posted on 2012-04-11
7
617 Views
Last Modified: 2012-04-12
On reboot of my server in the application log I get the following warning from the Source MSExchange Web Services.

The exchange certificate
cn=ServerA.domain

Issuer
cn=ServerA.domain


Serial number
###

Not Before
Install date of server

Not After
1 year from install date of server

Thumbprint
####

will expire on  (1 year from install date of server).

This certificate was issued by this server.  When a Get-ExchangeCertificate command is run I do not see the above listed certificate. When I check the EMC I see two certificates one issued by digicert and one issued by "Federation"; neither of which have that expiration date.  Where else can I find this certificate that is giving the error?
0
Comment
Question by:TuscarawasCountyAdmin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 14

Expert Comment

by:isaman07
ID: 37833476
Launch internet explorer on your exchange server, tools---> internet options--->Content--->certificates
Check under trusted root certification authority and intermediate if you can find it. If the issuer is your exchange server itself you can safely delete that certificate, since your exchange already has other valid certificates used by IIS.
0
 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37834037
Sorry, I forgot to state that I had already done that also and there is nothing listed with the same expriation date or even close to it.
0
 
LVL 14

Expert Comment

by:isaman07
ID: 37834369
Check if there are any certificates applied by a GPO in active directory.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37834393
There are none.
0
 
LVL 14

Accepted Solution

by:
isaman07 earned 500 total points
ID: 37834553
Did you check any sub site under IIS using the mentioned certificate?
0
 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37837163
Ah ha!  I found the certificate in there.  It is labelled temp.  I also see the two other certificates, my cert issued by digicert and the one by federation.  Is it safe to delete this temp certificate?  It must have been created by the vendor when our exchange server was installed.
0
 
LVL 14

Expert Comment

by:isaman07
ID: 37837755
Yes, it is safe, as long as you don't see it used in your EMC. But try to copy it just to be on the safe side.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In-place Upgrading Dirsync to Azure AD Connect
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question