Solved

The Exchange Certificate will expire warning

Posted on 2012-04-11
7
613 Views
Last Modified: 2012-04-12
On reboot of my server in the application log I get the following warning from the Source MSExchange Web Services.

The exchange certificate
cn=ServerA.domain

Issuer
cn=ServerA.domain


Serial number
###

Not Before
Install date of server

Not After
1 year from install date of server

Thumbprint
####

will expire on  (1 year from install date of server).

This certificate was issued by this server.  When a Get-ExchangeCertificate command is run I do not see the above listed certificate. When I check the EMC I see two certificates one issued by digicert and one issued by "Federation"; neither of which have that expiration date.  Where else can I find this certificate that is giving the error?
0
Comment
Question by:TuscarawasCountyAdmin
  • 4
  • 3
7 Comments
 
LVL 14

Expert Comment

by:isaman07
ID: 37833476
Launch internet explorer on your exchange server, tools---> internet options--->Content--->certificates
Check under trusted root certification authority and intermediate if you can find it. If the issuer is your exchange server itself you can safely delete that certificate, since your exchange already has other valid certificates used by IIS.
0
 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37834037
Sorry, I forgot to state that I had already done that also and there is nothing listed with the same expriation date or even close to it.
0
 
LVL 14

Expert Comment

by:isaman07
ID: 37834369
Check if there are any certificates applied by a GPO in active directory.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37834393
There are none.
0
 
LVL 14

Accepted Solution

by:
isaman07 earned 500 total points
ID: 37834553
Did you check any sub site under IIS using the mentioned certificate?
0
 
LVL 1

Author Comment

by:TuscarawasCountyAdmin
ID: 37837163
Ah ha!  I found the certificate in there.  It is labelled temp.  I also see the two other certificates, my cert issued by digicert and the one by federation.  Is it safe to delete this temp certificate?  It must have been created by the vendor when our exchange server was installed.
0
 
LVL 14

Expert Comment

by:isaman07
ID: 37837755
Yes, it is safe, as long as you don't see it used in your EMC. But try to copy it just to be on the safe side.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
This video discusses moving either the default database or any database to a new volume.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question