Add second domain to exchange 2007 certificate

Posted on 2012-09-18
Last Modified: 2012-09-18

We have a exchange 2007 mail server (part of SBS 2008). I added a new accepted domain and given the users an new email address in the new domain. I also made the new email address primary.

Now I get the following error in the event log:
Microsoft Exchange could not find a certificate that contains the domain name in the personal store on the local computer. Therefore, it is unable to support the STARTTLS SMTP verb for the connector Send Connector with a FQDN parameter of If the connector's FQDN is not specified, the computer's FQDN is used. Verify the connector configuration and the installed certificates to make sure that there is a certificate with a domain name for that FQDN. If this certificate exists, run Enable-ExchangeCertificate -Services SMTP to make sure that the Microsoft Exchange Transport service has access to the certificate key.

I think I have to create a certificate for the new domain and enable the SMTP service for it. Or I can add the new domain to the existing certificate which is now used bij

I have tried to make a certificate request file (.csr) but i don't know how to get from there.

It has to be a self signed certificate.

All help is very welcome.

M. Belali
Question by:PramoIT
    1 Comment
    LVL 18

    Accepted Solution

    You can't add the domain name in existing certificate for that you have to reissue the certificate with multiple domain.

    To create a self sign certificate please refer below links.


    Shell command for create self sing certificate :

    New-ExchangeCertificate -SubjectName "c=US, o=abc Bank," -DomainName,

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Suggested Solutions

    Set OWA language and time zone in Exchange for individuals, all users or per database.
    "Migrate" an SMTP relay receive connector to a new server using info from an old server.
    The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now