SSL Certificate Import in SBS 2011 to SBS 2011

Posted on 2013-01-02
Medium Priority
Last Modified: 2013-01-06
I am doing a migration from SBS 2011 to 2011 (changing hardware and wanting a clean install of SBS). I have followed the MS instructions to export my trusted SSL certificate from the old server and copied it to the new one.
If I browse to the Computer Personal Certificate store I can see the certificate in there, however when I run the Add a Trusted Certificate Wizard and browse for certificates it does not appear in the list.

When I go to help on SBS it says this below.  Guess what they are in that location.  
If the trusted certificate that you want to add is not listed:

It may not be in the Certificates\Personal store. Search for the certificate and import it into the correct certificate store.

Any ideas?
Question by:pctechmi
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38738514
The other reason for the certificate not appearing is that you haven't run the wizards to configure the name, or the name has changed between the two servers.

For example your certificate is for mail.example.com and the name in the wizard has been set to remote.example.com.

SBS will only show you certificates that match the name configured in its Internet name wizards.


Author Comment

ID: 38738870
the name is exactly the same mail.domain.com

I have run the other wizards for the network.  Everything detailed in migration guide before hand and have the certificates imported and they are in the Personal folder as listed in instructions.  When I run the add trusted certificate option in the SBS Console it only shows self signed certificates.

Expert Comment

ID: 38739750
The certificate should be imported to the computer-account - not the user-account. The IIS and Exchange only see the computer-account-certificates.
You can open a "MMC" and choose the certificates-Plugin. After choosing it it will ask you if you want the local machines or the user-certificates. Use the local machine and import the certificate again.

The external-Address of your CN must be in the external-address-fields within your servers client-connectivity-configurations.
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.


Author Comment

ID: 38740663
Yes I did use the computer account.  Here are the exact steps I followed.

To export a trusted certificate from the Source Server
1.      On the Source Server, click Start, click Run, type mmc.exe, and then press ENTER.
2.      On the console, click File, and then click Add/Remove Snap-in.
3.      Click Add, choose Certificates from the list, click Add, and then click OK.
4.      In the pop-up window that appears, click Computer Account, click Finish, and then click OK.
5.      Expand Certificates, expand Personal, and then click Certificates.
6.      Right-click the certificate that is issued to your website (for example: remote.contoso.com), click All Tasks, and then click Export.
There may be multiple certificates with the same name. Ensure that you choose a certificate that has a valid expiration date and that was issued by a trusted authority. If you are not sure which certificate to use, open Internet Information Services (IIS), determine which certificate IIS is using on the Source Server, and then choose the same certificate.
7.      In the Certificate Export Wizard, click Next.
8.      Ensure Yes, export the private key is selected, and then click Next.
9.      Ensure Include all certificates in the certificate path if possible and Export all extended properties are selected, and then click Next. Do not select Delete the private key if the export is successful.
10.      Type a password to protect the certificate file, and then click Next.
11.      Choose a location to save the .pfx file (for example, C:\trustedcert.pfx), and then click Next.
12.      Finish the wizard.
 To import the trusted certificate to the Destination Server
1.      Move the trustedcert.pfx file to the Destination Server by using the network or a USB flash drive.
2.      On the Destination Server, click Start, type mmc.exe, and then press ENTER.
3.      On the console, click File, and then click Add/Remove Snap-in.
4.      Choose Certificates from the list, and then click Add.
5.      In the pop-up window that appears, select Computer Account, click Finish, and then click OK.
6.      Expand Certificates, expand Personal, and then click Certificates.
7.      Right-click Certificates, click All Tasks, and then click Import.
8.      On the Certificate Import Wizard Welcome page, click Next.
9.      Browse to the location of the saved .pfx file, and then click Next.
10.      Type the password that you typed in the Export procedure, ensure that Mark this key as exportable and Include all extended properties are selected, and then click Next.
11.      Ensure that the certificate is imported to the Personal folder, and then click Next.
12.      Finish the wizard.
To ensure that the Destination Server is using the newly imported certificate, run the Add a Trusted Certificate Wizard:
 To run the Add a Trusted Certificate Wizard
1.      Open the Windows SBS 2011 Standard Console.
2.      On the navigation bar, click the Network tab, and then click Connectivity.
3.      In the task pane, click Add a trusted certificate.
4.      On the Welcome page, read the information, and then click Next.
5.      On the Get the certificate page, click I want to use a certificate that is already installed on the server, and then click Next.
6.      On the Choose an installed certificate page, click the certificate that you just imported, and then click Next.
If you cannot find the certificate that you just imported in the previous step, check to ensure that the Internet address configured on the Destination Server is exactly the same as the Internet address configured on the Source Server.
7.      When the wizard finishes, click Finish.
LVL 63

Accepted Solution

Simon Butler (Sembee) earned 2000 total points
ID: 38742321
When you ran the wizard to setup the Internet name, did you modify it to use that URL - as it prefers and will setup remote.example.com by default. If you look in the SBS console under network it will tell you what SBS has setup the external name to be.

It could also be that the certificate is corrupt.


Author Comment

ID: 38749559
I left the name with remote but our certificate is in the mail.domain.com format.  Update the Internet name and it accepted it.

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Issue: One Windows 2008 R2 64bit server on the network unable to connect to a buffalo Device (Linkstation) with firmware version 1.56. There are a total of four servers on the network this being one of them. Troubleshooting Steps: Connect via h…
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses
Course of the Month12 days, 2 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question