Solved

Certificate for OA

Posted on 2013-01-21
6
227 Views
Last Modified: 2013-01-29
Hi Guys,

I am about to purchase certificates for outlook anywhere but i am a bit confused.

Basically, we got 2 exchange 2010 servers located in different sites and both are in the same domain.

Now my question is, will a wild-card certificate work for my 2 exchange servers or do i need to purchase a certificate per server?
0
Comment
Question by:R2_D2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 37

Expert Comment

by:Jamie McKillop
ID: 38801571
Hello,

A wildcard certificate will work fine, unless you have older Windows mobile devices or you have OCS2007 and need integration. If you have Windows XP clients that aren't at the latest service pack level, you also need to make some changes to the certprincipalname so that is uses msstd:*.yourdomain.com

If you choose to purchase a SAN certificate, you need at least mail.domain.com and autodiscover.domain.com, provided only one of your sites is internet facing. If both sites are internet facing, you will need a third name on the cert for the second site.

JJ
0
 
LVL 49

Expert Comment

by:Akhater
ID: 38804110
I wouldn't recommend using a wild card, although technically it works  it is sensibly harder to configure specially if you are not experienced

I would buy a SAN certificate and include all the needed URI in it
0
 

Author Comment

by:R2_D2
ID: 38805627
will it work if i install 2 certificates, one on each server ?

because  is cheaper rather than buying a  SAN or Wild-Card Cert.
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 
LVL 49

Expert Comment

by:Akhater
ID: 38805638
no it won't you do need a SAN certificate (or a wild card)

san certificates are less than $100 a year
0
 
LVL 37

Accepted Solution

by:
Jamie McKillop earned 500 total points
ID: 38805650
Yes, it is possible to use a single name certificate. You will need to have an SRV record created in your DNS zone for the autodiscover service.

Here is a script that will help you set it up - http://virtualbarrymartin.me/2009/12/29/how-to-setup-exchange-2010-to-use-a-single-certificate-for-internal-and-external-use/

JJ
0
 

Author Closing Comment

by:R2_D2
ID: 38830209
Yes that worked
0

Featured Post

Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

After hours on line I found a solution which pointed to the inherited Active Directory permissions . You have to give/allow permissions to the "Exchange trusted subsystem" for the user in the Active Directory...
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question