• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 575
  • Last Modified:

"There is no valid SMTP TLS certificate for the FQDN of exchange.whatever.com. The existing cert has expired..."

Hi,
I have a SBS2011 and start to get this message of "There is no valid SMTP TLS certificate for the FQDN of exchange.whatever.com. The existing cert has expired..."

I read through some posts as to run commands on Exchange but no clue as to where and how to , the IT guy left so I am a bit stuck, could someone give a a simple walkthrough ?

I get this is the cmdlet needed but are there any parameters I need to change to reflect my own server ?
Get-ExchangeCertificate -thumbprint thumbprintofcert | New-ExchangeCertificate

Many thanks
0
Combemartin
Asked:
Combemartin
  • 3
  • 3
  • 3
2 Solutions
 
Suliman Abu KharroubIT Consultant Commented:
first of all check the date setting on exchange server if it correct... if so, then the current installed certificate is expired and needed to be renewed..
0
 
Suliman Abu KharroubIT Consultant Commented:
0
 
AkhaterCommented:
open exchange management shell and run new-exchangecertificate it should solve the issue for you (restart the exchange transport service)

if it doesn't then issue a get-exchagnecertificate and give me the result
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
CombemartinAuthor Commented:
Thanks,
Do I need to delete the expired certs first ?
0
 
CombemartinAuthor Commented:
Ok, I am a bit lost here, on the new cert creation, I can only see options for IMAP and POP, the two expired certs are :

IMAP, POP, SMTP           CN=Sites
IMAP, POP, IIS, SMTP     CN=mail.xxxxx.net

Which option should I be ticking within the createion process?
Thanks
0
 
Suliman Abu KharroubIT Consultant Commented:
The most important one is IIS, select all of them.
0
 
AkhaterCommented:
no don't select anything, all you need it for is smtp
0
 
CombemartinAuthor Commented:
Hi, thanks, do I select all or just SMTP ?
Also, do I need to delete the expired certs first before I create new ones ?
Thanks all.
0
 
AkhaterCommented:
again you don't need to select anything it will autmatically be assigned for the SMTP and you do not need to delete it before
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

  • 3
  • 3
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now