Renew Exchange Server 2010 ssl certificate with larger key length

Hi

I need to renew the SSL on my exchange server but it currently has a 1024bit key length.

I have 80 external users connecting over https so cannot afford to just remove the cert and recreate a new one as presumably it will involve having to install the new cert on all the remote users?

If this is the case what are the steps to renew my current cert but with a larger key length.

thanks

Tim
timb551Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
Simon Butler (Sembee)Connect With a Mentor ConsultantCommented:
Don't bother with IIS.
Do the certificate request through Exchange 2010 using its wizard and complete the request on Exchange as well.
Until you enable the certificate, nothing will change for the clients.
That is the safest way.

Simon.
0
 
mumbaiexpertsCommented:
Hi, kindly foloow the below links and increase the key size first and then renew the certificates.Increase the key size with the help of the below mentioned articles

http://www.geocerts.com/support/iis_upgrade_key_size,
https://support.quovadisglobal.com/KB/a88/how-to-increase-your-csr-key-size-on-microsoft-iis.aspx.

Once complete the above process renew the certificate with the help of this article.
http://exchangepedia.com/2008/01/exchange-server-2007-renewing-the-self-signed-certificate.html

Thanks.
0
 
timb551Author Commented:
Im using iis7 is there a guide for that or do I need to try and follow as best I can to the iis6 one.
0
NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

 
timb551Author Commented:
Do you mean create a new request through exchange? rather than a renewal.
0
 
Simon Butler (Sembee)ConsultantCommented:
Correct.
That will mean putting all of the information in again, but that will allow you to do the request in such a way that it doesn't interfere with the live certificate.

Simon.
0
 
timb551Author Commented:
But when i swap to the new one will i need to install the new cert on all the clients that currently connect.
0
 
Simon Butler (Sembee)Connect With a Mentor ConsultantCommented:
No.
That is why you use a commercial trusted certificate, because you don't have to install it on the clients. It is the same certificate type as used by your Bank, Amazon et al. They don't require you to install their certificate.

Simon.
0
 
timb551Author Commented:
ok thats great, thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.