Solved

Self signed certificate on Exchange 2013

Posted on 2013-10-24
6
691 Views
Last Modified: 2013-10-29
Hi,

I am in the process of doing an Exchange 2007 to 2013 migration. On our current 2007 environment we are just using a self signed certificate as we don't use Outlook Anywhere. We do use OWA but we just have the DNS entry for OWA pointing to the Exchange server and users don't mind clicking through the security alert to get to the login page.

In Exchange 2013 is it fine to run it like this with just the self signed certificate or do we need to buy a SAN or wildcard certificate?

The current users are running Outlook 2010 on Windows XP and Windows 7.
0
Comment
Question by:southwestsixteen
6 Comments
 
LVL 13

Expert Comment

by:Mark Galvin
ID: 39596995
You can continue with the self signed cert but, as you probably know, its not the recommended way.

Thanks
Mark
0
 
LVL 6

Accepted Solution

by:
vmdude earned 500 total points
ID: 39597005
If possible I would always go with a SAN certificate. There are arguments for and against wildcards, but I'm a fan of the SAN :)

Yes you can function with a self-signed certificate but you can get SAN certificates relativity cheaply these days and this will ensure that you are configured to best practice and, should the need arise that you need to use either OWA, Outlook Anywhere or ActiveSync, then you have the certificate all ready and waiting to go.
0
 
LVL 3

Author Comment

by:southwestsixteen
ID: 39597126
Thanks for the advice guys. We currently have the self signed and are able to connect emails to our phones with Activesync (by just ignoring the security error). Will this still be the case in Exchange 2013?
0
Want to promote your upcoming event?

Attending an event? Speaking at a conference? Or exhibiting at a trade show? Easily inform your contacts by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

 
LVL 13

Expert Comment

by:Mark Galvin
ID: 39597169
yes
0
 
LVL 6

Expert Comment

by:vmdude
ID: 39597176
OWA will work, but I'm not sure 100% with phone devices. Some will not allow you to continue without a certificate that the device trusts.
If you are planning the use ActiveSync then I would still advise that it is worth investing the $ in a SAN certificate.
0
 
LVL 12

Expert Comment

by:Md. Mojahid
ID: 39599823
you can't use active sync device if you want to then you have to trusted certificate.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now