Solved

Certificate issue in Exchange 2010

Posted on 2013-11-27
8
280 Views
Last Modified: 2013-11-27
We have installed public SAN certificate in Exchange 2010 and everything works fine.

However, we encounter problem when users are connecting to the internal LAN, as the public server don't have the internal name for the Exchange servers. Actually, we have already generated a certificate with alterative name but it still doesn't work. Is it because the IIS service doesn't bind to the internal server ?

However, if we bind the IIS service to internal certificate, the external access would not work.

Any idea for the problem ?

Tks
EX01.png
0
Comment
Question by:AXISHK
  • 5
  • 2
8 Comments
 
LVL 15

Assisted Solution

by:Jaroslav Mraz
Jaroslav Mraz earned 200 total points
ID: 39680111
Hi,

simple generate the certificate with all of names you need in new exchange certification wizard.

in part of Certified Domains the last step. Add all of domains you wanted to have in certificate but YOU MUST USE FDQN server.domain.extention format.

http://exchangeserverpro.com/configure-an-ssl-certificate-for-exchange-server-2010/

Then save your request and submit it to AD Certificate authority from web server https://servername/certsrv  SUBMIT Certificate request

but download in BASE 64 it usually works better every other steps from https://servername/certsrv in manual down is same.

http://exchangeserverpro.com/how-to-issue-a-san-certificate-to-exchange-server-2010-from-a-private-certificate-authority/

or you can use commercial pays authority like godady
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 300 total points
ID: 39680311
All you need to do is configure a split DNS so the external name resolves internally, then configure Exchange to use the external name internally.
http://semb.ee/hostnames

No need to generate new certificates if you already have a trusted certificate, as that just increases headaches and unless you control every machine connecting an internal certificate is going to generate prompts.

Simon.
0
 

Author Comment

by:AXISHK
ID: 39680345
Internal and external use the same domain.
internal: ex01.abc.com ex02.abc.com exdag.abc.com mail.abc.com autodiscover.abc.com
external:mail.abc.com autodiscover
lls bind to
0
 

Author Comment

by:AXISHK
ID: 39680349
lls bind to public certificate
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:AXISHK
ID: 39680361
Currently mail.abc.com is resolved with interal lp address
0
 

Author Comment

by:AXISHK
ID: 39680375
For my problem is it affected by lls bind to public cert
0
 
LVL 15

Expert Comment

by:Jaroslav Mraz
ID: 39680390
When you have a certificate with every name you need because this is basic problem in lot of corporation people usually make one certificate with name mail .... and server needs one certificate with multiple names like in manual up.

Then second thing is after import a certificate you must use Exchange console to assign services to the certificate

you go to:

server configuration
select certificate you want
in right axing services to certificate
and chose all services you want tu have for certificate IIS, POP3, IMAP ..... it is simple wizard

after you can test it
0
 

Author Closing Comment

by:AXISHK
ID: 39682579
Great Tks.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
how to add IIS SMTP to handle application/Scanner relays into office 365.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now