Solved

New SSL certificate needed for SBS2011 with 5 email domains

Posted on 2013-12-19
3
421 Views
Last Modified: 2013-12-25
Hello Experts - we have an SBS2011 server with a self-signed certificate which has been working fine until we created autodiscover DNS records to fix calendars for Outlook Anywhere staff.

We have a single static public IP address

Out set up is like this:

the cn of the existing cert is remote.company.com.au

Outlook Anywhere proxy server :  remote.company.com.au

This server also collects mail for 5 other domains.

The autodiscover DNS address for each of these domains looks like:


Autodiscover.company.com.au
Autodiscover.company2.com.au
Autodiscover.company3.com.au
Autodiscover.company4.com.au
Autodiscover.company5.com.au
Autodiscover.company5.com.au

We have one static IP address

Outlook now produces this error about 30 seconds after opening (see attached)



I checked ClientAccessServer and WebServicesVirtualDirectory settings in Exchange and they look fine

I think we need a new certificate but don't know enough about them

Someone has suggested a UN / SAN certificate such as from:

http://www.geotrust.com/ssl/ssl-certificates-san-uc/ 

Any help appreciated

thanks
Outlook-Cert-Error.png
0
Comment
Question by:Brett4567
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 19

Assisted Solution

by:R--R
R--R earned 250 total points
ID: 39731136
You can create a CSR in Exchange with all the domain names required and submit the file to the CA, they will provide you with required certificate.

You can go to godaddy.com and check it.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 250 total points
ID: 39731279
On SBS 2011, you need to create the certificate request through Exchange, but enable it through SBS. If you do it any other way then you get problems.

http://exchange.sembee.info/2010/install/ssl-sbs2011.asp

You will need to include remote.example.com and Autodiscover.example.com.
Watch the SSL wizard as it will try to set example.com as the common name - you need to change it to remote.example.com.

Simon.
0
 

Author Closing Comment

by:Brett4567
ID: 39739317
Thank you both. Have purchased from Go Daddy
0

Featured Post

Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
exchange , email 8 38
Outlook 2016 connecting to SBS 2011 (Exchange 2010) 2 43
exchange 2013 10 29
Block Hacker? 2 27
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question