Solved

New SSL certificate needed for SBS2011 with 5 email domains

Posted on 2013-12-19
3
412 Views
Last Modified: 2013-12-25
Hello Experts - we have an SBS2011 server with a self-signed certificate which has been working fine until we created autodiscover DNS records to fix calendars for Outlook Anywhere staff.

We have a single static public IP address

Out set up is like this:

the cn of the existing cert is remote.company.com.au

Outlook Anywhere proxy server :  remote.company.com.au

This server also collects mail for 5 other domains.

The autodiscover DNS address for each of these domains looks like:


Autodiscover.company.com.au
Autodiscover.company2.com.au
Autodiscover.company3.com.au
Autodiscover.company4.com.au
Autodiscover.company5.com.au
Autodiscover.company5.com.au

We have one static IP address

Outlook now produces this error about 30 seconds after opening (see attached)



I checked ClientAccessServer and WebServicesVirtualDirectory settings in Exchange and they look fine

I think we need a new certificate but don't know enough about them

Someone has suggested a UN / SAN certificate such as from:

http://www.geotrust.com/ssl/ssl-certificates-san-uc/

Any help appreciated

thanks
Outlook-Cert-Error.png
0
Comment
Question by:Brett4567
3 Comments
 
LVL 19

Assisted Solution

by:R--R
R--R earned 250 total points
ID: 39731136
You can create a CSR in Exchange with all the domain names required and submit the file to the CA, they will provide you with required certificate.

You can go to godaddy.com and check it.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 250 total points
ID: 39731279
On SBS 2011, you need to create the certificate request through Exchange, but enable it through SBS. If you do it any other way then you get problems.

http://exchange.sembee.info/2010/install/ssl-sbs2011.asp

You will need to include remote.example.com and Autodiscover.example.com.
Watch the SSL wizard as it will try to set example.com as the common name - you need to change it to remote.example.com.

Simon.
0
 

Author Closing Comment

by:Brett4567
ID: 39739317
Thank you both. Have purchased from Go Daddy
0

Featured Post

Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
how to add IIS SMTP to handle application/Scanner relays into office 365.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now