[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

New Exchange 2010 Certificate

Posted on 2014-01-06
7
Medium Priority
?
305 Views
Last Modified: 2014-01-29
Hello,
We are in the process of renewing our SAN cert for our Exchange 2010 environment. We are also going to change the domain that will be used for all of our ActiveSync devices.  When I go through the Exchange Configuration page of the cert request it looks like it only allows me to choose one address for ActiveSync. We would like to apply the certificate without causing all of our current ActiveSync devices to stop working. Is this possible?

Also will I need an auto-discover for the new domain? We currently have
mail.domain.com
autodiscover.domain.com
domain.com

And would like to add --> mail.domain.mobi for ActiveSync clients.
0
Comment
Question by:Damon Rodriguez
  • 4
  • 3
7 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39759980
The names you select in the wizard have no bearing on the names used for ActiveSync.
Therefore just step to the end, and add in the required names - so host.example.com Autodiscover.example.com, host.example.mobi etc.
If you have the old and the new name then clients will continue to work fine, just change the virtual directories so that any that can use Autodiscover will pick up your preferred address.

Simon.
0
 

Author Comment

by:Damon Rodriguez
ID: 39763614
Ok Thanks. 1 last question. Do you know if users will prompted to accept the new certificate on their mobile devices? We would like to forewarn people before we do it if that is the case.
0
 

Author Comment

by:Damon Rodriguez
ID: 39763641
Disregard the previous post please.

After reading a bit more on this I am wondering if you meant that I should configure an autodiscover redirect site?

Couldn't I use an external SRV record instead?
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39766177
Autodiscover is based on the user's email address.
Therefore if you have autodiscover.example.com in the SSL certificate, and the user is @example.com, then  you are fine, even if the ActiveSync URL is host.example.mobi.

When it comes to the SSL certificate, as long as the certificate is trusted by the client and has the old and the new name as one if its additional names then you shouldn't get any prompts - the change will be completely transparent to the end users.

Simon.
0
 

Author Comment

by:Damon Rodriguez
ID: 39766504
Ok I understand what is needed for the cert, thanks for clarifying. However I am now a bit confused about the external URL.  All I've read about is multi-site configurations but nothing on just using a different URL but not having a different email domain for activesync users. I was just going to make a cname record that pointed to autodiscover.domain.com but all the references to this says to use an SRV record or to add a redirect site.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1200 total points
ID: 39766789
The external URL can be anything you like - it doesn't really matter, as long as it is on the SSL certificate and resolves correctly.
The only host name that matters is Autodiscover, because that comes off the email address. Autodiscover returns the host name that you have configured.

If you aren't using the domain for email, then you don't need an Autodiscover record for it.

Simon.
0
 

Author Closing Comment

by:Damon Rodriguez
ID: 39818168
Thank you for the quick response on this. We need to wait for the Quarter End call, which is this week, and then we can make the changes. I am awarding you the points as this question was flagged as abandoned.
0

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I will demonstrate that how to do a PST migration from Exchange Server to Office 365. This method allows importing one single PST, or multiple PST's at once.
Good news! Plesk 12.5 (with update #28 and above) now includes support for HTTP/2. This is a major update to HTTP1.1, which is over 15 years old. Read below to learn how to enable HTTP/2 on your Media Temple DV with Plesk.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

612 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question