?
Solved

New Exchange 2010 Certificate

Posted on 2014-01-06
7
Medium Priority
?
300 Views
Last Modified: 2014-01-29
Hello,
We are in the process of renewing our SAN cert for our Exchange 2010 environment. We are also going to change the domain that will be used for all of our ActiveSync devices.  When I go through the Exchange Configuration page of the cert request it looks like it only allows me to choose one address for ActiveSync. We would like to apply the certificate without causing all of our current ActiveSync devices to stop working. Is this possible?

Also will I need an auto-discover for the new domain? We currently have
mail.domain.com
autodiscover.domain.com
domain.com

And would like to add --> mail.domain.mobi for ActiveSync clients.
0
Comment
Question by:Damon Rodriguez
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39759980
The names you select in the wizard have no bearing on the names used for ActiveSync.
Therefore just step to the end, and add in the required names - so host.example.com Autodiscover.example.com, host.example.mobi etc.
If you have the old and the new name then clients will continue to work fine, just change the virtual directories so that any that can use Autodiscover will pick up your preferred address.

Simon.
0
 

Author Comment

by:Damon Rodriguez
ID: 39763614
Ok Thanks. 1 last question. Do you know if users will prompted to accept the new certificate on their mobile devices? We would like to forewarn people before we do it if that is the case.
0
 

Author Comment

by:Damon Rodriguez
ID: 39763641
Disregard the previous post please.

After reading a bit more on this I am wondering if you meant that I should configure an autodiscover redirect site?

Couldn't I use an external SRV record instead?
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39766177
Autodiscover is based on the user's email address.
Therefore if you have autodiscover.example.com in the SSL certificate, and the user is @example.com, then  you are fine, even if the ActiveSync URL is host.example.mobi.

When it comes to the SSL certificate, as long as the certificate is trusted by the client and has the old and the new name as one if its additional names then you shouldn't get any prompts - the change will be completely transparent to the end users.

Simon.
0
 

Author Comment

by:Damon Rodriguez
ID: 39766504
Ok I understand what is needed for the cert, thanks for clarifying. However I am now a bit confused about the external URL.  All I've read about is multi-site configurations but nothing on just using a different URL but not having a different email domain for activesync users. I was just going to make a cname record that pointed to autodiscover.domain.com but all the references to this says to use an SRV record or to add a redirect site.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1200 total points
ID: 39766789
The external URL can be anything you like - it doesn't really matter, as long as it is on the SSL certificate and resolves correctly.
The only host name that matters is Autodiscover, because that comes off the email address. Autodiscover returns the host name that you have configured.

If you aren't using the domain for email, then you don't need an Autodiscover record for it.

Simon.
0
 

Author Closing Comment

by:Damon Rodriguez
ID: 39818168
Thank you for the quick response on this. We need to wait for the Quarter End call, which is this week, and then we can make the changes. I am awarding you the points as this question was flagged as abandoned.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses
Course of the Month11 days, 1 hour left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question