Solved

SSL Certificate renewal not working on Exchange 2003

Posted on 2014-01-10
6
743 Views
Last Modified: 2014-01-10
Hi Experts!

We've got a customer with an SSL certificate that expired and we tried to renew it.  Everything works with the CSR request, but when we get the certificate back via email from our SSL provider, it won't import the certificate.  Currently, I've manually imported the certificate (using the certificates add-in in MMC) and have attached the proper certificate (meaning it has the new expiration date) to the Default Website (the one that contains /exchange).  However, it's not working.  Anyone have some ideas I can try?  I've disabled the "default" Rapid SSL certificate and imported the certificate authority that they sent.  We're stuck and the customer can't get email via smart phones or web.

Thanks!
0
Comment
Question by:tganus
  • 4
  • 2
6 Comments
 

Author Comment

by:tganus
ID: 39770933
I've even tried deleting the certificate and going through the entire process (by creating a new certificate request in directory security).  But it refuses to import the .cer file I create and talks about private keys (sorry I don't have the exact error message)...
0
 

Author Comment

by:tganus
ID: 39770969
Here's the exact error message when I try to import the .cer file:

The pending certificate request for this response file was not found.  This request may be canceled.  You cannot install selected response certificate using this Wizard.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39771182
I would go back to the SSL provider and ask if you can get the SSL certificate reissued from a new CSR. Then generate a new CSR in IIS manager and send it to them.

It isn't unusual for CSRs to get corrupt at either stage - I remember once having to do it five times because the firewall was corrupting it!

Simon.
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:tganus
ID: 39771431
I got a new SSL certificate (a wildcard this time) from our provider and went through the entire process and it worked.  But, I can't access my website.  It's not giving me any errors or anything, even local https://servername doesn't work.  I'm lost.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39771918
Check in IIS manager that you have the correct bindings. You should have two - 80 and 443.

Simon.
0
 

Author Comment

by:tganus
ID: 39771975
Simon,

Thanks for the help.  Ended up doing the new certificate and it worked, but I had followed some instructions elsewhere on EE about doing the certificate renewal with a temporary website.  IIS had started the temp website instead of "Default Website".  Once I deleted the temporary one, all is well.  Still would have liked to figure out the corruption of the old one, but completely new SSL certificate wins.  Thanks!
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now