Solved

Issue with Updating Exchange UCC SSL Certificate and local domain name

Posted on 2014-01-22
4
1,549 Views
Last Modified: 2014-01-22
I am running Exchange 2010 on an IIS 6 server.  My certificate is expiring, so I went and got a new UCC certificate.  The valid domains were:

webmail.domain.com
autodiscover.domain.com
email-01
email-01.domain.local

When I renewed the certificate I was not allowed to renew the "email-01" and "email-01.domain.local" because they can't be verified.  I didn't think anything of it at the time.

However this morning I installed the new certificate and now my users are getting a warning when opening outlook that the name on the certificate doesn't match.  They are connecting to email-01.domain.local.

I understand what is happening, but not sure of the best resolution.

Suggestions?
0
Comment
Question by:Railroad
  • 2
4 Comments
 
LVL 16

Accepted Solution

by:
Carol Chisholm earned 500 total points
ID: 39800405
You will not be allowed to get a certificate with a "private" domain name any more.
Here's why
http://www.networking4all.com/en/ssl+certificates/faq/change+san+issue/


You have various choices, like changing the virtual directories
http://nathanwinters.co.uk/2010/05/30/script-to-set-internalurl-and-externalurl-for-all-exchange-2010-virtual-directories/
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39800522
As stated you need to configure your virtual directories so that it is pointing to one of the names in the cert. You can no longer using internal domain names and if your clients are pointing to the internal name of the Exchange Vitrual directory it will give you a certificate error because the Exchange server name does not exist in the cert.

We also do the same thing in our environment and internal names need to be added to some certs the way that we get around this is have a .com internal domain have it as a registrar. You can then add your company whois details to this and although you do not have to publish this to the internet it is just another method the 3rd party certificate companies can identify that it is you. If your internal domain name is taken externally, or it is not a valid external domain like (.local) then you are out of luck.

Changing your virtual directories it the quickest fix for your situation.

Will.
0
 

Author Closing Comment

by:Railroad
ID: 39800642
Ran the script to update the virtual directories and all is working.

Thank you for the help!
0
 
LVL 16

Expert Comment

by:Carol Chisholm
ID: 39800731
Glad to be useful.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
A phishing scam that claims a recipient’s credit card details have been “suspended” is the latest trend in spoof emails.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video discusses moving either the default database or any database to a new volume.

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question