Solved

SAN Cert SSL Hell

Posted on 2014-03-18
5
330 Views
Last Modified: 2014-07-15
Is it possible to take the SAN cert for exchange 2010 I got from Godaddy and push it to all our clients so Outlook doesn't keep yelling about our internal CAS array not being in the SAN cert?
0
Comment
Question by:mauisun
  • 2
  • 2
5 Comments
 
LVL 35

Expert Comment

by:Mahesh
ID: 39937027
CAS array name is not required in SAN certificate
You need to setup Split DNS so your internal Exchange hostnames are same as external hostnames
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937041
Thanks for your comment.

SAN cert says webmail.domain.org, autodiscover.domain.org.
Outlook is connecting to cas1.localdomain.org, cas2.localdomain.org

we used to have two TMGs. They're gone now. And we've applied the public cert to the cas servers.

I'm  a little lost here.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39937076
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937210
But the SAN SSL still has to have the server name in it yes?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39937281
The SSL certificate does not have to have the name of the server in it, and I would go as far as to say it shouldn't do.

The CAS Array is a unique host name, used for the MAPI TCP access only. It should not be used for anything else.

Configure a split DNS system so the external name resolves internally, then use the article of mine above (also at http://semb.ee/hostnames) to configure Exchange to use the external host name internally.

That will stop the errors - no need to push anything to the clients.

Simon.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
how to add IIS SMTP to handle application/Scanner relays into office 365.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now