Solved

SAN Cert SSL Hell

Posted on 2014-03-18
5
336 Views
Last Modified: 2014-07-15
Is it possible to take the SAN cert for exchange 2010 I got from Godaddy and push it to all our clients so Outlook doesn't keep yelling about our internal CAS array not being in the SAN cert?
0
Comment
Question by:mauisun
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 39937027
CAS array name is not required in SAN certificate
You need to setup Split DNS so your internal Exchange hostnames are same as external hostnames
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937041
Thanks for your comment.

SAN cert says webmail.domain.org, autodiscover.domain.org.
Outlook is connecting to cas1.localdomain.org, cas2.localdomain.org

we used to have two TMGs. They're gone now. And we've applied the public cert to the cas servers.

I'm  a little lost here.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39937076
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937210
But the SAN SSL still has to have the server name in it yes?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39937281
The SSL certificate does not have to have the name of the server in it, and I would go as far as to say it shouldn't do.

The CAS Array is a unique host name, used for the MAPI TCP access only. It should not be used for anything else.

Configure a split DNS system so the external name resolves internally, then use the article of mine above (also at http://semb.ee/hostnames) to configure Exchange to use the external host name internally.

That will stop the errors - no need to push anything to the clients.

Simon.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question