Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

SAN Cert SSL Hell

Posted on 2014-03-18
5
Medium Priority
?
341 Views
Last Modified: 2014-07-15
Is it possible to take the SAN cert for exchange 2010 I got from Godaddy and push it to all our clients so Outlook doesn't keep yelling about our internal CAS array not being in the SAN cert?
0
Comment
Question by:mauisun
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 39937027
CAS array name is not required in SAN certificate
You need to setup Split DNS so your internal Exchange hostnames are same as external hostnames
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937041
Thanks for your comment.

SAN cert says webmail.domain.org, autodiscover.domain.org.
Outlook is connecting to cas1.localdomain.org, cas2.localdomain.org

we used to have two TMGs. They're gone now. And we've applied the public cert to the cas servers.

I'm  a little lost here.
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937210
But the SAN SSL still has to have the server name in it yes?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 39937281
The SSL certificate does not have to have the name of the server in it, and I would go as far as to say it shouldn't do.

The CAS Array is a unique host name, used for the MAPI TCP access only. It should not be used for anything else.

Configure a split DNS system so the external name resolves internally, then use the article of mine above (also at http://semb.ee/hostnames) to configure Exchange to use the external host name internally.

That will stop the errors - no need to push anything to the clients.

Simon.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This video discusses moving either the default database or any database to a new volume.

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question