Improve company productivity with a Business Account.Sign Up

x
?
Solved

SAN Cert SSL Hell

Posted on 2014-03-18
5
Medium Priority
?
349 Views
Last Modified: 2014-07-15
Is it possible to take the SAN cert for exchange 2010 I got from Godaddy and push it to all our clients so Outlook doesn't keep yelling about our internal CAS array not being in the SAN cert?
0
Comment
Question by:mauisun
  • 2
  • 2
5 Comments
 
LVL 41

Expert Comment

by:Mahesh
ID: 39937027
CAS array name is not required in SAN certificate
You need to setup Split DNS so your internal Exchange hostnames are same as external hostnames
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937041
Thanks for your comment.

SAN cert says webmail.domain.org, autodiscover.domain.org.
Outlook is connecting to cas1.localdomain.org, cas2.localdomain.org

we used to have two TMGs. They're gone now. And we've applied the public cert to the cas servers.

I'm  a little lost here.
0
 
LVL 1

Author Comment

by:mauisun
ID: 39937210
But the SAN SSL still has to have the server name in it yes?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 39937281
The SSL certificate does not have to have the name of the server in it, and I would go as far as to say it shouldn't do.

The CAS Array is a unique host name, used for the MAPI TCP access only. It should not be used for anything else.

Configure a split DNS system so the external name resolves internally, then use the article of mine above (also at http://semb.ee/hostnames) to configure Exchange to use the external host name internally.

That will stop the errors - no need to push anything to the clients.

Simon.
0

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In an Exchange Crossforest migration, the distribution groups can be a very complex operation that would cause loss of time, lots of issues and continued headaches if not solved in a timely manner. I had to do a similar project so I created a sc…
In migration, Powershell can be a very crucial tool to achieve success and finalize projects within deadline or even fix issues. X500 or Legacy Exchange DN Attribute can cause lots of issue during the migration
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question