Simon Chen
asked on
can I delete all expire cert in Exchange shell
hi,
I have renewed the self signed certificate in Exchange Server 2007 on our SBS 2008, and I found there is lots expired cert in the list. can I delete them all? and also I found in the server even log there show a error msg, is that caused by expired cert? I can receive and send email without any issue.
error msg is:
There is no valid SMTP Transport Layer Security (TLS) certificate for the FQDN of remote.xxx.com. The existing certificate for that FQDN has expired. The continued use of that FQDN will cause mail flow problems. A new certificate that contains the FQDN of remote.xxxx.com should be installed on this server as soon as possible. You can create a new certificate by using the New-ExchangeCertificate task.
cert.JPG
I have renewed the self signed certificate in Exchange Server 2007 on our SBS 2008, and I found there is lots expired cert in the list. can I delete them all? and also I found in the server even log there show a error msg, is that caused by expired cert? I can receive and send email without any issue.
error msg is:
There is no valid SMTP Transport Layer Security (TLS) certificate for the FQDN of remote.xxx.com. The existing certificate for that FQDN has expired. The continued use of that FQDN will cause mail flow problems. A new certificate that contains the FQDN of remote.xxxx.com should be installed on this server as soon as possible. You can create a new certificate by using the New-ExchangeCertificate task.
cert.JPG
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
I would make sure I had a new cert for all the in-use ones you have before deleting them. If not for anything but to have their info to refer to when generating/requesting a new cert.
- gurutc
- gurutc
ASKER
here is my live cert, is that mean I have connect all the service? can i go ahead to delete the expired cert now or still need to check? and how to check it?
I have gone through all the cert and found the status is invalid.
cert2.JPG
I have gone through all the cert and found the status is invalid.
cert2.JPG
The link I provided above should give you a clear walkthrough on how to validate before you delete anything.
Type
get-exchangecertificate | fl
in the Exchange Management Shell to check and see what services are connected to the certificate.
ASKER
good support
Once the expired certificates have no services connected to them run the following from the Exchange Management shell
Open in new window
where