Solved

Exchange 2010 SSL Certificate Renewal, no Subject Access Names allowed for internal domain names.

Posted on 2014-09-09
2
241 Views
1 Endorsement
Last Modified: 2014-09-09
Hi,

Up until recently GoDaddy have allowed local names in their SAN for SSL certificates. This meant we could have

external-ex01.ourcompany.com/owa

and

internal-ex01.ourcompany.local/owa

on the same certificate. Unfortuantely CA's have now preventing the renewal on SANs that are not FQDN. We have created Self-Signed Exchange 2010 certificates with the local names and rolled them out to our users via GPO. However Outlook 2010 is still looking at the SSL certificate for the external names.

How do we resolve this?
1
Comment
Question by:SimonBrook
2 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40312107
This is a very common problem and easily resolved.
You just need to use the external host name internally via a split DNS system.

http://semb.ee/hostnames2010

Forget about using self signed certificates, waste of time.

Simon.
0
 
LVL 1

Author Closing Comment

by:SimonBrook
ID: 40312116
Thanks for this!
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
A procedure for exporting installed hotfix details of remote computers using powershell
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question