Renew Self Signed Cert SBS 2008
Posted on 2014-09-22
Good day folks. I received this error:
"There is no valid SMTP Transport Layer Security (TLS) certificate for the FQDN of SBSERVER01.mydomain.local. The existing certificate for that FQDN has expired. The continued use of that FQDN will cause mail flow problems. A new certificate that contains the FQDN of SBSERVER01.mydomain.local should be installed on this server as soon as possible. You can create a new certificate by using the New-ExchangeCertificate task."
A couple weeks ago I renewed the UCC SSL certificate for server.domain.com. And since there has been an "industry decision" to no longer include .local or intranet domain names within the SANs of SSL certificates, I'm now receiving an error about the self-signed certificate since my FQDN is server.domain.local
Normally this wouldn't be too big of a deal, but since we're dealing with SBS 2008 this makes the things a little different.
All of the AutoDiscover URLs, EWS, OAB, and critical virtual directories of Exchange are all pointed to the server.domain.com and not the .local. Yet the event viewer is still throwing up this error like it's going to cause a disruption in mail flow. I'm not sure I should believe it or not, but I'd like to at least renew the self signed cert.
I would normally accomplish this by using the SBS Console. However since SBS is wizard driven, I have a feeling generating a self signed cert through the "Add a trusted certificate" wizard, it will completely overwrite the cert I just renewed for the .COM.
Any advice would be greatly appreciated. Thank you.