Solved

Multiple UCC SSL certificates on MS Exchange 2010

Posted on 2014-10-23
11
169 Views
Last Modified: 2014-12-25
I have an  Exchange 2010 server that is currently hosting one authoritative domain. For this domain we also have a UCC SSL certificate.  I want to add another authoritative domain.  How can I add a second UCC SSL certificate so the each domain can use their own secured website to access the Exchange server?
0
Comment
Question by:David Barman
  • 6
  • 3
  • 2
11 Comments
 
LVL 4

Expert Comment

by:Sabi Goraya
ID: 40400877
Unless the exchnage is in hosted mode you will have to use the primary domain SSL.

The reason why i say that is because for authentication purposes you still have to use the local domain credentials anyway.

Also it depends on the scenario which meets our requirement.

The SSL is associated with the IIS directory which can only have one certificate associated with it.
0
 

Author Comment

by:David Barman
ID: 40400894
I am not familiar with hosted mode. Can you explain?

IIS is limited to one certificate?
0
 
LVL 4

Expert Comment

by:Sabi Goraya
ID: 40401014
Sorry What i meant was one SSL for Exchange to use with IIS

We offer similar solution to our clients where we host few domains.

What i have done is created  a domain called hosted.local and all the clients can use the same domain for authentication and a SSL certificate for a domain that i created called hosted.sbc.com

By creating a separate database for Hosted i am able to isolate them from the address list for internal business.

Does that work for you?

Can you advise if the second domain is for external client that you are adding or for internal use only?

Sorry for amateur answers as i am trying to figure out what you are trying to achieve and what your limitations or security concerns are ?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40401224
The whole point of having a UCC certificate is to allow different domains to be listed on the certificate.
Therefore if you have mail.example.com as the common name, you can add mail.example.net as an additional name. Users can browse to mail.example.net and get connected without any errors.
Only if they open the SSL certificate properties would they see the common name.

However, even if you were to put a second certificate on to the server, you are not going to be able to hide the common name. You have to configure URLs within Exchange which will correct the browser or device to use the preferred name. Even if you add an additional IIS web site, or server, if they are in the same Exchange org, it is one URL for all users.

What you haven't said is what connection this second domain is to your business.
If it is just an additional subsidiary, then you are fine. If it is a client then you are breaking the terms of your licence agreement. You would need to be on a Microsoft licence scheme for hosting providers.

Simon.
0
 

Author Comment

by:David Barman
ID: 40401860
It's for a sister company that we acquired.
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 

Author Comment

by:David Barman
ID: 40401861
Is it possible to keep the GALs separate by using different databases?
0
 

Author Comment

by:David Barman
ID: 40401865
If I added the other domain name to the certificate, will that allow them to use their domain to access the server either via owa, activesync, or Outlook via rcp over https?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40401872
If you add their domain to the certificate, they will initially use their own name. However it will be corrected to the name as configured on the URLs within Exchange by Autodiscover. It isn't possible to have different URLs for different users unless the servers are separate and in separate active directory sites.

Databases don't separate the GALs. You need to look at Address Book Policies.

Simon.
0
 

Author Comment

by:David Barman
ID: 40401881
But the url will automatically change?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40403162
Yes, it will.
That is done by Exchange and Autodiscover automatically. Nothing you can do to stop that.

Simon.
0
 

Author Closing Comment

by:David Barman
ID: 40517594
Thank you
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now