Installing digital certificate via powershell

Posted on 2014-11-22
Last Modified: 2016-06-20
I requested a commercial digital certificate for my Exchange 2010 on Windows 2012 to migrate mailboxes from Exch 2003 to 2010. I then later installed the received commercial certificate  using powershell rather than running the Exchange 2010 EMC to complete the pending request certificate status. I also assigned services using powershell. But I noticed that the CSR status in Exhange Management Console still says "pending". Would that ever go away or do I need to again install the digital certificate but this time use the EMC and also assign the services via EMC?? I am tempted to run it again and complete the pending request via EMC, but I am concern that it may have un-intended effect on the certificate or the exchange configuration. When I used the cmdlet get-exchangecertificate | fl I can see my digital certificate and it did say valid for status and also I can see the services I assigned, and it did say too the CA issuer so it looked like it was installed properly but EMC says otherwise. Any ideas?? Let me know please. Thanks!
Question by:lotusmail1
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3

Expert Comment

ID: 40459416
Check the cert you have installed in the certmgr.msc Personal store. In the Properties/General tab does it have the "You have a private key that corresponds to this certificate" message showing?

If not, then you need to copy the Thumbprint value on the Details tab and run the following command in Powershell:

Certutil –repairstore My <thumbprint>


Author Comment

ID: 40459522
Thanks for the reply.
I checked and it did say "You have a private key that corresponds to this certificate"  in the general tab. Would it hurt if I re-run and complete the CSR request via EMC this time? Let me know please. Thanks!

Expert Comment

ID: 40459524
In that case, could it be possible that you initially generated 2 CSRs, and only one has been (correctly) completed?
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Expert Comment

ID: 40459525
You could try and complete the unfinished CSR through EMC but it's unlikely to work though as I suspect the cert you have may not match the original CSR. If you have it working you should able to cancel the outstanding CSR with no ill effect.

Author Comment

ID: 40459526
That's a good point, but I am not sure as I had somebody performed the CSR request and I heard that he had trouble the first time. I will verify it and get back. Thanks for your quick reply.


Accepted Solution

lotusmail1 earned 0 total points
ID: 40460652
Hi there,

Ok I think I found out the reason why the CSR in EMC was still showing despite successful installation of the certificate via Powershell. During the process of installing the certificate via Powershell I had all the services included ie IIS, POP, IMAP, SMTP and Powershell prompted me to respond to a question:
Do you want to enforce SSL communication on the root web site? If not, rerun the cmdlet with the -DoNotRequireSSL parameter. I clicked "No". I should have click "yes" because as far as the system is concern my effort was incomplete hence when I checked the CSR in the EMC the pending request CSR is still showing.  Anyway I went ahead and assigned IIS service via Powershell and that completed the whole CSR request per EMC. Thanks for time and advice. This issue is closed.

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question