Solved

Generate Certificate file in Exchange 2010

Posted on 2015-01-02
6
95 Views
Last Modified: 2015-01-09
When generating Certificate file for Exchange 2010, do we need to do that for CAS server only or other servers too (such as HT , Edge, Mbox) ?
if we generate certificate for CAS server only, does it matter which CAS we select to generate certificate file?

I have see the steps in the link below, but I still need some clarifications, since they have just one server shown in the snapshot.

http://exchangeserverpro.com/configure-an-ssl-certificate-for-exchange-server-2010/

Any help will be appreciated .

Thanks
0
Comment
Question by:jskfan
6 Comments
 
LVL 30

Accepted Solution

by:
Gareth Gudger earned 167 total points
Comment Utility
When generating Certificate file for Exchange 2010, do we need to do that for CAS server only or other servers too (such as HT , Edge, Mbox) ?

CAS only. If you have multiple CAS, once you process the request, you export it from one and import into others.

if we generate certificate for CAS server only, does it matter which CAS we select to generate certificate file?

Doesn't matter. As long as you complete the request on the same server. Once completed you can export and import the cert to other CAS servers.

That article is correct. Paul Cunningham is an Exchange MVP.
0
 
LVL 3

Assisted Solution

by:Sudhir Bidye
Sudhir Bidye earned 167 total points
Comment Utility
I would recommend to run the CSR generating wizard on the Internet facing CAS server itself, as it's gonna be the first server where you will be installing the certificate.
I have faced private key missing error while exporting and importing certificate between CAS servers sometimes. Of course we can fix them easily with the command but why waste time doing it.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 166 total points
Comment Utility
You will also need to make sure that when you have installed the cert itself you will still need to proceed to add the appropriate services to the new cert in place. I would also recommend removing the old cert after you have tested the new cert and don't run into any issues.

- Open EMS
get-exchangecertificate
- You should see the current and the new Exchange Cert listed
enable-exchangecertificate -thumbprint xxxxxxxxxxxxxxx -services "pop,imap,smtp,iis"

Once you have tested this and it was successful you can remove the old certificate
remove-exchangecertificate -thumbprint xxxxxxxxxxxxxxx

Will.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 

Author Comment

by:jskfan
Comment Utility
Sudhir Bidye
Our CAS servers do not have "Internet facing " checkbox enabled.
we have 2 CAS servers do we need to enable one of them for Internet facing ?
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
That is not necessary jskfan.
0
 

Author Closing Comment

by:jskfan
Comment Utility
Thank you Guys!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now