Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Generate Certificate file in Exchange 2010

Posted on 2015-01-02
6
Medium Priority
?
144 Views
Last Modified: 2015-01-09
When generating Certificate file for Exchange 2010, do we need to do that for CAS server only or other servers too (such as HT , Edge, Mbox) ?
if we generate certificate for CAS server only, does it matter which CAS we select to generate certificate file?

I have see the steps in the link below, but I still need some clarifications, since they have just one server shown in the snapshot.

http://exchangeserverpro.com/configure-an-ssl-certificate-for-exchange-server-2010/

Any help will be appreciated .

Thanks
0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 668 total points
ID: 40528801
When generating Certificate file for Exchange 2010, do we need to do that for CAS server only or other servers too (such as HT , Edge, Mbox) ?

CAS only. If you have multiple CAS, once you process the request, you export it from one and import into others.

if we generate certificate for CAS server only, does it matter which CAS we select to generate certificate file?

Doesn't matter. As long as you complete the request on the same server. Once completed you can export and import the cert to other CAS servers.

That article is correct. Paul Cunningham is an Exchange MVP.
0
 
LVL 3

Assisted Solution

by:Sudhir Bidye
Sudhir Bidye earned 668 total points
ID: 40528870
I would recommend to run the CSR generating wizard on the Internet facing CAS server itself, as it's gonna be the first server where you will be installing the certificate.
I have faced private key missing error while exporting and importing certificate between CAS servers sometimes. Of course we can fix them easily with the command but why waste time doing it.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 664 total points
ID: 40529681
You will also need to make sure that when you have installed the cert itself you will still need to proceed to add the appropriate services to the new cert in place. I would also recommend removing the old cert after you have tested the new cert and don't run into any issues.

- Open EMS
get-exchangecertificate
- You should see the current and the new Exchange Cert listed
enable-exchangecertificate -thumbprint xxxxxxxxxxxxxxx -services "pop,imap,smtp,iis"

Once you have tested this and it was successful you can remove the old certificate
remove-exchangecertificate -thumbprint xxxxxxxxxxxxxxx

Will.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 

Author Comment

by:jskfan
ID: 40530098
Sudhir Bidye
Our CAS servers do not have "Internet facing " checkbox enabled.
we have 2 CAS servers do we need to enable one of them for Internet facing ?
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40530240
That is not necessary jskfan.
0
 

Author Closing Comment

by:jskfan
ID: 40541574
Thank you Guys!
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Are you looking for the options available for exporting EDB files to PST? You may be confused as they are different in different Exchange versions. Here, I will discuss some options available.
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question