Solved

Cannot get Signed SSL certificate into the right place in SBS 2011

Posted on 2015-01-12
12
264 Views
Last Modified: 2015-01-25
Been mucking around with SSL certificates for hours.

Long time since I've done this.

Ordered certificates, downloaded, right-clicked on, and installed. (GoDaddy)

Kept getting errors on remote connectivity Analyzer.

Realized that it wasn't using my purchased certificate.

It's in personal, When I try and export it, it won't take all its properties and the import fails.

I followed GoDaddy's Article at: https://support.godaddy.com/help/article/5863/installing-an-ssl-certificate-in-microsoft-exchange-server-2010?locale=en

When I get to to #23, I do not see "Complete Pending Request..."
0
Comment
Question by:MJCS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +3
12 Comments
 
LVL 29

Expert Comment

by:becraig
ID: 40545944
Ok so from what you are saying it seems like you have already processed the request.

Are you running all this on the same server you need to install the certificate on ?


You indicated the certificate is now installed in personal, verify it has the private key installed
You can do this by double clicking the certificate (you should see text that says "You have a private key ..."

Once this is done simply run the fix my network wizard and point to the new certificate you just got from godaddy.
0
 
LVL 2

Author Comment

by:MJCS
ID: 40545946
Ran the wizard, it only sees the self-signed key. Then says it can't fix it, restart certificate service and retry.

I rebooted

Same.
0
 
LVL 29

Assisted Solution

by:becraig
becraig earned 100 total points
ID: 40545950
Did you see an indication that they private key is installed for the new certificate when you opened it in the mmc ?

winkey + r
mmc.exe
Add Remove Snap in
Certificates
Local Computer
Expand Personal

If the cert is present look to see if they private key is present.

If not ask to have it rekeyed, or simply do a repair on the certificate with the following command
certutil -repairstore MY serialnumber (obtained from the details tab in the new certificate)


Then try the wizard again.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 2

Author Comment

by:MJCS
ID: 40545993
Network repair wizard?
0
 
LVL 29

Expert Comment

by:becraig
ID: 40545999
The fix my network wizard once you're able to get the private key repaired.
0
 
LVL 2

Expert Comment

by:Michael Zehr
ID: 40546143
Hi, did you Import the godaddy intermediate certificate?
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 100 total points
ID: 40546408
The primary reason the wizard will not see your certificate is due to a common name mismatch.
The wizard only looks at the common name.

Therefore if the wizards in SBS were run in their default configuration, the common name it wants to see is remote.example.com. If the common name is mail.example.com or even example.com then the wizard will not see the certificate and you cannot choose it.

With an SBS server, it is best to use remote.example.com everywhere, as per the wizards expectation. It also makes following any tutorials easier.
However if you created the SSL certificate request in Exchange 2010 and didn't change the configuration, then the common name will be example.com (ie the root of the domain) rather than remote.example.com.

Simon.
0
 
LVL 35

Assisted Solution

by:Cris Hanna
Cris Hanna earned 200 total points
ID: 40546411
This article was written by a member of the SBS team.   It works exactly the same for SBS 2011 as it does on SBS 2008
http://sbs.seandaniel.com/2009/02/installing-godaddy-standard-ssl.html  Installing a GoDaddy Standard SSL Certificate on SBS 2008
0
 
LVL 6

Assisted Solution

by:Flipp
Flipp earned 100 total points
ID: 40548129
Not sure if this applies to your cert or not, but http://blogs.msmvps.com/bradley/2010/02/18/so-ya-wanna-in-your-trusted-cert-wizard/ explains how to have a non-remote.domain.com cert to show in SBS wizards when installing a new cert.
Bailed me out a number of times :)
0
 
LVL 35

Assisted Solution

by:Cris Hanna
Cris Hanna earned 200 total points
ID: 40548141
I didn't see anything in the original post to indicate that this is a wildcard cert
0
 
LVL 2

Accepted Solution

by:
MJCS earned 0 total points
ID: 40559804
I appreciate all the comments!

I deleted the certificate and re-ran through GoDaddy's step-by-step. I must have previously done a step wrong because it worked for me that time.
0
 
LVL 2

Author Closing Comment

by:MJCS
ID: 40568984
I've credited the helpful advice, but ultimately it was fixed by re-running the wizard.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2010 CAS array Load Balancing. 7 62
office 365 5 41
SSL on Apache 2... config file 1 33
Disabeld users still apear in Skype For Business 4 31
Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question