Solved

Exchange 2010 -DAG, CAS - SSL SAN Cert, update internal names to external

Posted on 2015-01-29
3
27 Views
Last Modified: 2015-05-28
Hello Experts,

A little background about  my environment: Exchange 2010, 2 CAS servers using Windows NLB, and 2 Database DAG servers. Both running 2008 R2.

I am in the middle of renewing my SSL SAN cert for my Exchange 2010 environment and I know that your are no longer allowed to use Internal names on the cert. I know that I need to change my: Autodiscover, OAB, Web Services, ActiveSync, OWA, and ECP to reflect the external domain name which is not a problem. My worry comes when updating the CAS array name from casarray.internal.local to mail.external.domain.

I see that I can basically change the internal name on the NLB by updating the Full Internet Name value under properties of the load balancer. I can also update the RPC value of the mailbox databases to use the external domain via PS. What I need is some clarification on are the Outlook profiles. From what I am reading, Exchange 2010 SP2 RU 3 and higher will automatically force the Outlook client to update to the new value. Is that correct? I am running SP3 Rollup 8a so I should be in the clear. I would hate to have my users redo all their Outlook profiles...

Thanks in advance,
-Mike
0
Comment
Question by:BAYCCS
  • 2
3 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40577943
There should be no issues doing this. Just make sure that you have the proper DNS records associated with your name change. Also you could test this by adding a local record to your host file as well. But you should be fine.

Will.
0
 
LVL 5

Author Comment

by:BAYCCS
ID: 40577982
What happens if I make these changes during the day? Would users see a major disruption or would they just get prompted in Outlook after the changes are made?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40577997
If the URL changes and you are using Exchange 2010 it uses persistent connections from CAS to the mailbox server. This means that you will break the connection between the CAS and Mailbox server for each user. They will need to close and re-open Outlook.

Autodiscover should take care of any clients pointing to a cached dns entree on their local machine for the internal.domain.com

Will.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question