Solved

Exchange 2010 -DAG, CAS - SSL SAN Cert, update internal names to external

Posted on 2015-01-29
3
21 Views
Last Modified: 2015-05-28
Hello Experts,

A little background about  my environment: Exchange 2010, 2 CAS servers using Windows NLB, and 2 Database DAG servers. Both running 2008 R2.

I am in the middle of renewing my SSL SAN cert for my Exchange 2010 environment and I know that your are no longer allowed to use Internal names on the cert. I know that I need to change my: Autodiscover, OAB, Web Services, ActiveSync, OWA, and ECP to reflect the external domain name which is not a problem. My worry comes when updating the CAS array name from casarray.internal.local to mail.external.domain.

I see that I can basically change the internal name on the NLB by updating the Full Internet Name value under properties of the load balancer. I can also update the RPC value of the mailbox databases to use the external domain via PS. What I need is some clarification on are the Outlook profiles. From what I am reading, Exchange 2010 SP2 RU 3 and higher will automatically force the Outlook client to update to the new value. Is that correct? I am running SP3 Rollup 8a so I should be in the clear. I would hate to have my users redo all their Outlook profiles...

Thanks in advance,
-Mike
0
Comment
Question by:BAYCCS
  • 2
3 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40577943
There should be no issues doing this. Just make sure that you have the proper DNS records associated with your name change. Also you could test this by adding a local record to your host file as well. But you should be fine.

Will.
0
 
LVL 5

Author Comment

by:BAYCCS
ID: 40577982
What happens if I make these changes during the day? Would users see a major disruption or would they just get prompted in Outlook after the changes are made?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40577997
If the URL changes and you are using Exchange 2010 it uses persistent connections from CAS to the mailbox server. This means that you will break the connection between the CAS and Mailbox server for each user. They will need to close and re-open Outlook.

Autodiscover should take care of any clients pointing to a cached dns entree on their local machine for the internal.domain.com

Will.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Check out this infographic on what you need to make a good email signature that will work perfectly for your organization.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
This video discusses moving either the default database or any database to a new volume.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now