Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Exchange 2010 UC SAN Certificate Questions.

Posted on 2015-02-04
2
Medium Priority
?
167 Views
Last Modified: 2015-02-04
Hey Folks,

I have stood up a new Exchange 2010 SP3 Server (VM) into an existing 2010 Standard Site.  I need to go through the New Exchange Certificate Wizard and have a few questions.

On the wizard step below I am seeing the old server MSX (currently in production) listed with new server. Should I leave the old server "MSX" in the field below?  Does it cause any issues to remove it and leave just the new server "MSX-V"?  Not cutting over for a month or so.

Client Access server (Outlook Web App)
    Domain name you use to access Outlook Web App internally.
       msx.ourdomain.com,msx-v.ourdomain.com


Under the wizard step below the wizard double entered the domain name?  Should txt in bold be removed?

Client Access Server (Web Services, Outlook Anywhere, and Autodiscover)
Outlook Anywhere is enabled
      External host name for your organization (example: mail.contoso.com)
            mail.ourdomain.com,ourdomain.com

Under the wizard step below it is populating the field with ourdomain.com shouldn't this be mail.ourdomain.com?

Hub Transport server
      Use mutual TLS to help secure Internet mail.
            ourdomain.com

I am looking at Digicert, Geotrust and Thawte for the UC SAN Certificate.  Anyone have any issues with any of the three and is there any consensus on which one is best?  

Thanks,
Rich
0
Comment
Question by:rjearley1966
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 40590030
Certificate vendor - personally I use a GoDaddy reseller, as they have widespread device coverage and are cheap.

The certificate wizard takes its information from the configuration of Exchange. With the recently changes to the certificate rules, the best practise is to no longer use the internal server name anywhere, but to change to using the public name both internally and externally.
http://semb.ee/hostnames2010

The certificate wizard also makes the common name the root of the domain. I have never understood why and will always remove it. Make the common name the name the users will use most - mail.example.com.
In most cases you can get away with just two names on the certificate:
- mail.example.com
- Autodiscover.example.com

Any others are optional.

Simon.
0
 
LVL 1

Author Closing Comment

by:rjearley1966
ID: 40590155
Thanks a bunch Sembee,
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you an Exchange administrator employed with an organization? And, have you encountered a corrupt Exchange database due to which you are not able to open its EDB file. This article will explain all the steps to repair corrupt Exchange database.
This month, Experts Exchange sat down with resident SQL expert, Jim Horn, for an in-depth look into the makings of a successful career in SQL.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question