?
Solved

Exchange 2010 TLS and Certificate Question.

Posted on 2015-02-18
5
Medium Priority
?
135 Views
Last Modified: 2015-02-18
Newly built Exchange 2010 fully updated.  Initiating a certificate request and am wondering about Mutual TLS.

The server is already responding with opportunistic TLS because I see the TLS response during a telnet
test:  250-STARTTLS.

Do I even need to select Mutual TLS in the certificate request wizard?  Is it reccomended?

Hub Transport Server : Use mutual TLS to help secure internet mail

Finally I have test mailbox that I online moved to the new server and I have connected that outlook 2010 account to the new Exchange 2010 server yet I see the certificate from the old Exchange 2010 server when I configure a new outlook connection.   Currently the two Exchange 2010 servers are co-existing but is this normal to see the old server's self signed cert in new outlook clients of the new server?

Thanks,
Rich
0
Comment
Question by:rjearley1966
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40617104
For complete details on Mutual TLS I would refer to the technet below which outlines the entire process.
https://technet.microsoft.com/en-us/library/bb123543%28v=exchg.141%29.aspx

Do you have your CAS servers load balanced? You are using Exchange 2010 so when you get a new certificate you will need to update the cert on all of the Exchange 2010 servers. You will also need to run the Enable-ExchangeCertificate -Thumbprint <> -Services "pop,imap,smtp,iis" as well on all of your CAS Servers.

Once you have tested this you can remove old certs using the Remove-ExchangeCertificate -Thumbprint <> -Services "pop,imap,smtp,iis"

Depending on how your have your virtual directories set for your internal URL's you might have to keep the self singed cert if you are pointing to the fqdn of the server name. Personally if you have split DNS configured I would be have the External and Internal URL's the same for simplicity.

Will.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617115
Hello Will,

No CAS Servers we are doing an in place transition from physical Exchange Server 2010 to Virtual Exchange 2010.  

So currently our two Exchange Servers are essentially sharing a self signed cert?  

I just went through the wizard and submitted the request to Digicert.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617121
There is a pending cert request on the new server only.  Nothing under the old server except for the old self signed cert which is set to expire in June.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 1500 total points
ID: 40617223
If you have 2 CAS servers in your environment and they are not being properly load balanced (they are dependent on each other), meaning it will be a round robin affect when clients access their mailboxes. They will reference Active Directory for a CAS server and AD shows 2 CAS servers and will send a the request to either one.

Now if you power off one of the CAS servers you you will run into issues because as stated above, they are dependent on each other. AD does not show these machines in any time of load balancing configuration so it will send requests to both CAS servers even when one is offline. This will create error messages for clients etc.

Will.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617272
Understood thanks.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question