Solved

Exchange 2010 TLS and Certificate Question.

Posted on 2015-02-18
5
106 Views
Last Modified: 2015-02-18
Newly built Exchange 2010 fully updated.  Initiating a certificate request and am wondering about Mutual TLS.

The server is already responding with opportunistic TLS because I see the TLS response during a telnet
test:  250-STARTTLS.

Do I even need to select Mutual TLS in the certificate request wizard?  Is it reccomended?

Hub Transport Server : Use mutual TLS to help secure internet mail

Finally I have test mailbox that I online moved to the new server and I have connected that outlook 2010 account to the new Exchange 2010 server yet I see the certificate from the old Exchange 2010 server when I configure a new outlook connection.   Currently the two Exchange 2010 servers are co-existing but is this normal to see the old server's self signed cert in new outlook clients of the new server?

Thanks,
Rich
0
Comment
Question by:rjearley1966
  • 3
  • 2
5 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40617104
For complete details on Mutual TLS I would refer to the technet below which outlines the entire process.
https://technet.microsoft.com/en-us/library/bb123543%28v=exchg.141%29.aspx

Do you have your CAS servers load balanced? You are using Exchange 2010 so when you get a new certificate you will need to update the cert on all of the Exchange 2010 servers. You will also need to run the Enable-ExchangeCertificate -Thumbprint <> -Services "pop,imap,smtp,iis" as well on all of your CAS Servers.

Once you have tested this you can remove old certs using the Remove-ExchangeCertificate -Thumbprint <> -Services "pop,imap,smtp,iis"

Depending on how your have your virtual directories set for your internal URL's you might have to keep the self singed cert if you are pointing to the fqdn of the server name. Personally if you have split DNS configured I would be have the External and Internal URL's the same for simplicity.

Will.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617115
Hello Will,

No CAS Servers we are doing an in place transition from physical Exchange Server 2010 to Virtual Exchange 2010.  

So currently our two Exchange Servers are essentially sharing a self signed cert?  

I just went through the wizard and submitted the request to Digicert.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617121
There is a pending cert request on the new server only.  Nothing under the old server except for the old self signed cert which is set to expire in June.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40617223
If you have 2 CAS servers in your environment and they are not being properly load balanced (they are dependent on each other), meaning it will be a round robin affect when clients access their mailboxes. They will reference Active Directory for a CAS server and AD shows 2 CAS servers and will send a the request to either one.

Now if you power off one of the CAS servers you you will run into issues because as stated above, they are dependent on each other. AD does not show these machines in any time of load balancing configuration so it will send requests to both CAS servers even when one is offline. This will create error messages for clients etc.

Will.
0
 
LVL 1

Author Comment

by:rjearley1966
ID: 40617272
Understood thanks.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now