Link to home
Start Free TrialLog in
Avatar of sara2000
sara2000

asked on

S/MIME and certificate

New to Exchange2010 .Have a question regarding the encryption.
We have EXchange2010 and the CAS server and it has ssl SAN installed.
If we want to enable S/MIME at end users outlook.
Do we have to install third-rate trusted certificate?
or
We will be ok with internal CA and install the certificate to users via AD?
Avatar of Carol Chisholm
Carol Chisholm
Flag of Switzerland image

SAN for connection encryption and S/MIME are two different things.
However in general you now should always go with a third party certificate from a reliable provider.

Self signed certificates really are not a good idea unless you have a fully published PKI, and if you had that you would not be asking the question.

https://technet.microsoft.com/en-us/library/bb738140(v=exchg.141).aspx

https://social.technet.microsoft.com/Forums/en-US/b8440ebc-4a86-4ff7-be22-1277a8a06a05/smime?forum=exchange2010
Avatar of sara2000
sara2000

ASKER

Carol,
Thank you for your reply.
I am having problem of understanding this ssl and S/Mime.
Hope you will put me in the correct direction.
i noticed that one SAN certificate has been installed on all four CAS servers(may be export or copy)
When you say third party from a trusted source, Say for an example we have 100 outlook clients.
we able to install one certificate at all 100 users computers like the CAS servers?
ASKER CERTIFIED SOLUTION
Avatar of Carol Chisholm
Carol Chisholm
Flag of Switzerland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial