Link to home
Start Free TrialLog in
Avatar of vmich
vmichFlag for United States of America

asked on

Certificate for exchange 2010 server question

We currenlty have a certificate that is getting ready to expire. Our domain name is in this format:
domain
So since the .local is not allowed any longer in the certificate, I found a link on how to change the exchange autodiscover, etc items that need to be changed to the internal urls to be the same as the external urls.
Our cert now has the 2 exch server names in it like this:
server1.domain
server2.domain
Do I even need to have these as part of my certificate since I have to remove them because of the .local
ASKER CERTIFIED SOLUTION
Avatar of Seth Simmons
Seth Simmons
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of vmich

ASKER

We have the split dns setup because I can ping the external url from inside and it responds to the exchange server and also if I ping the external url from the outsdie, it responds to th external ip of the exchange server.
But as i mentioned the domain name is domain
So that is a .local which the cert has the 2 exchn servers in it which are server1.domain and server2.domain
So do I need these in the exchange cert?
You cannot put a raw domain (ie one without a suffix) on the SSL certificate. That simply isn't allowed.

In simple terms, all names on the SSL certificate MUST resolve on the internet. host.domain would not resolve, so wouldn't be allowed.

Simon.
Avatar of vmich

ASKER

Simon,
My question is will it be an issue if I leave off the 2 servers names.domain since there domain name now is still a .local domain name since the certificate companies dont allow the .local names on the certs?
Meaning will it affect exchange at all?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of vmich

ASKER

Yes I will be changing all of the internal urls to match the external urls and all of the virtual directories...
Avatar of vmich

ASKER

new cert