Exchange 2010 certificate issues

vbcosupport
vbcosupport used Ask the Experts™
on
Noob Exchange Admin here.
Running Exchange 2010 SP3 and have an annoying certificate message poping up when you launch Outlook or access via OWA.
"Name on the security certificate is invalid or does not match the name of the site". Users click Proceed and all is well.
There are 2 certificates on this server. One is a Verisign cert with the name webmail.mydomain.com the other is an exchange certificate with the name ExchangeSrv. All services (IMAP,POP,IIS,SMTP) are assigned to the ExchangeSrv certificate.
Under Server Config in the Client Access group, OWA has internal and external URLs of https://webmail.mydomain.com/owa.
In the Exchange Control Panel config, I have an internal URL of https://exchangesrv.mydomain.com/ecp but the external URL is https://mail.mydomain.com/ecp.
My question is, can i move all the services to the Verisign webmail cert and remove the exchange without killing everyone's connection to the exchange server?
Also, would I need to change the ECP Urls to be webmail.mydomain.com?

About to migrate to Exchange 2016 standalone and want to make sure all my certs are properly configured before I start the migration.

Thanks for you input.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
IvanSystem Engineer
Commented:
Hi,

you can migrate all services to webmail.mydomain.com. What you should do is reconfigure all required services to point (to use) new address, and then assigne VeriSign certificate to those services.
What I usually do, is I use public name, such as webmail.mydomain.com  for both internal and external access. You would need to configure internal DNS zone of mydomain.com  so that you could use those names internally.

To reconfigure URL: Log into EMC --> Servers --> Virtual Directories --> select and edit service
Important: After reconfiguration of OutlookAnywhere and URL --> iisreset

PS: I always leave that self signed cert, never remove it :)
PPS: ECP and OWA should use same address.

Regards,
Ivan.
EE Solution Guide - Technical Dept Head
Most Valuable Expert 2017
Commented:
Please check this article which will help you to do this
http://www.experts-exchange.com/articles/13676/Out-Of-office-not-working.html

Author

Commented:
Thanks guys!! Scheduling downtime to do this.
MASEE Solution Guide - Technical Dept Head
Most Valuable Expert 2017

Commented:
FYI no down time required to do this.

Author

Commented:
Thanks all. Worked like a champ.
Now on to migrating to 2016.....

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial