Solved

cannot create certificate for EXCH2013 migration

Posted on 2016-10-17
21
54 Views
Last Modified: 2016-10-18
Hello,
I want to migrate from EXCH2007 to 2013.
Now I want to build up the coexistence.
I have created a cert request on the new EXCH2013 server.

From the documentation, I have created this request :

New-ExchangeCertificate -FriendlyName 'Contoso Exchange 15 Certificate' -GenerateRequest -PrivateKeyExportable $true -KeySize '2048' -SubjectName 'C=EG,S="Cairo",L="Cairo",O="Contoso",OU="IT",CN=mail.contoso.com' -DomainName 'mail.contoso.com','autodiscover.contoso.com' ,'legacy.contoso.com','autodiscover.domain.com','mail.domain.com','mobile.externaldomain.com' | out-file c:\sw\e15_csr.txt

Open in new window



But I cannot read this with my Windows 2008 CA.
Do you have any ideas ?
0
Comment
Question by:Eprs_Admin
  • 11
  • 8
  • 2
21 Comments
 
LVL 49

Expert Comment

by:Akhater
ID: 41846669
0
 

Author Comment

by:Eprs_Admin
ID: 41846709
I entered the same command on my old HUBCAS 2007.
Here I had to shorten the subjectname.
I have got a CSR file with this one I was able to create an certificate.

But with a CSR from EXCH2013 server it is impossible. Why ?
0
 
LVL 25

Assisted Solution

by:-MAS
-MAS earned 250 total points
ID: 41846724
Hi,
Please post the error.

Please try to create a CSR using this.
https://www.experts-exchange.com/articles/28662/Easy-CSR-creation-Exchange-2007-2010-and-2013.html
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 

Author Comment

by:Eprs_Admin
ID: 41846733
Hi MAS,

now I have created the CSR on my HUBCAS2007.
Is it a problem ?

Because on the EXCH2013 I can create the CSR, but I cannot use the CSR with my CA.
Remember my CA is on WIN2008.
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41846745
no problem you can't use the CSR of 2007
0
 

Author Comment

by:Eprs_Admin
ID: 41846747
And I have another question to your solution:

About this command:
Enable-ExchangeCertificate -Thumbprint A826389C71ED5870137B866F01192D47F69CE526 -Services IIS,POP,IMAP

Open in new window

Why SMTP is not enabled here ?
On my old EXCH2007 the active certificate has all enabled.
Can you tell me why ?
0
 
LVL 49

Assisted Solution

by:Akhater
Akhater earned 250 total points
ID: 41846748
you do not need to worry about SMTP needs to use internal certificate anyway
0
 

Author Comment

by:Eprs_Admin
ID: 41846818
Now I want to enable the cert but again with error:

It is not possible on the EXCH2013 Powershell.
When I do it on the  EXCH2007 Powershell all works and I can export the cert with the key.

Why is it like this ?
Has it to do with my old ROOT CA ? WIN2008
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41846826
Can you please share the error? What do you mean not possible?

Did you export the certificate with private key from 2007 and installed it on 2013?
0
 
LVL 25

Assisted Solution

by:-MAS
-MAS earned 250 total points
ID: 41846827
0
 

Author Comment

by:Eprs_Admin
ID: 41846882
Did you export the certificate with private key from 2007 and installed it on 2013?
YES !
Is it a problem ?
0
 
LVL 49

Assisted Solution

by:Akhater
Akhater earned 250 total points
ID: 41846883
Not at all this is what you need to do...

What is the error?
0
 

Author Comment

by:Eprs_Admin
ID: 41846903
I cannot send the error now.

I have created the CSR on EXCH2013.
I have exported the CSR and imported to my CA. This always failed, no download option came up.
There was no error.
When I tried to request a CERT from CA (GUI) then an error came up WIN32: 13
Sorry I cannot tell you more about it.
0
 

Author Comment

by:Eprs_Admin
ID: 41846909
ok, so I can import the CERT on all old HUBCAS and on all new EXCH2013 servers right ?
0
 
LVL 49

Accepted Solution

by:
Akhater earned 250 total points
ID: 41846913
yes with private key
0
 

Author Comment

by:Eprs_Admin
ID: 41846917
ok thanks, will do and proceed with the migration.
0
 

Author Comment

by:Eprs_Admin
ID: 41847807
about this command:

.\setup /m:Install /Roles:ca,mb,mt /IAcceptExchangeServerLicenseTerms /InstallWindowsComponents /DBFilePath:"C:\DB01\DB01.edb" /LogFolderPath:"C:\DB01\Logs" /MdbName:"DB01"

Open in new window


I haven't installed like this, I used the GUI.
There is no DB created. Can I do this manually at every time ?
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41847817
wrong question ??
1
 

Author Comment

by:Eprs_Admin
ID: 41847826
another ticket ?
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41847830
yes please let's keep this question relevant :)

If it was answered kindly close it

ربنا يخليك
0
 

Author Closing Comment

by:Eprs_Admin
ID: 41847831
I could generate the CSR and the CERTs.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question