Solved

Certificate Basics for Small business server 2011

Posted on 2016-10-17
4
47 Views
Last Modified: 2016-11-06
HI all,

Im new to installing an actual real certificate on a server and am not sure how to go about it. I know how to actually install it, its just the topology is confusing me

I have a registered domain which lest say is abc.com
I have a mail server on hosted in my office which is using a dynamic ip. I have registered a hos name with no-ip which lets say is abc.ddns.net
The mx records for abc.com point to abc.ddns.net
Everything works fine.
In attempt to get rid of errors associated with self signed certificates i thought i would try and install a certificate, however im not sure how i order this certificate under this topology.

When i generate the request, as the SBS server is set up with the external domain of abc.com, it generates the certificate request with the common name of remote.abc.com. However users will actually connect to the server by entering abc.ddns.net. Will this cause a problem?

Any advice for this scenario welcome
0
Comment
Question by:Michael
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 81

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points (awarded by participants)
ID: 41847643
yes it will generate an error as the name doesn't match the name on the certificate
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41848080
Is there a reason they can't get a static in?

My only other thought would be that go to external DNS records  and modify the A record for remote. domain. com to point to abc. does.net
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 250 total points (awarded by participants)
ID: 41848727
I have done this loads of times. Ran my own Exchange server with a dynamic IP for three years (no other choice at the time).

Using the domain that you own, create a CNAME for remote.example.com and put it on the DNS of the dynamic IP address provider (site.dyndns.com). You can do the same for Autodiscover.example.com. Not exactly best practise because it involves an additional DNS lookup, but for an SBS server it should be fine.
Then request an SSL certificate for remote.example.com in the usual way.

With SBS 2011 though, it has to be done in a certain way to work properly.
Create the certificate request through Exchange, not SBS. That way you can include remote.example.com and Autodiscover.example.com (using a UC type certificate). Then once you have received the response and completed it, use the SBS certificate wizard, choosing the option to use an existing SSL certificate.

http://exchange.sembee.info/2010/install/ssl-sbs2011.asp
0
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 41876001
Sembee's answer fixes the problem
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question