Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Certificate Basics for Small business server 2011

Posted on 2016-10-17
4
Medium Priority
?
67 Views
Last Modified: 2016-11-06
HI all,

Im new to installing an actual real certificate on a server and am not sure how to go about it. I know how to actually install it, its just the topology is confusing me

I have a registered domain which lest say is abc.com
I have a mail server on hosted in my office which is using a dynamic ip. I have registered a hos name with no-ip which lets say is abc.ddns.net
The mx records for abc.com point to abc.ddns.net
Everything works fine.
In attempt to get rid of errors associated with self signed certificates i thought i would try and install a certificate, however im not sure how i order this certificate under this topology.

When i generate the request, as the SBS server is set up with the external domain of abc.com, it generates the certificate request with the common name of remote.abc.com. However users will actually connect to the server by entering abc.ddns.net. Will this cause a problem?

Any advice for this scenario welcome
0
Comment
Question by:Michael
  • 2
4 Comments
 
LVL 84

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1000 total points (awarded by participants)
ID: 41847643
yes it will generate an error as the name doesn't match the name on the certificate
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41848080
Is there a reason they can't get a static in?

My only other thought would be that go to external DNS records  and modify the A record for remote. domain. com to point to abc. does.net
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1000 total points (awarded by participants)
ID: 41848727
I have done this loads of times. Ran my own Exchange server with a dynamic IP for three years (no other choice at the time).

Using the domain that you own, create a CNAME for remote.example.com and put it on the DNS of the dynamic IP address provider (site.dyndns.com). You can do the same for Autodiscover.example.com. Not exactly best practise because it involves an additional DNS lookup, but for an SBS server it should be fine.
Then request an SSL certificate for remote.example.com in the usual way.

With SBS 2011 though, it has to be done in a certain way to work properly.
Create the certificate request through Exchange, not SBS. That way you can include remote.example.com and Autodiscover.example.com (using a UC type certificate). Then once you have received the response and completed it, use the SBS certificate wizard, choosing the option to use an existing SSL certificate.

http://exchange.sembee.info/2010/install/ssl-sbs2011.asp
0
 
LVL 84

Expert Comment

by:David Johnson, CD, MVP
ID: 41876001
Sembee's answer fixes the problem
0

Featured Post

New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this post, I will showcase the steps for how to create groups in Office 365. Office 365 groups allow for ease of flexibility and collaboration between staff members.
The Internet has made sending and receiving information online a breeze. But there is also the threat of unauthorized viewing, data tampering, and phoney messages. Surprisingly, a lot of business owners do not fully understand how to use security t…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question