Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Will SBS Self Signed SHA1 certificates work with RWW after 2017?

Posted on 2016-11-16
9
Medium Priority
?
147 Views
Last Modified: 2016-11-23
Hi,

We've inherited a few customers who occasionally use RWW or OWA and have valid SHA1 SBS self signed certificates.
They installed using the SBS generated Certificate bundle on their remote PC's.
Even though they get the warning on the URL bar, will they still be able to use Remote Web Workplace or OWA with these certs?
0
Comment
Question by:Ace-IT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41891429
What is the warning for?
0
 
LVL 1

Author Comment

by:Ace-IT
ID: 41892328
Sorry, the question is in the subject.
I'm wondering if they'll still be able to use the SBS self signed sha1 cert for RWW/Owa after Jan 2017.
0
 
LVL 35

Accepted Solution

by:
Cris Hanna earned 2000 total points
ID: 41892491
Actually starting in Feb, they will be completely blocked...but this is a really easy fix...spend 5.00/yr for a trusted single name cert using the SBS trusted cert wizard in the console
0
Introducing the WatchGuard 420 Access Point

WatchGuard's newest access point includes an 802.11ac Wave 2 chipset, providing the fastest speeds for VoIP, video and music streaming, and large data file transfers. Additionally, enjoy the benefits of strong security as the 3rd radio delivers dedicated WIPS protection!

 
LVL 1

Author Comment

by:Ace-IT
ID: 41892508
Thanks Cris.

Does this mean the Self Signed one will continue to work for the internal .local DNS and the trusted single name cert will be for a single external DNS (remote.domainname.com for example?)

The issue with this is that you need a wildcard/UCC cert to cover the Autodiscover & Remote. or Mail. sub domains, otherwise Activesync, Outlook Over RPC etc. won't work I believe?
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41892682
Someone has given you bad information about needing a UCc cert.   Only a single name cert is required.  . Local is not supposed in any certain now.
0
 
LVL 1

Author Comment

by:Ace-IT
ID: 41898414
So are you saying that only remote.contoso.com needs an ssl cert and not autodiscover.contoso.com for Outlook anywhere or RWW client to connect without ssl errors?
I know that .local internal domain names aren't used anymore but SBS 2008-11 uses this as default and a lot of them still have it.
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41898457
That's what I'm saying and it's always been true.   In fact updates were issued that remove the .local portion when doing a request for a 3rd party cert
0
 
LVL 1

Author Comment

by:Ace-IT
ID: 41900024
OK Thanks for that.
It looks like there is additional configuration for the External DNS to allow autodiscover on a single cert too:
http://www.thirdtier.net/2011/06/setting-up-autodiscover-for-sbs-2011/
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 41900027
that's correct.  Susan's original article for SBS is right here http://blogs.msmvps.com/bradley/2008/12/19/autodiscover-and-dns/
but it's quick to set up
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you need a certificate so you can offer SSL encryption.  But which one should you get?  There are so many choices out there! Here is a generic overview of the main types of SSL certificates sold by the majority of commercial Certification Auth…
The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question