Avatar of Gonthax
Gonthax
 asked on

Exchange 2010: How to set up certificates for OWA/Autodiscover, and TLS between SMTP servers, and Edge Subscription?

Hi there. We have a two server Exchange 2010 set up: One internal server that is the Client Access and Hub Transport and an external server that is our Edge.

We have an SSL certificate from a public CA we want to present when users log in to OWA/Autodiscover/etc. We would also like to have TLS connections using an SSL cert between external SMTP servers and of course, a cert is needed to handle the Edge subscription between Edge and the Hub.

When trying to use the same certificate for these use cases, Exchange will throw an error saying: "Sharing the same certificate between Edge and Hub Transport servers is not allowed."

What's not clear from searching around is what the best practice is here: Use a public CA cert for OWA/Autodiscover/etc., and use a self-signed for SMTP/TLS? Wouldn't it be advantageous to use a public CA cert for SMTP connections between external SMTP servers? Should we buy two certs then for this case?

Thanks in advance!
Exchange

Avatar of undefined
Last Comment
Gonthax

8/22/2022 - Mon
viktor grant

Hi,

You receive this error when you try to create the Edge Susbcription ( "Sharing the same certificate between Edge and Hub Transport servers is not allowed.") ?

Cheers
Gonthax

ASKER
Hi Viktor,

Yes, that's correct. Thanks!
ASKER CERTIFIED SOLUTION
viktor grant

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Gonthax

ASKER
Thanks, Viktor - self-signed certificates are OK for communication between external SMTP servers (meaning our server connecting to a foreign SMTP server)? They're implicitly trusted? Thanks!
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
viktor grant

Hi,

Exactly! Perfect that the issue is solved
Gonthax

ASKER
Thank you Viktor for your help - I'm surprised self-signed certificates are ok for such use, but it seems to work. Cheers!