Avatar of D_wathi
D_wathi
Flag for India asked on

ssl certificate for exchange server

Dear Experts
We are in process of implementing on-premise exchange enterprise email server for this we have install SSL certificate, please suggest which provider and what type of ssl certificate should we have to go for exchange enterprise email server. thanks in advance.
ExchangeEmail ServersSSL / HTTPSWindows Networking

Avatar of undefined
Last Comment
M A

8/22/2022 - Mon
M A

You need a SAN certificate (i.e. multi domain certificate).
And you need two names minimum. Common name and autodiscover.email.com.
Assuming you have only 1 email domain.
Please check this for more details.
https://www.experts-exchange.com/articles/31221/Fix-for-Exchange-server-2016-2019-certificate-and-related-issues.html
https://www.experts-exchange.com/articles/29662/Exchange-2013-Fix-for-an-Invalid-certificate-and-related-issues.html

You can buy any 3rd party certificate.
Digicert which is expensive
Godaddy, Comodo. which is cheap.
Seth Simmons

And you need two names minimum

or get a wildcard certificate which you can use on all your servers in that domain
D_wathi

ASKER
Thank you very much following help requested
1) email domain    orange.com

think common name :  mail.orange.com    
auto discover name: autodiscover.orange.com

please correct if the above common name and autodiscover name found to be correct if not request to please correct

2) email domain  apple.com
common name: mail.apple.com
auto discover name: autodiscover.apple.com
please correct if the above common name and autodiscover name found to be correct if not request to please correct

3) domain jackfruit.com  for this multiple subdomains are there
email domain: mail.jackfruit.com
common name: mail.jackfruit.com
auto discover: autodiscover.jackfruit.com

Please note all the above 03 emails domains to be configured in the same exchange server where it is in the domain network of jackfruit.com
if this is the case should we have to go for one SAN certificate that is for above  1 and 2 and for 03 go for wildcard and if we go for wildcard, please help.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
ASKER CERTIFIED SOLUTION
M A

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
D_wathi

ASKER
Thanks for suggestion, all the email domains will be on one single exchange server and above option 2 which is as following is what I have planned and going for multidomain (SAN) certificate
Single common name for all domains and add autodiscover for those domains.
1. mail.orange.com  
2. autodiscover.orange.com
3. autodiscover.apple.com
4. autodiscover.jackfruit.com
hope this works fine, please let me know.
M A

-->hope this works fine, please let me know.
Yes this is correct.