Friday, March 6, 2015

certificates

Exchange uses self-signed certs by default.  not appropriate for production environment.








Configuring a domain to uise a CA SAN/UCC certificate form GoDaddy

1. use the Exchange Certificate Wizard to obtain a Certificate Signing Request (CSR)

2. use the CSR to complete the GoDaddy certificate process

3. download the certificate and complete the pending certificate wizard

4. assign the IIS service to the new certificate and demonstrate that it works



Error when using self signed certificates





Create a CSR



Pending state of the certificate




Certificate request text file (CRF)



paste into domain register's request form

Make sure common name is correct



intermediate and root certification



Now, in exchange Admin center you can complete the certificate request
point UNC path to new certificate

Now certificate is considered valid CA signed certificate

assign services to certificate




if there are other exchange servers needing the certificate, you can import and export it


No comments:

Post a Comment