Jump to content

Recommended Posts

Posted

Hi All,

 

I need to add autodiscover.domain.com as a SAN to my existing self signed exchange cert.

 

How do I do this? If I have to create a new one that's fine but some instruction would be great.

Posted

Thanks for the reply. I want to avoid having to buy a cert. Client doesn't want to spend £.

 

They currently have a self signed cert which covers mail.domain.com, remote.domain.com but not autodiscover.domain.com.

 

Now when a PC, which is not on the domain, using Outlook to connect to the exchange server they get the name mismatch error all the time because it cant find autodiscover.domain.com in the cert.

Posted
We didn't want to spend $ either, but we had the same issue and our consulting company basically told our head to stop being tight as there wasn't another way to do it!
Posted

Hi,

 

We have a wildcard certificate, but have to purchase a separate certificate for exchange because of this local entry being necessary. The Subject Alternate Name needs to be specified when creating the certificate - I know we had to but another in the end, therefore costing us extra cash which was a pain. Your preferred certificate provider should be able to sell you a certificate with a SAN included, if you search on their website.

 

Meldrew

Posted
Could I create a whole new self signed cert just for autodiscover.domain.com and use that along side the existing one? Really cant go down the road of paying for anything.
Posted
If it's not a domain machine and you're using an internally or self signed cert - you'll have to import the root certificate to each machine to get the client to trust it
Posted
how would I go about identifying the correct root cert? I have already installed the cert which presents the error. It was installed into the trusted root authority folder
Posted

Is it signed by an internal CA, or was it created by exchange? if exchange, this should work: Installing a Self-Signed Certificate as a Trusted Root CA in Windows Vista - The Windows Server Essentials and Small Business Server Blog - Site Home - TechNet Blogs

 

If it's a internal CA, you'll need to get the root cert from the certificates manager of that box.

 

I'd also say, it's easier to have a SAN with all the names in rather than separate certs for roles, as it starts getting a bit messy. That said using an internally signed cert for external clients is going to be messy anyway.

 

This is also worth a read: Exchange 2010: Autodiscover Names and SSL Certificates

Posted
We didn't want to spend $ either, but we had the same issue and our consulting company basically told our head to stop being tight as there wasn't another way to do it!

 

Worth pointing out at this point that SWGfL can do certificates via JANET. Cost is £35 for a three year certificate. I've just installed a new certificate this morning on our Exchange 2007 server. Only downside it takes about 48Hrs for the process to run but we got there in the end, SWGfL were very helpful.

 

Pete

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...