Mr_M_Cox Posted January 20, 2014 Posted January 20, 2014 Hi All, I need to add autodiscover.domain.com as a SAN to my existing self signed exchange cert. How do I do this? If I have to create a new one that's fine but some instruction would be great.
Oaktech Posted January 20, 2014 Posted January 20, 2014 This may be of no help at all, but we just bought a *.domain.com wildcard certificate from godaddy.com to cover all bases...
Mr_M_Cox Posted January 20, 2014 Author Posted January 20, 2014 Thanks for the reply. I want to avoid having to buy a cert. Client doesn't want to spend £. They currently have a self signed cert which covers mail.domain.com, remote.domain.com but not autodiscover.domain.com. Now when a PC, which is not on the domain, using Outlook to connect to the exchange server they get the name mismatch error all the time because it cant find autodiscover.domain.com in the cert.
Oaktech Posted January 20, 2014 Posted January 20, 2014 We didn't want to spend $ either, but we had the same issue and our consulting company basically told our head to stop being tight as there wasn't another way to do it!
Meldrew Posted January 20, 2014 Posted January 20, 2014 Hi, We have a wildcard certificate, but have to purchase a separate certificate for exchange because of this local entry being necessary. The Subject Alternate Name needs to be specified when creating the certificate - I know we had to but another in the end, therefore costing us extra cash which was a pain. Your preferred certificate provider should be able to sell you a certificate with a SAN included, if you search on their website. Meldrew
Mr_M_Cox Posted January 20, 2014 Author Posted January 20, 2014 Could I create a whole new self signed cert just for autodiscover.domain.com and use that along side the existing one? Really cant go down the road of paying for anything.
Domino Posted January 20, 2014 Posted January 20, 2014 If it's not a domain machine and you're using an internally or self signed cert - you'll have to import the root certificate to each machine to get the client to trust it
Mr_M_Cox Posted January 20, 2014 Author Posted January 20, 2014 how would I go about identifying the correct root cert? I have already installed the cert which presents the error. It was installed into the trusted root authority folder
Domino Posted January 20, 2014 Posted January 20, 2014 Is it signed by an internal CA, or was it created by exchange? if exchange, this should work: Installing a Self-Signed Certificate as a Trusted Root CA in Windows Vista - The Windows Server Essentials and Small Business Server Blog - Site Home - TechNet Blogs If it's a internal CA, you'll need to get the root cert from the certificates manager of that box. I'd also say, it's easier to have a SAN with all the names in rather than separate certs for roles, as it starts getting a bit messy. That said using an internally signed cert for external clients is going to be messy anyway. This is also worth a read: Exchange 2010: Autodiscover Names and SSL Certificates
FragglePete Posted January 20, 2014 Posted January 20, 2014 We didn't want to spend $ either, but we had the same issue and our consulting company basically told our head to stop being tight as there wasn't another way to do it! Worth pointing out at this point that SWGfL can do certificates via JANET. Cost is £35 for a three year certificate. I've just installed a new certificate this morning on our Exchange 2007 server. Only downside it takes about 48Hrs for the process to run but we got there in the end, SWGfL were very helpful. Pete
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now