googlemad Posted May 24, 2017 Posted May 24, 2017 Have just purchased a GoDaddy SSL certificate for our Exchange servers with the primary domain of owa.ourdomain.com which got all validated. However tried adding autodiscover.internalourdomain.com, cas1.internalourdomain.com and cas2.internalourdomain.com as alternative names to stop a security warning popping up in Outlook as those were on the previous self signed certificate but now GoDaddy wants to validate those by accessing a HTML page placed on the web servers, trouble is since they're internal they won't be able to! Any ideas? We do have some external services on internalourdomain.com but not Exchange!
mukz Posted May 25, 2017 Posted May 25, 2017 Iirc SAN certs no longer do internal certs. We have a CA which does the ssl for internal use.
Arthur Posted May 25, 2017 Posted May 25, 2017 Any ideas? Like you our internal domain is different from our external domain so this is what I did when it came to renewing our Exchange certificate. Created a forward lookup zone on our internal DNS for schoolname.county.sch.uk Created A records for mail, autodiscover, cas, edge within this zone that each point to the relevant Exchange server internal IPs. Renewed our SAN certificate for mail.schoolname.county.sch.uk and used the Subject Alt. Names: mail.schoolname.county.sch.uk autodiscover.schoolname.county.sch.uk cas.schoolname.county.sch.uk edge.schoolname.county.sch.uk Because all of the Alt. Names are using the same (external) domain I only had to verify schoolname.county.sch.uk. The only A records in our external DNS are mail and autodiscover.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now