Jump to content

[SOLVED] Renew Exchange 2010 Certificate without Certificate Signing Request


Recommended Posts

Posted (edited)

Hi,

 

I'm trying to renew the digital certificate on our Exchange 2010 server as the current one is about to expire. We use GoDaddy as our CA and they have generated a new certificate which I have downloaded. I tried to follow the step-by-step instructions on their site, but have got a bit stuck.

 

Their renewal process didn't require me to create a Certificate Signing Request in Exchange. All I (or our Finance Officer as she has the school credit card) had to do was log into the GoDaddy site and click the Renew button next to our current certificate, enter the school credit card details and out popped an email with our new primary and intermediate certificates.

 

I followed the instructions to install the intermediate certificate without a problem, but to install the primary certificate it said to select the Complete Pending Request action on the Certificate Signing Request. At this point there was no CSR to complete, so I thought I could create one, then go through the Complete Pending Request action and point it towards the new certificate that I already had as the instructions indicated. This seemed to work, the Complete Pending Request accepted the certificate and said the operation completed successfully, however the status of the CSR didn't change from pending and nothing else seemed to happen. I tried it again and now it fails saying "Cannot import certificate. A certificate with the thumbprint xxxx already exists".

 

A bit of Googling suggested using certutil -repairstore My "" to fix a stuck pending request, but this hasn't helped.

 

I'm now stuck, and my knowledge of the inner workings of Exchange and certificates is somewhat limited, so can anyone suggest how I can dig myself out of this hole please?

Edited by MrLudwig
Posted
Just re-do it and arrange a re-key through the GoDaddy website its much easier and ensure it just works, you get i think its 48 or 72hrs before the current cert is nuked by them when you re-key so plenty of time. It doesn't cost anything to re-key (I've done it several times with ours when I forget / mess up / forget to make Private Key exportable etc)
  • Thanks 1
Posted
Just re-do it and arrange a re-key through the GoDaddy website its much easier and ensure it just works, you get i think its 48 or 72hrs before the current cert is nuked by them when you re-key so plenty of time. It doesn't cost anything to re-key (I've done it several times with ours when I forget / mess up / forget to make Private Key exportable etc)

 

Thanks john, you're a star. Just waiting for GoDaddy to process the re-key now.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...