ZFarnworth_geek Posted August 28, 2021 Posted August 28, 2021 [emoji51] I’m deploying exchange 2013 next week, so best get a backup and Antivirus to be safe…
3s-gtech Posted August 28, 2021 Posted August 28, 2021 [emoji51] I’m deploying exchange 2013 next week, so best get a backup and Antivirus to be safe… Any reason for not using 2016?
ZFarnworth_geek Posted August 28, 2021 Author Posted August 28, 2021 Hello all. Hope you are all staying safe. Over the next 2 weeks I will be deploying exchange 2013 (I know I shouldn’t be using it but love 2013 version) anywho, I’m using cloud flare just so I can get a free wildcard and I wanted to double check if I can do this with the csr request when I create it in the EAC and I just wanted to check if it would work. Thanks, Zak Appreciate any advice
FN-GM Posted August 29, 2021 Posted August 29, 2021 [emoji51] I’m deploying exchange 2013 next week, so best get a backup and Antivirus to be safe… I’m curious as to why you’re going Exchange and not Office 365?
elsiegee40 Posted August 29, 2021 Posted August 29, 2021 (edited) Sorry to be blunt, but don’t do it. Exchange 2013 went into extended support in 2018. All support ends April 2023. Extended support is there to give sites more time to move away. It’s not intended to allow new installs. “I love it” is no excuse for using a product that is on borrowed time. With all the ransomware attacks and other security risks now, it’s hard to find an excuse not to use the most up to date versions of operating systems and software. And these days, I would also question your decision not to get stuff on the cloud… eg Office 365. Edited August 29, 2021 by elsiegee40 4
3s-gtech Posted August 29, 2021 Posted August 29, 2021 I’m curious as to why you’re going Exchange and not Office 365? I’ve been an Exchange hold-out for years, but even I migrated to Exchange Online this summer. Keeping a server on-site for Hybrid is one thing, but I wouldn’t put a fresh install in.
Arthur Posted August 29, 2021 Posted August 29, 2021 I’m curious as to why you’re going Exchange and not Office 365? More details here... www.edugeek.net/forums/windows-server-2012/223506-exchange-2013-cloudflare-wildcard-ssl.html#post1914935 Based on the forum the thread is in, I am assuming ZFarnworth_geek is also installing Exchange 2013 on Windows Server 2012 R2 which is unsupported from 10 October 2023.
elsiegee40 Posted August 29, 2021 Posted August 29, 2021 Being kinder, EduGeek is here to help if lack of training or knowledge is hampering an attempt to do anything. We cannot all be experts in everything and there are many who have had their hands held over upgrades and moves to cloud.
3s-gtech Posted August 29, 2021 Posted August 29, 2021 I had to get a particular Exchange cert when I last renewed. A wildcard *should* work but I followed advice to get certs which covered the autodiscover and mail delivery, as well as the IIS part. What a faff it all is!
ZFarnworth_geek Posted August 29, 2021 Author Posted August 29, 2021 (edited) Sorry to be blunt, but don’t do it. Exchange 2013 went into extended support in 2018. All support ends April 2023. Extended support is there to give sites more time to move away. It’s not intended to allow new installs. “I love it” is no excuse for using a product that is on borrowed time. With all the ransomware attacks and other security risks now, it’s hard to find an excuse not to use the most up to date versions of operating systems and software. And these days, I would also question your decision not to get stuff on the cloud… eg Office 365. Yep, completely right again, I just love exchange server and the faff it is to get an email to deliver [emoji23] but if I’m going to do anything next it would be adfs because it’s a challenge that I would like to at least get working for my office 365 clients as everyone has made me think [emoji189] it’s best to move to the cloud these days with remote working and ease of access. Edited August 29, 2021 by elsiegee40
Norphy Posted August 29, 2021 Posted August 29, 2021 Even ADFS isn’t worth the faff these days. You can use Azure AD Connect to handle transparent authentication for Office 365 stuff and use Azure AD to handle federation for external services. The less stuff you have exposed to the Internet on your local network, the better. 2
HPlum78 Posted August 29, 2021 Posted August 29, 2021 (edited) Never mind that Exchange 13 is in extended support the supported OS (2012) went extended support this july from memory! So add that to the list of reasons not to do this... Oh and then net framework the list continues. @elsiegee40 is right Its just not smart no matter how much you love something (hell 1/2 of us on here would still be running DOS if it where about the love of it!) @Norphy is also bang on with ADFS again spend the faff getting federated access done via cloud based offering that and your mail service. As one great man said "well that will just about cover the flbys" Edited August 29, 2021 by elsiegee40 1
elsiegee40 Posted August 29, 2021 Posted August 29, 2021 (edited) Yep, completely right again, I just love exchange server and the faff it is to get an email to deliver [emoji23] but if I’m going to do anything next it would be adfs because it’s a challenge that I would like to at least get working for my office 365 clients as everyone has made me think [emoji189] it’s best to move to the cloud these days with remote working and ease of access. You seem to be talking about what you like and what is a challenge to you like it’s just for your entertainment. This is just not the mindset you need. The challenge for anyone setting up this kind of thing needs to have data and network security first and foremost. Leave playing with things you want to have a go at for your own home setup. Your employer’s network is not the place for anything other than a professional no-nonsense approach. All software and operating systems on extended support need to go asap no matter how much you like them. If your network were to be compromised and a review was done, how would you look if your choice of installations had not been done in the interests of security? It would be pretty damning if the report was that everything was outdated due to the NM/IT tech. Edited August 29, 2021 by elsiegee40 4
ZFarnworth_geek Posted August 29, 2021 Author Posted August 29, 2021 I’ll be completely honest with you guys, I’ve been really trying now to get my sh**t together. Your guys comments have really shown me what I need to sort out and I thank you all for that. I have made the decision to stay on office 365 as I realise it’s the best option for me and my clients. I have chosen to go with adfs as it is something I would like to have setup for my network and my clients. I’ve been using okta free for office 365 because that’s all I have and use for productivity I guess you could say. and for anyone who is wanting a free federation service which makes life easier for you and I would really recommend it. But I would really really like to deploy adfs because it would be an achievement to me and something I would like to have for long term and for my helpdesk. I have got firewall setup and ready to go. I meant to say that in the second reply I did earlier. But I have also realised from all of your comments that since covid everyone has been moving to remote working and simpler solutions cloud is the way and I got bored of the cloud and how easy things are now as I think that company’s are moving to office 365 and google and we might not all like that but sometimes we’ve got to do what’s best for the company or school. And I will be upgrading all of my servers to 2019 or 2016 if the specs can handle it. And ssd upgrades for all [emoji16] But I would like to thank you all for your comments you all have really opened my eyes. Thanks, Zak Stay safe
ZFarnworth_geek Posted August 29, 2021 Author Posted August 29, 2021 You seem to be talking about what you like and what is a challenge to you like it’s just for your entertainment. This is just not the mindset you need. The challenge for anyone setting up this kind of thing needs to have data and network security first and foremost. Leave playing with things you want to have a go at for your own home setup. Your employer’s network is not the place for anything other than a professional no-nonsense approach. All software and operating systems on extended support need to go asap no matter how much you like them. If your network were to be compromised and a review was done, how would you look if your choice of installations had not been done in the interests of security? It would be pretty damning if the report was that everything was outdated due to the NM/IT tech. Completely right and getting everything updated is a priority for me over the next 2 weeks whilst I’ve got time because yes if my network gets compromised I’ll be shi**ting all night long. So that is my no.1 priority right now. Thanks Stay safe [emoji4]
ZFarnworth_geek Posted August 29, 2021 Author Posted August 29, 2021 I’m curious as to why you’re going Exchange and not Office 365? I’ll be completely honest with you, I prefer the layout and design of exchange 2013 and there is more features I guess more control
elsiegee40 Posted August 30, 2021 Posted August 30, 2021 Posts from the Skinners thread merged into this one to avoid duplicate conversation. http://www.edugeek.net/forums/security/222398-skinners-kent-schools-closed-after-data-breach.html 1
Popular Post elsiegee40 Posted August 30, 2021 Popular Post Posted August 30, 2021 (edited) Completely right and getting everything updated is a priority for me over the next 2 weeks whilst I’ve got time because yes if my network gets compromised I’ll be shi**ting all night long. So that is my no.1 priority right now. Thanks [emoji4] Stay safe [emoji4] I’ll be completely honest with you guys, I’ve been really trying now to get my sh**t together. Your guys comments have really shown me what I need to sort out and I thank you all for that. I have made the decision to stay on office 365 as I realise it’s the best option for me and my clients. I have chosen to go with adfs as it is something I would like to have setup for my network and my clients. I’ve been using okta free for office 365 because that’s all I have and use for productivity I guess you could say. and for anyone who is wanting a free federation service which makes life easier for you and I would really recommend it. But I would really really like to deploy adfs because it would be an achievement to me and something I would like to have for long term and for my helpdesk. I have got firewall setup and ready to go. I meant to say that in the second reply I did earlier. But I have also realised from all of your comments that since covid everyone has been moving to remote working and simpler solutions cloud is the way and I got bored of the cloud and how easy things are now as I think that company’s are moving to office 365 and google and we might not all like that but sometimes we’ve got to do what’s best for the company or school. And I will be upgrading all of my servers to 2019 or 2016 if the specs can handle it. And ssd upgrades for all [emoji16] But I would like to thank you all for your comments you all have really opened my eyes. Thanks, Zak Stay safe Good because quite frankly what you have been saying about the need to upgrade and implementing firewalls (seriously?!) terrifies me. You have clients. This is your business. You are working in schools spending tax-payers money. If a school’s data is encrypted it cannot admit pupils onsite until they get at least their MIS basic data back (see the Skinners thread). That’s days of education lost by kids who have already lost a lot due to covid. In secondaries there’s exam work that could be destroyed along with a child’s future. If there’s a data protection breach the fines are potentially massive… and you could be held liable. For a business they could lose their ability to trade and to pay you. Death of a sole trader is no excuse for a delay in submitting VAT records, as we found out when my dad died, and I doubt HMRC will consider encryption any more sympathetically. Please read the Skinners thread in detail … and others in the Security forum… and if you’re out of your depth then admit it and others on here will be able to help you implement what is necessary. Edited August 30, 2021 by elsiegee40 5
CrootUK Posted September 2, 2021 Posted September 2, 2021 Couldn't agree more, I almost thought he was being sarcastic.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now