Jump to content

Recommended Posts

Posted
If you've got an AD then why not set up your own CA and issue from there - saves a whole lot of problems, especially if (like me) you keep issuing the certificate for the wrong domain name/purpose - quite trickey with Exch 2010 & I presume 2007 is the same.
Posted

I did / had no issues with own CA, however with all this snow, suddenly everyones using owa - and people want it fixing now even tho i've explained how to click past the cert error.

I did use digicert to create the CSR and i'm currently waiting on ipsca now. Bit concerned as to wether its a ucc tho ?

 

this seems a good straightforward document for certs Sembee | Exchange 2007 and SSL Certificates - Take 2

Posted
But then this causes problems with OWA as it's not a trusted certificate

 

On Domain computers you can use a GPO to install the CA certificate (i.e. your own CA) in their Trusted store, then all issued certifcates will automatically be trusted. For non-domain computers, if you're in a school I don't see why you can't tell your users either to ignore the OWA certificate's 'not-trusted' pop-up or else to add the cert to their trusted store manually. Works nicely for us. (edit: ah, just read your last post - maybe your users are too thick for this!)

Posted

they see big warning signs and run away - not a bad attitude i admit, but they should read and see what it says first.

 

well got the certificate from ipsca now time to break things i guess ;p

Posted

well installed, and with a bit of messing got it to work (cert errors in outlook internally but was easy enough to fix), thanks for the link

 

cert doesnt seem to be trusted in firefox tho ?

Posted

I know you shouldn't knock a free.. but IPSCA was a bit of a pain for OWA last time I went near one. You need to make sure you have reasonably current MS cert updates on Windows OS's which isn't very predictable for home PCs, you also need to install and serve up the intermediate certs on the Exchange server etc. May well be fixable because I spent very little time on it, but I gave up on trying to figure out how to make Firefox happy.

 

All-in-all it wasn't obvious that this was easier than using your own CA, and then giving your users the CA cer file to install on any non-domain machines. OWA is not a general public web service after all, the user's are your own and can be told that if they want the warnings gone strongly enough then all they need to do is...

Posted

I've since done a bit of reading about IPSCA and it seems they are only really supported by Microsoft.

I've tried our owa in osx, linux and windows (xp and 7) and found it only works on windows with chrome or IE (7,8,9) (not firefox) so not that much better than a self cert :(

shame really might have to consider getting a multi domain from godaddy or similar, that or plead ignorance and say our IT dept. only supports windows and microsoft browsers ;p

 

BTW I tried using 123-reg but their support is terrible, I just couldn't get the CSRs to work on their site and the delay in responding to questions was horrendous!

Posted

We use ipSCA for our certificates and all work well with our Exchange OWA, VLE and for remote access.

 

The only browser complaining at the moment about them is Firefox, why its taken so long I don't know. I did look on the bug/request list for Firefox and apparently the developers have asked for more info from ipSCA but have not recieved it for some reason. I've already had one parent querying the certificate while their child accessed our VLE but I wrote a short e-mail explaining the situation.

 

Saves a bit of money for the school, I know certs are cheaper these days but a saving is a saving.

 

As mentioned you don't need a .edu domain, I got ours for our .sch.uk domain but the education certificates are manually checked (takes a bit longer) but work fine.

 

Pete

Posted

Just looking at the ipsca site and on the request page there is a dropdown for server types. What should I choose for a certificate to work with Exchange 2010? Is it Microsoft IIS 7.x or Exchange?

 

Thanks.

Posted
I totally recommend the digicert exchange certificates . They make the process easy, I don't think its expensive and it's money well spent in any case; certificate problems in exchange will erode your sanity. They also have a decent write up on the whole exchange and certificates thing here where they point out the alternative (wildcard certs).
Posted
All down to budget really, ours is quite small. Personally i think its ridiculous to be expected to pay for a cert after installing exchange - but thats just me I guess :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...