file · web viewprovide the certificate path to import in exchange server which has been...

25
This document contains the following: Creating New Exchange certificate using Exchange management console and generating CSR to internal Domain controller to get SAN Certificate Installing pre-requisites for CA Server. Installing the CA Server to get SAN certificate. Submitting the Exchange 2010 CSR to get SAN certificate. Installing SAN certificate to Exchange 2010 Trusted root. Complete the pending Exchange certificate using Exchange management console. (Importing Certificate) Enable exchange 2010 client services on SAN certificate.

Upload: tranxuyen

Post on 06-Mar-2018

220 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

This document contains the following:

Creating New Exchange certificate using Exchange management console and generating CSR to internal Domain controller to get SAN Certificate

Installing pre-requisites for CA Server. Installing the CA Server to get SAN certificate. Submitting the Exchange 2010 CSR to get SAN certificate. Installing SAN certificate to Exchange 2010 Trusted root. Complete the pending Exchange certificate using Exchange

management console. (Importing Certificate) Enable exchange 2010 client services on SAN certificate.

Page 2: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Click on New Exchange Certificate from Server Configuration action console

Uncheck enable wildcard certificate and click on next

Page 3: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Enter the external FQDN which is registered which will be used for OWA

Enter the external FQDN which is registered which will be used for ActiveSync

Page 4: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Enter the external FQDN which is registered which will be used for Auto discover

Enter the external FQDN which is registered which will be used for Exchange 2003/2007

Page 5: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Verify the FQDN and click on next

Enter the Org. details and give the path to save CSR, Click on next

Page 6: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Verify the completion and observed the commands which is used via poweshell at backend.

Page 7: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Select IIS for Cert Server virtual directory

Click on certificate services and you will be prompted a popup for warning

Click on yes for warning message.

Page 8: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Select enterprise root CA and click on next

Give the common as desired and click on next

Page 9: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Leave the default settings and click on next

Observe the progress

Page 10: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Observe the progress

Click on finish to complete

Page 11: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Verify the virtual directory is created on CA server.

Run the above command to enable SAN certificate generate support for Windows 2003 CA server.

Page 12: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Login to CA server and browse local host giving the virtual directory path and select request a certificate.

Select advanced certificate

Page 13: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Select 2nd option

Open the Exchange CSR into text file and copy it to saved request

Page 14: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Copy and paste the Exchange, select webserver on certificate template and click on submit

Page 15: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Select base 64 encoded and click on download certificate chain

Save it to Exchange computer to complete the pending request/Import which was generated from Exchange Server.

Page 16: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Import the certificate 1st into Exchange computer trusted root zone.

Via EMC – Server configuration – right click the newly created exchange cert and select complete pending request.

Page 17: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Provide the certificate path to import in exchange server which has been generated from root CA

Page 18: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Verify the path and click on complete the pending request.

Verify the completion and click on finish

Page 19: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Make sure there is no error on the certificate console

Assign exchange client services to certificate

Page 20: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Select the server on which to assign the services.

Select Imap, POP & IIS and click on next

Page 21: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

.

Verify the command and click on assign

Verify and click on finish to complete

Page 22: file · Web viewProvide the certificate path to import in exchange server which has been generated from root CA. Verify the path and click on complete the pending request

Verify the exchange client services are assigned to the SAN certificate.

Run the above command to get the Exchange Server certificate status.

Thank You!

Hope that’s been informative to you!