SSL SAN Certificate
I am in the process of getting a UCC/SAN SSL certificate (from GoDaddy) for my Exchange 2007 server. Before I did, I wanted to make sure I had all the names I needed. I am a little different because we have 3 different external domains here that have to be separate. Do I really need to register all of these names?- mail.externaldomain1.com- mail.externaldomain2.com- mail.externaldomain3.com- externaldomain1.com- externaldomain2.com- externaldomain3.com- autodiscover.externaldomain1.com- autodiscover.externaldomain2.com- autodiscover.externaldomain3.com- internaldomain.local- servername.internaldomain.localAlso, what happens if we need to add a fourth domain or change the one of the domain names? Any forseeable problemswhen changing the SAN, revoking the old UCC certificate and reinstalling the new one?Please advise@ndyP
September 10th, 2009 6:27pm
Hi,Since you are having three different externalSMTP domain names which will be used for UC, you must register and buy three different Certificates and can use those certifcate for all the services for that SMTP domain name.Hope thebelow article's can help you out.http://help.godaddy.com/article/3908http://www.digicert.com/unified-communications-ssl-tls.htm
Free Windows Admin Tool Kit Click here and download it now
September 10th, 2009 7:09pm
Yes, you need to register all three domain names with anyone of ISP then only they will be be able to provide you SAN certificates with these names since they need authorization of administrative contacts from WHOIS database of these domains...
Unified Communications Certificate Partners for Exchange 2007 and for Communications Server 2007
http://support.microsoft.com/kb/929395
DigiCert's Exchange 2007 CSR Tool - for cmdlet syntax generation...
https://www.digicert.com/easy-csr/exchange2007.htm
Certificate Use in Exchange Server 2007
http://technet.microsoft.com/en-us/library/bb851505.aspxAmit Tank | MVP Exchange Server | MCITP: EMA | MCSA: M | http://ExchangeShare.WordPress.com
September 10th, 2009 7:20pm
Hi,Thanks for the replies.Considering the situation, I guess I should of selected a better term than register.FYI... the 3 domains are already owned and "registered" with GoDaddy.I was more interested in verifiying if I had all of the domains correct that need to be put into the certificate request.If I need to make a certificate request for ONE UCC SSL certificate, does it really need to include all of these names:- mail.externaldomain1.com- mail.externaldomain2.com- mail.externaldomain3.com- externaldomain1.com- externaldomain2.com- externaldomain3.com- autodiscover.externaldomain1.com- autodiscover.externaldomain2.com- autodiscover.externaldomain3.com- internaldomain.local- servername.internaldomain.localNew second question though, if I did get three different certificates, does Exchange 2007 have different HTTP virtual servers like 2003 did?Please advise,
@ndyP
Free Windows Admin Tool Kit Click here and download it now
September 11th, 2009 4:34pm
Add simple host name of Exchange server in the list...
servernameAmit Tank | MVP Exchange Server | MCITP: EMA | MCSA: M | http://ExchangeShare.WordPress.com
September 11th, 2009 6:50pm