disturbedone
Vendor
I have taken over an Exchange 2010 environment and the SSL certificate is due to expire shortly. I have a pretty good idea of the process but would like to clarify it with someone.
Firstly, some background. There are 2x CA/HT (CA1 and CA2) servers and 2x MBX (MX1 and MX2) servers.
This is what I think is the correct procedure:
1. On CA1 server go to IIS Manager/Security/Server Certificates. Currently I see the existing certificate that with name="exchange 2010", IssueTo='mail.domain.com" and IssuedBy="Thawte SSL CA".
2. Right-click and select 'Renew'. Options are to 'Renew an existing certificate', 'Create a renewal certificate request' and 'Complete certificate renewal request'. As the certificate comes from an external authority (Thawte) I would select the 'Create a renewal certificate request' - is that correct? It asks for where to store the output file - does this need to be request.csr or can it be request.txt (it seems to let me call it anything)
3. I assume the output file is a CSR (Certificate Signing Request) and viewing the text file would show something like this example.
4. I would then go to Thawte and request a renewal and past this CSR into the suitable field online.
5. Thawte would send me certificate
6. I would then go to CA1, right-click the certificate and select the 3rd option to 'Complete certificate renewal request' and upload the supplied file eg certificate.cer
Hopefully that is correct. If so, then the next step would be to get the renewed certificate onto CA2. I think all I'd need to do would be to 'Complete certificate renewal request' and upload the new *.cer file. I wouldn't think I'd need to create a CSR because I want the same certificate on both servers. Can someone confirm this is all I need to do to CA2?
Is there anything else that needs to be done to get the renewed certificate on? Is there anything inside Exchange EMC/CLI that needs to be done?
Thanks in advance.
Firstly, some background. There are 2x CA/HT (CA1 and CA2) servers and 2x MBX (MX1 and MX2) servers.
This is what I think is the correct procedure:
1. On CA1 server go to IIS Manager/Security/Server Certificates. Currently I see the existing certificate that with name="exchange 2010", IssueTo='mail.domain.com" and IssuedBy="Thawte SSL CA".
2. Right-click and select 'Renew'. Options are to 'Renew an existing certificate', 'Create a renewal certificate request' and 'Complete certificate renewal request'. As the certificate comes from an external authority (Thawte) I would select the 'Create a renewal certificate request' - is that correct? It asks for where to store the output file - does this need to be request.csr or can it be request.txt (it seems to let me call it anything)
3. I assume the output file is a CSR (Certificate Signing Request) and viewing the text file would show something like this example.
4. I would then go to Thawte and request a renewal and past this CSR into the suitable field online.
5. Thawte would send me certificate
6. I would then go to CA1, right-click the certificate and select the 3rd option to 'Complete certificate renewal request' and upload the supplied file eg certificate.cer
Hopefully that is correct. If so, then the next step would be to get the renewed certificate onto CA2. I think all I'd need to do would be to 'Complete certificate renewal request' and upload the new *.cer file. I wouldn't think I'd need to create a CSR because I want the same certificate on both servers. Can someone confirm this is all I need to do to CA2?
Is there anything else that needs to be done to get the renewed certificate on? Is there anything inside Exchange EMC/CLI that needs to be done?
Thanks in advance.