Certificate Install and Setup for Exchange 2007
OK,
I know that I have not posted anything to this site in a LONG time, but alas, here we go again.
We did the whole migration from windows 2000 domain servers and exchange 2000 to the big move up to windows 2008 domain and 2007 exchange server. We wanted to be able to have mobile devices connect to our exchange server to get updated emails, contacts, calendar, etc. With the old 2000 exchange this was done with no problems, however, in 2007 you need to have a cert in place with the Exchange server and IIS configured for this. I did many web site searches for help and finally figured this whole thing out,, I will try to remember all the steps in doing this, but I may skip a step or two,, a few days have passed since this was setup and I'll try to remember everything.
1. First off you need to decide whether you want an internal cert (windows based on your own network) or external cert via a certificate authority (CA). I decided to go with the external CA, since I did not want an internal one and then have to install this manually on each device trying to connect. I did go with Go Daddy for this part which was pretty simple to do.
2. Log in to Go Daddy site, create an account if needed, the click on SSL Certificates, SSL Certificates. I did the Standard SSL and also the Mulitple Domain (UCC), let me explain this, if you have domains like I did,, mail.domain.com and mail.domain.local for both external and internal connections this made things much easier. So I went ahead and did the whole add to basket, without all the frills and crap and just did a check out. This then created an account for SSL management. (These next parts I am still fuzzy about).
3. Once you are in the Go Daddy part you can then manage your SSL cert, this is where I believe that you can then start adding in the names of servers, domains, etc in this field,,so I did the following>> FQDN for our environment, ex. mail.domain name.com, SERVER NAME mail, I also added the following, autodiscover.domain name.com and that was pretty much it. Like I said, I am a little fuzzy about what needed to happen there. You also need to select mail type, such as IIS, Lotus Notes. When this was done, GoDaddy emailed my account ( which was setup prior ) to let me know the order was placed and then in another email that they were contacting the administrative contacts for our domain to authorize then to move forward with a cert. In my case it was me and our domain entry handlers on the Internet. Once this was done, time to get a CSR from our email server.
4. Go to the following kick ass site https://www.digicert.com/easy-csr/exchange2007.htm
insert the common name mail.domain name.com, ( by the way I am using MAIL for references only, you will NEED to user your own exchange server name here ). Now in the subject lines you can enter the other "alias" names you were using prior in the Go Daddy registration. Input your Organization name, Department, City, State, Country (GO USA hehehe) and then Key Size, I kept the default here, click on Generate, this will give you the information you will need on the exchange server to gen the CSR.
5. On your email server, copy the entire information to a command exchange shell and then hit the enter key. This will generate the CSR needed by Go Daddy. The CSR will be generated into the root of your C: drive, this information is the cert info Go Daddy will need to complete their request ( Still fuzzy on that part ).
6. Go Daddy will email you the information needed to download and install the cert.
7. I copied both certbundle info, gd_iis file and the cert file back to the exchange server.
8. Now it gets FUN... open an MMC console then click on File, Add/remove Snap-in, you will need to select the Certificates mod and then click on Add, you can then close back to the MMC which is now open and has the Cert mod loaded. Click on Intermediate Certification Authorities to open this, you will then see Certificates under this listing, right click on this and then click on All Taks, import, you will browse to the gd_iis file and upload into this field. Then in the root tree click on Personal and expand this as well. There is another Certificates here as well, right click All Tasks and Import again and browse to the mail. cert file you also copied to the server. You should get a message that both are imported successful ( My second import did take awhile and also caused the MMC to go into a non responsive but patience prevailed and this did work.
9. Off to the IIS manager in exchange, expand the directories until you see the Default Web Site, on the right hand side of the window under Edit Site, there should be a listing for Bindings, click on this to open the window, now you will see the https in the Site Bindings window, highlight this and then click on edit. Under the SSL Certificate I now had (2) Microsoft Exchange listings, I chose the second one listed and then clicked on VIEW to make sure this was the one with all the server and FQDN listings, mail name etc. Then just clicked OK,,OK , until I was back to the original screen.
10. You can now test your cert install with the following web site, ( which is pretty cool ).
https://www.testexchangeconnectivity.com/
I hope parts of this article will help some techies out then needing that little extra info, like I said, I was a little unsure of some steps listed but take your time, go slow, and the references should get you through it.. Also, if needed, it is more than worth the money to call MS Tech support and spend the $259 (I think) to help get things up and running quickly instead of spending time and getting frustrated.
Well, thats my story and I am sticking to it..
biz
I know that I have not posted anything to this site in a LONG time, but alas, here we go again.
We did the whole migration from windows 2000 domain servers and exchange 2000 to the big move up to windows 2008 domain and 2007 exchange server. We wanted to be able to have mobile devices connect to our exchange server to get updated emails, contacts, calendar, etc. With the old 2000 exchange this was done with no problems, however, in 2007 you need to have a cert in place with the Exchange server and IIS configured for this. I did many web site searches for help and finally figured this whole thing out,, I will try to remember all the steps in doing this, but I may skip a step or two,, a few days have passed since this was setup and I'll try to remember everything.
1. First off you need to decide whether you want an internal cert (windows based on your own network) or external cert via a certificate authority (CA). I decided to go with the external CA, since I did not want an internal one and then have to install this manually on each device trying to connect. I did go with Go Daddy for this part which was pretty simple to do.
2. Log in to Go Daddy site, create an account if needed, the click on SSL Certificates, SSL Certificates. I did the Standard SSL and also the Mulitple Domain (UCC), let me explain this, if you have domains like I did,, mail.domain.com and mail.domain.local for both external and internal connections this made things much easier. So I went ahead and did the whole add to basket, without all the frills and crap and just did a check out. This then created an account for SSL management. (These next parts I am still fuzzy about).
3. Once you are in the Go Daddy part you can then manage your SSL cert, this is where I believe that you can then start adding in the names of servers, domains, etc in this field,,so I did the following>> FQDN for our environment, ex. mail.domain name.com, SERVER NAME mail, I also added the following, autodiscover.domain name.com and that was pretty much it. Like I said, I am a little fuzzy about what needed to happen there. You also need to select mail type, such as IIS, Lotus Notes. When this was done, GoDaddy emailed my account ( which was setup prior ) to let me know the order was placed and then in another email that they were contacting the administrative contacts for our domain to authorize then to move forward with a cert. In my case it was me and our domain entry handlers on the Internet. Once this was done, time to get a CSR from our email server.
4. Go to the following kick ass site https://www.digicert.com/easy-csr/exchange2007.htm
insert the common name mail.domain name.com, ( by the way I am using MAIL for references only, you will NEED to user your own exchange server name here ). Now in the subject lines you can enter the other "alias" names you were using prior in the Go Daddy registration. Input your Organization name, Department, City, State, Country (GO USA hehehe) and then Key Size, I kept the default here, click on Generate, this will give you the information you will need on the exchange server to gen the CSR.
5. On your email server, copy the entire information to a command exchange shell and then hit the enter key. This will generate the CSR needed by Go Daddy. The CSR will be generated into the root of your C: drive, this information is the cert info Go Daddy will need to complete their request ( Still fuzzy on that part ).
6. Go Daddy will email you the information needed to download and install the cert.
7. I copied both certbundle info, gd_iis file and the cert file back to the exchange server.
8. Now it gets FUN... open an MMC console then click on File, Add/remove Snap-in, you will need to select the Certificates mod and then click on Add, you can then close back to the MMC which is now open and has the Cert mod loaded. Click on Intermediate Certification Authorities to open this, you will then see Certificates under this listing, right click on this and then click on All Taks, import, you will browse to the gd_iis file and upload into this field. Then in the root tree click on Personal and expand this as well. There is another Certificates here as well, right click All Tasks and Import again and browse to the mail. cert file you also copied to the server. You should get a message that both are imported successful ( My second import did take awhile and also caused the MMC to go into a non responsive but patience prevailed and this did work.
9. Off to the IIS manager in exchange, expand the directories until you see the Default Web Site, on the right hand side of the window under Edit Site, there should be a listing for Bindings, click on this to open the window, now you will see the https in the Site Bindings window, highlight this and then click on edit. Under the SSL Certificate I now had (2) Microsoft Exchange listings, I chose the second one listed and then clicked on VIEW to make sure this was the one with all the server and FQDN listings, mail name etc. Then just clicked OK,,OK , until I was back to the original screen.
10. You can now test your cert install with the following web site, ( which is pretty cool ).
https://www.testexchangeconnectivity.com/
I hope parts of this article will help some techies out then needing that little extra info, like I said, I was a little unsure of some steps listed but take your time, go slow, and the references should get you through it.. Also, if needed, it is more than worth the money to call MS Tech support and spend the $259 (I think) to help get things up and running quickly instead of spending time and getting frustrated.
Well, thats my story and I am sticking to it..
biz

0 Comments:
Post a Comment
<< Home