Home » Exchange 2010

[Updated] How to Renew Exchange 2010 Multiple Domain Certificate
(GoDaddy UCC)

This is an updated version of our existing Screencast How to Renew Exchange 2010 SSL Certificate.

The need for this update arises from the new Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, adopted by CA/Browser Forum (includes over 30 CA members and major browser vendors: Microsoft, Apple, Mozilla, Google, Opera):

– CA SHALL NOT issue a certificate with an Expiry Date later than 1 November 2015 with a SAN or Subject Common Name field containing a Reserved IP Address or Internal Server Name.
– Effective 1 October 2016, CAs SHALL revoke all unexpired Certificates whose SAN or Subject Common Name field contains a Reserved IP Address or Internal Server Name.

Quite often, the company’s Internal (Active Directory) and Public Domain Names are different. By default, Exchange setup configures and uses the Internal Exchange 2010 server’s name in the virtual directories URL. If that name uses a non routable domain suffix (ex .local), you need to reconsider the way you request/renew Exchange 2010 Multiple Domain certificates. So far, the whole process was simplified significantly just by adding the Exchange 2010 internal name in the Subject Alternative Names (SAN) field. The new requirements (the latest version is BR v 1.1.6) and more specifically the fact that you should avoid using Internal Server names in the certificate add a layer of complexity.

In the updated version of our Screencast, we address these requirements by:

– Configuring Split-Brain DNS or Pin-Point DNS zones on the local network. We demonstrate both approaches, so you can choose the one that fits better your needs.
– Modifying the Exchange 2010 internal URL

– Requesting and installing a GoDaddy Multiple Domain certificate (UCC) which doesn’t use our Internal Server’s name.

For your convenience, we have published the text file with our project plan and commands that we are using in the Screencast here .

Click to play 1 video
Step 1 We start with planning the names that must be included in our Exchange 2010 GoDaddy UCC (Multiple Domain Certificate) and the required changes in the local name resolution and Exchange internal URL

Click to play 2 video
Step 2 Next, we generate and submit a new Certificate Signing Request (CSR). Then, we approve the names included in the CSR and download the new certificate.

Click to play 3 video
Step 3 In the last step, we demonstrate how to configure Split-Brain DNS or Pin-Point DNS zones. After that we modify the Exchange 2010 internal URL. Finally, we enable the new Exchange certificate and delete the old one.

NetoMeter Screencasts

Step-by-Step Video Tutorials

Useful Links

netometer logo

Edtior's Picks

Latest Articles

©2024 NetoMeter All Right Reserved.