none
generating CSR & removing expired certificates RRS feed

  • Question

  • We have installed a new exchange 2007 server into our existing domain to share the Transport & CAS roles. Once we completed the setup & imported the certificates all our outlook users started getting the Certificate Security pop with the new server name.

    I am in the process of regenerating our digicert to add the new server name. for this i need to 1st generate a CSR.

    please advise, if i need to create this CSR on the old server or new server.

    Now when I go to IIS 7.0,

    on my old server, under server certificates, i can see 2 certificates, one is the existing working one & the other is the expired certificate.

    is it safe to remove the expired certificate?

    on my new server, under server certificates, i can see 2 certificates, one is the same as the working certificate as on my old server and the other is one issued by the server during setup, it has got the netbios name of the server itself.

    is it safe to remove this certificate?

    please advise.

    Thank You

    Philip

     

    Wednesday, April 11, 2012 9:11 AM

Answers

  • Hi,

    How did you installed the certificate?

    Please try to run the cmdlet below and then post the result here:

    get-exchangecertificate |fl

    We need to verify what service has been enabled on the new certificate.


    Xiu Zhang

    TechNet Community Support

    • Proposed as answer by Xiu Zhang Monday, April 16, 2012 5:34 AM
    • Marked as answer by Xiu Zhang Wednesday, April 18, 2012 6:50 AM
    Thursday, April 12, 2012 8:49 AM

All replies