Re: Creating a cert for OWA server?



On Sun, 1 Jul 2007 12:03:32 +0100, "Gonzo" <nospam@xxxxxxxxx> wrote:

I have a 2003 OWA server that needs a cert. How can I create a cert for it
to be https, I do have an internal cert server, but the OWA server is on a
DMZ. Just don't know where to start?

Anyone else done this before?



In the DMZ, as in not part of the AD domain?
Not a good idea.
Creating a cert is very easy using the certificate wizard in IIS under
the properties of the default website.
Submit it to a 3rd party certification authority and after they return
it, simply return to the wizard and import it it.

The FQDN of the cert is the name you want people to connect to in DNS.
So, if in DNS, external users connect to https://owa.domain.com, thats
the FQDN you request for the certificate.

I would recommend not using a self-signed certificate for a number of
reasons.

.



Relevant Pages

  • Re: Creating a cert for OWA server?
    ... Why is the OWA server bad int he DMZ? ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • Re: Creating a cert for OWA server?
    ... In the DMZ, as in not part of the AD domain? ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • Re: Options for Deploying Root and Int Certs to clients not part o
    ... Let's say I assign a cert to a web server that is accessible from the ... outside using certs from my internal cert server. ... issuing CA and the root CA cert's or just the root? ... The default certsrv Web page has an option to download the certificate ...
    (microsoft.public.security)
  • Re: Creating a cert for OWA server?
    ... but you have a domain member in the DMZ. ... publishes OWA from the internal network. ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • Re: ADFS Token-signing Certs Not in Trusted Root Store
    ... This is good info, Joe. ... So now I know that the token-signing certificate is ... Get a signing cert from a CA ... case, you never have to worry about expiration or CRL checking, as your cert ...
    (microsoft.public.windows.server.active_directory)