Re: SSl on FE Exchange

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Recommend buying a cert from a commercial CA for production FE boxes -
there are many low-cost CAs out there trusted by Windows/IE. For the price
these CAs sell certs for its not worth the time and effort involved in
setting up an internal CA - if issuing a SSL cert to your OWA FE is the only
reason you're doing it.

Should you need to set up an inhouse CA, you neither need nor should locate
it on a DMZ. You can generate a cert req from your DMZ FE box and transfer
the cert req file to your internal CA, then issue cert, and transfer the
cert using any media or method to the server in DMZ.

Users would need to be able to access the CRL which can be published at an
accessible location in your dmz, including public web servers.
--
Bharat Suneja
MCSE, MCT
www.zenprise.com
blog: www.suneja.com/blog
-----------------------------------------



"Lion" <Lion@xxxxxxxxxx> wrote in message
news:u0eOXwq9FHA.4036@xxxxxxxxxxxxxxxxxxxxxxx
> Can I setup my FE Exchange to issue SSL certificates to it's self or do I
> need another server in my DMZ to do this job.
>
> Thanks.
>


.



Relevant Pages

  • RE: RPC over Http
    ... dude the cert has to match the FQDN of the server that the cert is on not the ... > it has a flat name or FQDN? ... >>first of all you never put a front end server in a DMZ. ...
    (microsoft.public.exchange.admin)
  • Re: Creating a cert for OWA server?
    ... In the DMZ, as in not part of the AD domain? ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • Re: Creating a cert for OWA server?
    ... In the DMZ, as in not part of the AD domain? ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • Re: Creating a cert for OWA server?
    ... but you have a domain member in the DMZ. ... publishes OWA from the internal network. ... Creating a cert is very easy using the certificate wizard in IIS under ...
    (microsoft.public.exchange.admin)
  • ISA 2006 single NIC with two SSL certs
    ... I have ISA 2006 in the DMZ with a single NIC. ... it possible to bind two SSL certificates to this machine. ... internal(CA cert) cert talking to exchange named? ...
    (microsoft.public.isa)