Re: How to setup a Server Certificate with multiple domains?



Dean has said that their internal domain is a .local so there is no need to
create an internal DNS record for www.yourdomain.com access.

Usually running the CEICW will create the certificate needed and there
should be no reason to have to install Certificate Service to do so.

"steveb" <swb_mct@xxxxxxx> wrote in message
news:e1tNKWuTHHA.4028@xxxxxxxxxxxxxxxxxxxxxxx
You really only need one certificate with the common name for you public
domain address. .such as."owa.yourdomain.com" For internal access to OWA,
you create a zone on your internal DNS server with the name
"owa.yourdomain.com. Then you create an A record in the zone pointing to
the LAN address of you SBS2003 server box. With this setup, your
internal clients can access your SBS2003 server using thesame URL s your
external clients.

If you have public web site, you will also have to create an A record for
its IP address, or your internal clients will not be able to find it
because the internal zone will preempt your clients or the server from
looking to the external DNS servers for www.yourdomain.com.

There is probably a SBS method for creating a new certificate, but the the
General Microsoft way is to install Certificate Service and then create a
new Certificate in IIS for "owa.yourdomain.com"



"dean.carrefour" <deancarrefour@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:B7090491-D6C0-4740-A55C-B2D4AA121E7F@xxxxxxxxxxxxxxxx
We have a SBS2003. Right now it has a Server Certificate for our *.local
internal domain name. I am trying to setup a PDA/Mobile Device to access
its
Exchange email using AUTD. Anyway, whenever I try to access our OA email
from outside our internal network, I always get an error page like this:

-----------------
There is a problem with this website's security certificate.

The security certificate presented by this website was issued for a
different website's address.

Security certificate problems may indicate an attempt to fool you or
intercept any data you send to the server.
------------------

Right now the certificate is setup for our internal Windows *.local
domain
name. I would like to also add our external *.com domain name. How can
I do
this? I believe the current certificate was created internally as it
says
Issued To and Issued From, both pointing to this same machine.
Certificate
Authority service doesn't appear to be installed, I get an error when I
try
to run it that says:

Cannot manage Certificate Services.
The specified service does not exist as an installed service. 0x424
(WIN32:
1060)

I found this link:
http://technet.microsoft.com/en-us/library/04284d82-b1cf-4582-b784-f5aaed5b23c9.aspx
which seems like it should solve my problem, but its for Exchange 2007.

How can I setup my SBS2003 to allow users to connect via our internal
network *.local domain as well as our external *.com domain?

Thanks.




.



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: Help - how do you completly remove Certificate Services?
    ... >I wouldn't be unhappy removing the cert server and reinstalling it as a root ... >> root certificate for the certificate service that is no longer there. ... I have deleted them from several of the machines ...
    (microsoft.public.win2000.security)