Exchange 2010, UCC SSL, and the "new" CA/BROWSER Forum not issuing for .local

I don't know how many people have run into this yet, but the CA/BROSWER Forum, the "standards" authority for SSL issuing, has mandated that CA's can no longer issue a certificate using a FQDN "intranet" name for new or renewal SSL certificates effective
Nov 1, 2012.  i.e. the Microsoft standard of mydomain.local will no longer be accepted as a SAN on a UCC for Exchange 2010.  I've looked thru the KBs and Social forums, but haven't really found any guidance on how to solve this.  I'm presuming
that the certs will have to be split and the "external" domain name of server.mydomain.net will just become a single server SSL, and the internal name of server.mydomain.local will become a Self-Signed certificate.  With the increasing prevalence of OA
and ActiveSync devices, is there any baseline guidance yet on how to make this happen without completely fouling up production servers and killing access to the user community?

On the same topic, though likely different environment...
Against recommended deployment, I have a number of clients running all their services on one box.  Windows Server 2008, Active Directoy, DNS, Exchange 2010 ...and so on.  These servers all have .local addresses, which means of course that the SAN
certificates have .local addresses as one of the SANs.
I've read alot online about this issue, and am trying to find the most cost effective solution to switch numerous production servers running this configuration.
The best solution I've come up with so far is...
1. Virtual AD with new external domain, 2. Migrate Exchange CAS to this domain, 3.  Reconfigure network through the box.
Obviously these steps will contain alot more details, but this is just the outline atm.  At best, I see me having to take a second box with me to each location to perform these steps, and I can't see it happening without disruption to the work flow
of employees.
Thankfully, all of these businesses are relatively smal...under 25 employees.  Still, I'd like to find the smoothest transition solution possible.
Any suggestions would be greatly appreciated!
Regards

Similar Messages

  • Updated to 10.4 and the New Purchased feature is not working. Anyone else having this problem?

    Updated to 10.4 and the New Purchased feature is not working. Anyone else having this problem?

    I did originally, but it fixed itself after a few minutes.

  • I have IPod classic that I have been extremely happy with. I now have purchased ipod nano and Iphone. the older version and the new 2.2 are not compatiable. I want to use all my IPods and Iphone,

    have IPod classic that I have been extremely happy with. I now have purchased ipod nano and Iphone. the older version and the new 2.2 are not compatiable. I want to use all my IPods and Iphone, but I only have my one computer, how can I update all of my Apple products. I want to use them all.

    Hello graingers45,
    graingers45 wrote:
    have IPod classic that I have been extremely happy with. I now have purchased ipod nano and Iphone. the older version and the new 2.2 are not compatiable. I want to use all my IPods and Iphone, but I only have my one computer, how can I update all of my Apple products. I want to use them all.
    What do you mean it isn't' compatible?  What isn't compatible?
    There is no limit to the number of iPods you can sync to one computer, iTunes library, or iTunes account.  Simply connect each separate iPod/iPhone to your computer and configure each to sync whatever content you wish to.
    B-rock

  • I just downloaded a few tv show and the 'info' / 'description' section has not downloaded for the episodes...on previous items it has downloaded just not the recent few? Any ideas why?

    I just downloaded a few tv show and the 'info' / 'description' section has not downloaded for the episodes...on previous items it has downloaded just not the recent few? Any ideas why?

    Check permissions and ownership of the files. Maybe this helps....
    How to Take Ownership and Grant Permissions in Windows Vista

  • I have the original ipad. I can't delete my photos from the ipad, and the new itunes update does not give me the option to sync photos. What do I do?

    I have the orignal ipad. I synced all my photos from my computer onto. Now I don't have enough storage on my ipad so I want to delete these photos. When I try from my ipad it only gives me the option to share or copy, NOT DELETE. I went to resync my ipad to itunes, after I downloaded the new version and now it doesn't give me an option to sync photos. How do I get rid of them?

    Wow.  That's weird.
    Is your iPad jailbroke?  If it is, all bets are off.  If it is not jailbroke, keep reading.
    First, try a system reset.  It cures many ills and it's quick, easy and harmless...
    Hold down the on/off switch and the Home button simultaneously until you see the Apple logo.  Ignore the "Slide to power off" text if it appears.  You will not lose any apps, data, music, movies, settings, etc.
    If the Reset doesn't work, try a Restore.  Note that it's nowhere near as quick as a Reset.  It could take well over an hour!  Connect via cable to the computer that you use for sync.  From iTunes, select the iPad/iPod and then select the Summary tab.  Follow directions for Restore and be sure to say "yes" to the backup.  You will be warned that all data (apps, music, movies, etc.) will be erased but, as the Restore finishes, you will be asked if you wish the contents of the backup to be copied to the iPad/iPod.  Again, say "yes."
    At the end of the basic Restore, you will be asked if you wish to sync the iPad/iPod.  As before, say "yes."  Note that that sync selection will disappear and the Restore will end if you do not respond within a reasonable time.  If that happens, only the apps that are part of the IOS will appear on your device.  Corrective action is simple -  choose manual "Sync" from the bottom right of iTunes.
    If you're unable to do the Restore, go into Recovery Mode per the instructions here.

  • My Mail has frozen - can access my hotmail through Safari but Mail now has a blank rectangle on the screen and the inbox underneath it has not updated for 2 days

    Mail giving problems. Small white rectangular box comes up on screen and inbox underneath has not updated for 2 days.
    I can use Safari to get new messages but, since getting this laptop, when I go to Hotmail via Safari old messages self delete every so often, whereas via Mail messages stay in the inbox unless I actually delete them. Any suggestions?

    Here is a photo of what I see when I tap on the mail icon to open it. It stays there for a second or two and then goes dark. Then I actually have to put my iPad into sleep mode in order to use it again. The app will NOT close no matter what I do, just shutting it down or put it in sleep and then restart  it.
    here is when I tap the mail icon. It looks like an empty page but you will see the format of the mail page. Next photo is what is see after a second. And the last photo is what I see before the iPad locks up or Les blank. I hope this makes things clearer as to what the problem is. Thanks for your help, hope this helps! Diane May.

  • I accidentally lost a mail add on that I really liked, but I cannot find. The new one recommended is not working for me. Can anyone help?

    the icon was a very small white envelope that had a golden star and a tally of mail
    it was easy to install -- only needed e-mail, not server
    (I have mail through road runner)
    brought up the email address so you could click and it would take you to the list, bypassing password

    I still can't get it to work that way. I changed my cfexecute to:
    <cfexecute name="C:\windows\system32\cmd.exe" arguments="/c C:\Inetpub\wwwroot\captcha\#cmd_filename#" outputFile="C:\testoutput.txt" timeout = "90"></cfexecute>
    And I changed my bat file to have:
    <cfsavecontent variable="cmd_content">
    cd\
    TSC.exe /s "#newString#" C:\Inetpub\wwwroot\captcha\#FileName# Mary (for Telephone)
    </cfsavecontent>
    The output file is showing:
    C:\ColdFusion9\runtime\bin>cd\
    C:\>TSC.exe /s "3.....P.....4.....Z.....8.....U.....7.....X....." C:\Inetpub\wwwroot\captcha\3P4Z8U7X-105724.wav Mary (for Telephone)
    I still can't get it to run the exe. I have watched the process list while running this and the exe doesn't show up. I tried cfexecute on the exe directly before trying the bat method, with hard coded arguments, and it still didn't work. I am so lost right now this makes no sense to me.

  • I forgot my security question answers and the info apple has is not working for me and I don't want to call them, how do I reset my security questions?

    I forgot my security question answers and the info apple gave to me didn't help, how do I reset them, I also don't want to call them?

    From http://support.apple.com/kb/HT5665 :
    If you have three security questions and a rescue email address
    sign in to My Apple ID and select the Password and Security tab to send an email to your rescue email address to reset your security questions and answers (the steps half-way down that page should give you a reset link)
    If you have one security question and you know your Apple ID passwordsign in to My Apple ID and select the Password and Security tab to reset your security question.
    If you have one security question, but don't remember your Apple ID passwordcontact Apple Support for assistance. Learn more about creating a temporary support PIN to help Apple confirm your identity when you contact Apple Support.
    If you can’t reset them via the above instructions (you won't be able to add a rescue email address until you can answer your questions) then you will need to contact iTunes Support / Apple in your country to get the questions reset - which is likely to be by phone as they need to confirm your id and that it's your account.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699
    When they've been reset (and if you don't already have a rescue email address) you can then use the steps half-way down this page to add a rescue email address for potential future use : http://support.apple.com/kb/HT5312

  • HT4623 what if you go to general and the new up date is not there

    what if i go to general and my update does not automatic appear and my device need to be updated?

    If you have an iPad 1, the max iOS is 5.1.1. For newer iPads, the current iOS is 6.0.1. The Settings>General>Software Update only appears if you have iOS 5.0 or higher currently installed.
    iOS 5: Updating your device to iOS 5 or Later
    http://support.apple.com/kb/HT4972
    How to install iOS 6
    http://www.macworld.com/article/2010061/hands-on-with-ios-6-installation.html
    iOS: How to update your iPhone, iPad, or iPod touch
    http://support.apple.com/kb/HT4623
    If you are currently running an iOS lower than 5.0, connect the iPad to the computer, open iTunes. Then select the iPad under the Devices heading on the left, click on the Summary tab and then click on Check for Update.
    Tip - If connected to your computer, you may need to disable your firewall and anitvirus software temporarily.  Then download and install the iOS update. Be sure and backup your iPad before the iOS update. After you update to iOS 6.x, the next update can be installed via wifi (i.e., not connected to your computer).
     Cheers, Tom

  • HT1657 On my Movies tab I have a red Ticket on there and the movie I rented did not download for viewing...why????

    On my "movies" tab a red ticket appears but the rented Download did not appear in my files.  Why??? What does the dumb ticket mean and how can I down for load again without paying for it again??

    Try the 'report a problem' page to contact iTunes Support and see what they say : http://reportaproblem.apple.com
    If the 'report a problem' link doesn't work then you can try contacting iTunes support via this page : http://www.apple.com/support/itunes/contact/- click on Contact iTunes Store Support on the right-hand side of the page, then Purchases, Billing & Redemption

  • The new IPAD OS has some issues for Ipad 1 users

    I have found that I can not delete email messages.  What it does when you delete the nesasge is turn it into a no sender no subject message. You can't do any thing with this type of message. It also did something to the on screen typing I can now type faster than the screen will accept.
    What else have you found?
    Gord

    It sounds like it is time to try a rest. Press & hold together the Home and Power buttons for 10+ seconds, ignoring the red power-off slider, until you see the Apple logo.

  • Performance difference with my MBP 15" 2010 and the new 2011 one(gaming?)

    Hey guys,
    I have a 2.67 i7 2010 15" MPB(the higher end model)that I got last year. I use it for work and for college but I also like to play games on it.
    I recently got an Apple newsletter as I noticed the huge performance boost of the newer models. I went to a review site and my specific model nearly doubled in benchmark scores with the newer model. That doesn't seem like something that would normally happen. It seems like a rarity thats just too good to ignore. And this summer with the semesters being over I probably will go back to full on gaming(probably Portal 2 and WoW for the summer).
    My question to you is, since I can't go by the opinion of one site, what is the performance difference between the 2010 model I have and the newer 2011 one? Basically I am wondering if its worth it to sell it for several hundred dollars less than I payed for it and get the newer model now, or wait until 2012 to get the newest model then(if its going to be an even bigger difference in performance)?
    Excuse my poor judgement if I'm wrong, I probably seem like a maniac for using this comp for a year and already wanting to get the newer model. Its just that a lot of sites are making it seem like my model is fodder compared to the newer ones, and if so I might not let this offer pass by.

    bump for good measures!

  • IOS 4.3.1 + Exchange 2010 "was" fine with the mailbox on Ex2007 server

    Hi,
    i had used my iphone with ios 4.3.1 and active sync.
    The mailbox was hosted on the old exchange 2007 server.
    A new exchange 2010 server was running the last 4 weeks and the iphone was connection with activesync against the new exchange 2010 through local wlan and over internet.
    After i moved my profile to the new server i can´t connect anymore to the new server!
    Any idea what happend?

    It was working fine the last weeks with my mail account sitting on exchange 2007.
    Today i moved several mailboxes from exchange 2007 to 2010 SP1.
    I have some domain accounts that are created new and had their mailbox created on the exchange 2010 sp1 system.
    With these accounts i can connect and retrieve mails.
    But with my account (moved from 2007 to 2010) i can´t.
    All i get is a blank mailbox on my iphone.
    I even removed the mail account from my iphone and recreated the account.
    But it won´t retrieve mails.
    I refresh the offline addressbook at the exchange 2010 but nothing will help.
    Message was edited by: juergenb52

  • Day 11 of 14, New too Verizon and the new Thunderbolt, do we keep it or send it back?

    I have had a number of surprises so far after coming to Verizon with the new Thunderbolt.. We ordered 2 bolts. The battery issue was disappointing, but a bigger battery will fix it, and/or a daily charge seems to take care of it. 
    I live in the country on fridge of the city, my wife came from provider Sprint, and I came from AT&T.  We never had problems with our prior carriers, but must be out of range for the Verizon tower due to the bad signal and sound quality when making calls from the house.  Verizon suggested a network extender, so we had them send us one.  It did fix the signal and the noise problems at home.  Plus can take with us on the road,, guess this problem is fixed too.
    My wife's Bolt had static and noise in any area, 3G or 4G.  Mine has been great.  I called Verizon they said to take it to a Verizon store for an exchange.  I bought the phone online with Verizon, but the brick and mortar stores said they could not do it, I complained and did get them to change out the wife's Bolt.  The replacement serial and mac address was several thousand letters and numbers higher, so expect her phone was built early, but the new replacement is quiet, no noise problem solved.
    The 4G is very fast, speetest.net I was surprised how fast it is.  I love the phone, but I worry with all the issues people keep finding, and I really have not seen any official Verizon communications on what is actual and what might be in progress to fix for good.  Forums are great, but does Verizon read these posts? 
    I am on day 11 of 14.  First timer to Verizon, Thunderbolts aside, do you like them as a wireless carrier?  Thunderbolt's, we like them very much, but I now wonder if maybe insurance is a good idea, seems like we may have many issues in the future too.  I was on the build team for the HP Glisten, we had many issues on our first phones too, but eventually got it fixed too, in fact the prototype I still had when I left AT&T to come to Verizon.  I think we are going to give the phones a couple more days of heavy workout, and then decide.

    So far so good, a few hiccups but Verizon has supported me so far on each issue.  Some responders from the support line where not as good as others, but I did find several who were more than helpful.  The forums here are helpful too, aggravation does make some of the posts bias against the phone, but there are some good posts out there and the solution found posts will help us all. 
    Everyone who owns a Thunderbolt just needs a little patience, it is a new and powerful device.  I'm sure HTC and Verizon are working out the confirmed bugs, and will roll out confirmed updates when they have gathered more data. When I was prototyping the obsidian, which we marketed as the glisten, we had many issues too, but in the end worked most of them out. 
    The thunderbolt should also follow same result as long as Verizon and HTC keep it in the front line, so far they are still marketing it, even with having the Iphone now in their portfolio. I viewed a wirefly.com smackdown between the Thunderbolt and the new Iphone, and to me, I do like the Thunderbolt best.  On to day 12, so far so good. 

  • APP-PAY-06841: Person change exit between the old and the new date.

    Hi,
    Please help me by answering this question as very urgent basis.
    ABC employee Effective date should be of future dated 10-jan-2011.
    But ABC employee joining date has been entered on 10-Aug-2010.
    amd also this date is also ended by updating on 10-Dec-2010.
    But these records are wrong.This employee's effective date should be form 01-Jan-2011.
    how to datetrack.
    if iam changing the date bye keeping effective date as 10-Dec-2010 an an iam changing the record to 01-jan-2011,its throwing the error as "**APP-PAY-06841: Person change exit between the old and the new date**"
    Thanks&Regards,
    Sowmya.K

    What is the application release?
    Please see these docs.
    Error: APP-PAY-06841: Person changes exist between the old date and the new date [ID 399056.1]
    APP-PAY-06841 When Changing Latest Start Date Of An Employee Who Was An Ex-Contingent Worker [ID 1146414.1]
    Unable To Change Start Date for Employee, Get Error "APP-PAY-06841: Person Changes Exist Between The Old Date And The New Date" [ID 603233.1]
    Correcting Latest Start Date in People Screen Gives Error APP-PAY-06841 [ID 368289.1]
    How To Change the Latest Start Date of an Employee? [ID 329692.1]
    Thanks,
    Hussein

Maybe you are looking for