Need to generate a CSR for a new Lync 2013 Edge server

I am upgrading my Lync 2010 Edge to 2013. Part of the process is exporting all the certificates on the 2010, some public, and eventually importing them into my 2013 Edge. I have a problem with one certificate that was generated by our internal CA for the
2010 server itself named servername.domain.local. Since my new Edge will be renamed to the same name as the old Edge, I was planning on exporting this certificate but the private key can't be exported. The option is grayed out.
I need to therefore figure out how to get a certificate on my new Edge. No Lync software has been installed yet. What is the best way to generate a CSR so I can manually create a certificate on my internal CA. Since I don't have access to the internal CA
from the DMZ, I need to do it this way. I am thinking maybe the MMC but maybe Windows PowerShell? Once I get the CSR generated, I will figure out how to create a certificate on my internal CA.
I know I can do it during the Lync install but I wanted to have it ready on the server when installing.

The option is most likely grayed out, because the private key was not marked as exportable.
Now, you can either request the certificate by using the Deployment Tool and requesting the certificates, selecting offline and then manually copying the CSR to your Internal CA (and the certificate back)
Or you can use Powershell and do a Request-CsCertificate (see here: http://technet.microsoft.com/en-us/library/gg425723.aspx)
Try something like this: Request-CsCertificate -New -Type Internal -ComputerFqdn "lyncedge.domain.com" -FriendlyName "Internal Edge"
-Template jcila -PrivateKeyExportable $True -DomainName "edge.domain.com" -Output C:\path\test.req​
If this helped you please click "Vote As Helpful" if it answered your question please click "Mark As Answer"
Georg Thomas | Lync MVP
Blog www.lynced.com.au | Twitter
@georgathomas
Lync Edge Port Check (Beta)
This forum post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

Similar Messages

  • Do we need License for Lync 2013 Edge server?

    Hello Team,
    We are currently running Lync 2013 Standard Edition Server. We are planning to enable users for External access and planning to deploly Lync 2013 edge server.
    1. Do we need License for Lync 2013 Edge server?
    2. Any other client licenses needed?
    Please advise.

    Hi,
    No you don't required any additional License in order to install Lync Edge server. the only license required at OS level i mean windows server licence in terms of Lync concern you don't require any additional License   
    check this 
    https://products.office.com/en-us/lync/microsoft-lync-licensing-overview-lync-for-multiple-users
    http://lyncuc.blogspot.in/2013/02/lync-2013-licensing-guide-how-to.html
    And for client also you don't require any additional license with your existing client license will work for externally as well
    Whenever you see a helpful reply, click on Vote As Helpful & click on Mark As Answer if a post answers your question.

  • New Lync 2013 and no mobile to PC calling

    I have a new Lync 2013 enterprise server deployment.  PC with 2013 client and android phone with 2013 mobile client can both connect and IM fine.  but when I make a Lync call it will ring but not answer even if I click accept.  It just says
    connecting....  I have looked at logs for the PC, phone and on the server but dont see any errors.  I am just not sure where to go from here.  Any suggestions would be greatly appreciated.
    Thanks!!

    After looking through the massive lync clinet 2010 log for almost 3 hours I finally found this:
    02/07/2014|11:14:20.065 1250:120C INFO  :: BYE sip:[email protected];opaque=user:epid:F75G9E5FoVmO8RMWQRntYgAA;gruu SIP/2.0 Via: SIP/2.0/TLS 127.0.0.1:50042 Max-Forwards: 70 From: <sip:[email protected]>;tag=967b0de09e;epid=e115ec3448
    To: "phone"<sip:[email protected]>;tag=d007b4c5e;epid=212185984839 Call-ID: d6c4a0b89c58477b87650daa0bb16fe9 CSeq: 3 BYE User-Agent: UCCAPI/4.0.7577.0 OC/4.0.7577.0 (Microsoft Lync 2010) ms-client-diagnostics: 23; reason="Call failed to establish
    due to a media connectivity failure when one endpoint is internal and the other is remote";CallerMediaDebug="audio:ICEWarn=0x2b,LocalSite=10.1.1.158:14842,LocalMR=pu.bl.ic.ip-AV:3478,RemoteSite=10.38.210.159:19600,PortRange=1025:65000,LocalLocation=1,RemoteLocation=2,FederationType=0"
    Proxy-Authorization: NTLM qop="auth", realm="SIP Communications Service", opaque="E84145BE", targetname="FrontEndSrv1.domain.local", crand="f5c0735e", cnum="28", response="0100000065633334d5df23b80d7f3491" Content-Length: 0 
    02/07/2014|11:14:20.065 1250:120C INFO  :: End of Sending Packet - pu.bl.ic.ip-sip:443 (From Local Address: 127.0.0.1:50042) 994 bytes
    someone please tell me you know exactly what I need to do to fix it.  THANKS!!!

  • Error while generating CW kin for the new BG created for Taiwan

    HiAll,
    Please provide your help to resolve this issue,
    Iam getting error while generating CW kin for the new BG created for Taiwan, China.
    Error : Value TW is not a Valid context for the Descriptive Flexfield Person Developer DF.
    Please let me know, is there any step missed to create CW kins for new BG's.
    Thanks-
    Sowmya.
    Edited by: user13419037 on Jul 2, 2012 3:41 AM

    Hello ,
    Your solution can be solved by enabling the displayed check Box in Location Address DFF
    Thanks
    Bindu

  • In order to take advantage of the iPhone trade in, do I need to have met my upgrade eldigbility date, or do I just need to re-sign up for a new 2 year plan with the new iPhone 6?

    In order to take advantage of the iPhone trade in, do I need to have met my upgrade eldigbility date, or do I just need to re-sign up for a new 2 year plan with the new iPhone 6?

    thanks, a HUGE suggestion for you:  Please add that to the restrictions of the trade-in details online, it mentions that nowhere and is VERY deceptive.  Since at least 90% of 5c and 5s users are under a 2 year contract and both phones have been out just a year, there will be a majority of bitter customers who fell for the ad and will be taking advantage of the buy out options the other carriers are offering.

  • TopLink does not generate SQL statements for inserting new objects

    TopLink does not generate SQL statements for inserting new objects. Why?
    Thanks in advance...

    Please see the response in
    Why does not unitofwork.commit write data to the database?
    Regards,
    Chris

  • If my iphone 4s was unlocked by AT&T, but I need to use my warranty for a new iphone. Do I need to reunlock the new iphone? or will apple give me an unlocked iphone?

    If my iphone 4s was unlocked by AT&T, but I need to use my warranty for a new iphone. Do I need to reunlock the new iphone? or will apple give me an unlocked iphone?

    If your phone is officially unlocked, you will get an officially unlocked iPhone if yours is replaced under warranty. Apple maintains a data base of officially unlocked iPhones & can verify whether your phone is officially unlocked or not. To be safe, point this out to the genius bar, if you go to an Apple store or whoever you talk to, if dealing with AppleCare.

  • Do I need to buy Pages again for my new ipad 2?

    I have Pages on my Macbook Pro. Do I need to buy it again for my new ipad 2? I can't seem to find a way of accessing it from the ipad.

    Yes, you will need to buy the app version from the app store if you want to use it on the iPad - the version on your Mac (OS X) is not compatible with the iPad (iOS), they are different operating systems
    Pages for iPad : http://itunes.apple.com/gb/app/pages/id361309726?mt=8

  • Do i need to buy external microphone for my new hp desktop model p6821pb for others to hear me?

    Do i need to buy external microphone for my new HP Desktop model p6821pb ?
    I can hear when others speak on my Skype Call but they cannot hear me.
    I thought new models don't need external

    Hi,
    Sorry to say, but you'll need to buy an external microphone - there is no internal hardware for this.
    Best regards,
    DP-K
    ****Click the White thumb to say thanks****
    ****Please mark Accept As Solution if it solves your problem****
    ****I don't work for HP****
    Microsoft MVP - Windows Experience

  • Do I need a different SIM Card for the new iPhone?

    Do I need a different SIM Card for the new iPhone?

    The iPhone 5 will come with a new SIM Card in the iPhone ready for you to activate. If you want to make things a bit more difficult, you can cut a Micro SIM to the Nano Sim size with scissors. Of if you have any problems with your iPhone 5 and its SIM Card you can get a new one from your Carrier. But, again the new iPhone 5 will come with a new one for you.

  • Lync 2013 standard server for 3000

    Planning to deploy Lync 2013 standard server for 3000 users, IM/presence, Audio/video, persistence chat, monitoring/archive. external access required so 1 edge server in DC and 1 in DR. No enterprise voice. DC and DR are corrected with dark fiber
    one lync 2013 standard server in DC and 1 in DR. 1 edge server in DC and  1 Edge server in D R.have couple of queries. 
    1. can i get HA while doing server pairing in DC and DR?
    2. how much time will it take for frontend failover if my frontend server is down in DC.
    3. how much time will take for external access failover in DC and DR?
    4. are there any potential risks if using standard version instead of enterprise? 
    Basically client  need cost effective solution  as lync is not critical for him, does not want to use 3 FE servers in DC and 3 FE in DR to achive HA.  want to achieve the solution with standard servers.

    1) HA typically refers to automatic failover, so not with Standard edition, but you can get manual failover with this with nearly full functionality.
    2) Again, this is manual, but once invoked less than 20 minutes I'd think, possibly faster, only testing invoke-failover will tell you for sure but it won't be too bad.
    3) This involves a topology change to change the federation route, possibly next hop for the edge, and possibly media path for a front end pool.  That can be completed and replicated in under a minute.  You may want to point your external simple
    URLs and such (lyncdiscover) at the remaining server, this may be a DNS change to point to a separate reverse proxy.  Your _sipfederationtls._tcp SRV record can have a lower matching partner as well, but I typically prefer to keep low TTLs on the external
    DNS records so they can be changed quickly.
    4) Sure, no automatic failover, your scalability is limited without building out new pools later, no SQL backend that can be mirrored for a bit more resiliency.  But again, you can manually failover without issue, you just have to be able to tolerate
    a short outage.
    Technically, you'd only need 1 FE in the DR site.  You have to match Ent/Ent or Std/Std in a pool pair, but the number of servers don't need to match.  Still, the HLB and SQL requirements can be costly so I understand this.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • What are the ports required for the Audio, Video and A/V conferencing when the following end points are enabled for QoS in Lync 2013 server?

    Hi All,
    What are the ports required for the Audio, Video and A/V conferencing when the following clients are enabled for QoS in Lync 2013 server?
    Client Type
    Port range  and Protocol required for Audio
    Port range and Protocol required for
    Video
    Port range and Protocol required for
    A/Vconferencing
    Windows Desktop   Client
    Windows mobile App
    Iphone
    Ipad
    Andriod phone
    Andriod Tablet
    MAC desktop client
    Please advise. Many Thanks.

    Out of the box, 1024-65535 for all of the client ports.  :) 
    https://technet.microsoft.com/en-us/library/gg398833.aspx
    You'll want to tune your client ports a bit
    https://technet.microsoft.com/en-us/library/jj204760.aspx as seen here, and then the client ports would use those ranges which is easier to set QoS markings.  I'm not sure the mobile clients respect that setting.
    Elan's got the best writeup for Windows clients here:
    http://www.shudnow.net/2013/02/16/enabling-qos-for-lync-server-2013-and-various-clients-part-1/
    However, the marking of the packets is the tricky part.  Windows can do it via Group Policy, but for the other clients you'll need to have the network specifically prioritize ports regardless of DSCP markings.  You have to do it based on ports
    as the traffic could be peer to peer.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications
    This forum post is based upon my personal experience and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • What is best recommendstion for DNS LB for lync 2013 Edge servers

    What is best recommendation for DNS LB for lync 2013 Edge servers ?. We have F5 LB for edge and want to decide if we can go with DNS base LB for Edge servers.
    Anil MCC 2011,ITIL V3,MCSA 2003,MCTS 2010, My Blog : http://messagingschool.wordpress.com

    It will be better to Use Hardware Load balancing (F5).
    If you choose to use DNS load balancing for a pool but still need to implement hardware load balancers for traffic such as HTTP traffic, the administration of the hardware load balancers is greatly simplified. For example, configuring the hardware load balancer
    will be simpler as it will only manage the HTTP and HTTPS traffic, while all other protocols will be managed by DNS load balancing
    Also for more info., you can check below links
    http://technet.microsoft.com/en-us/library/gg615011.aspx
    http://technet.microsoft.com/en-us/library/gg398634.aspx
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • New lync 2013 , 2 subdomains ,ad one domain in foreign country

    As you can see in the picture below, I have the main AD called main.prod and two child1 and child2 subdomains. What is more  I have AD called international.prod placed in foreign country.  I have mbox, cas  using child1.main.prod domain and
    lync 2010  with UM funcion. The more I have 2way trust  between child2.main.prod subdomain and international.prod domain. Now what I would like to do is : make CAS in subdomain child2.main.prod which is authorising people from domain international.prod
    and have mailboxes on mbox from subdomain child1.main.prod as it is shown in the picture. Do you think it make sense? Or I have to make mbox in subdomain child2.main.prod????
    WHat else: I would like resign Lync 2010 and  install new  Lync 2013 and make people from subdomains: child1 and child2 and domain international.prod using this new Lync ,and move UM funcionality from old 2010 lync into new 2013.
    Any contraindications, suggestions??

    Lync Server supports the following topologies for Exchange UM integration:
    Multiple domain (that is, a root domain with one or more child domains). Lync Server, and Microsoft Exchange servers are deployed in different domains from the domain where you create users. Exchange UM servers can be deployed in different
    domains from the Lync Server pool they support.
    Lisa Zheng
    TechNet Community Support

  • I can't generated a CSR for a wildcard certificate

    I recently received a new Mac Mini OS X Server with the Server 2.2.1 app loaded.
    I cannot figure out how to create a CSR for a wildcard certificate.
    The wizard will not accept * in the input field.
    Can someone point me to the hard way of doing this?
    I need to secure every channel on the server with a wildcard SSL certificate.
    Thanks...

    Hi Gordon,
    You can use the command line to generate your wildcard CRS.
    1. Launch /Applications/Utilities/Terminal.app
    2. At the prompt, type the following command:
    openssl req -new -newkey rsa:2048 -nodes -keyout yourdomain.key -out yourdomain.csr
    Replace yourdomain with the domain name you're securing. For example, if your domain name is coolexample.com, you would type coolexample.key and coolexample.csr.
    Common Name: The fully-qualified domain name, or URL, you're securing.
    If you are requesting a Wildcard certificate, add an asterisk (*) to the left of the common name where you want the wildcard, for example *.coolexample.com.
    See http://support.godaddy.com/help/article/5269/generating-a-certificate-signing-re quest-csr-apache-2x?pc_split_value=3

Maybe you are looking for

  • 8100 WITH NO SOUND

    Can anybody please help, I have a Blackberry Pearl 8100 and for some reason the speaker/sound has stopped working - as in, no call/email/text, daily alarm alert sounds, can I fix this or is the phone just 'broken'?  Obviously I have taken battery and

  • Combo Type UDF

    I have created a UDF in AR Credit Memo which is type of combo in line level matrix. how can i clear that combo box? have any one solution ? when i am trying to remove items from combo box the error message occuring "Iem - The Item is not a user defin

  • Have a transaction propagated to two remote machines!!!(URGENT!!!)

              Can we have a transaction propagated to two ejb's in different machines if we have database interaction in both?           I tested it out with Account beans (examples)           deployed on two different(remote) servers both servers having

  • Sun Chart component

    Hi, My name is Vikrant Abdagire. I am a SUN India employee. I am developing an application using JSP.In which i want to draw a pie chart. Is there any char component develpoed by SUN which i can be use to create a pie chart.I dont want to use third p

  • Auto-populate fields

    When I press the tab key on my keyboard while I am filling out fields in a Safari web page, the name, address, etc. fields automatically populate with my personal information. I have recently moved and the fields contain my old address, etc. How (Whe