Use an existing certificate (we already own) on a Exchange server

This has to do with certificates and email - so I'm uncertain whether it should go in the security section (here) or in one ofthe Exchange forums... (?)
Anyway, here we go...
Usually I create a certificate request for the Exchange server on the Exchange server itself, submit the request and when the certificate is available, install the certificate and enable it.
What if an organization already has a wildcard certificate for its web servers...
What obstacles would prevent it from being used on an Exchange server?
The certificate is for "server authentication" - but probably not email (I know there are different certificate "types", "roles" or "templates" that may come into play here).
I was not involved in the purchase of the certificate, so I'm not sure if there is a maximum number of servers on which it can be used, or other legal considerations. That is something that must be taken into account all the same.
But from a technical standpoint, what would prevent a certificate (that can be exported, says the team involved in its acquisition) from being exported and imported to the Exchange server?
Getting a certificate specifically for the Exchange server might make more sense (I'm certainaly more familiar with that option) but would the situation above even be feasible?
One last note: there might be a migration to Exchange Online in the future.
Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

On Thu, 27 Mar 2014 16:30:40 +0000, David M (LePivert) wrote:
What if an organization already has a wildcard certificate for its web servers...
What obstacles would prevent it from being used on an Exchange server?
After reading your post, one of the Exchange forums would be a better place
to post it.
Thanks.
Paul Adare - FIM CM MVP
Systems programmers are the high priests of a low cult. - R. S. Barton

Similar Messages

  • Signing a document using an existing certificate

    Hi, I've been searching for APIs to digitally sign documents.
    I've successfully signed documents using Keystore and KeyPairGenerator (both of them work), but I haven't been able to use an existing certificate (a .cer file) to sign a document.
    Can anyone help me with this?
    An example code of signing a document using (for example) a certificate stored in myCertificate.cer would be really helpful.
    Thanks
    Juan Ignacio.

    Ok, here's what I've got:
    myCert.cer (certificate)
    myKey.pfx (PKCS12 keystore)
    With this two files I should be able to get the private key (from myKey.pfx), the public key (from the certificate)... and use this to sign the document.
    Can anyone help me to do that? (in Java Code)
    I'll apreciate any help...
    Juaris.

  • Webdispatcher use of existing certificate

    Hi guys,
    we are still runnig iis with reverseproxy (old portal EP6) on a gatewayserver in the dmz. Now we want to use the same server for webdispatcher on a different port (parallel for NW04s Portal). For http it works fine. But we want to run (terminated) https and want to use our "old" certificate from verisign (its still used for the reverseproxy and still valid).
    I only find description and helps with information of how to generate a pse for a certificate request but not of how to use my old valid certificat. How can i import my old certificate into the pse?
    Regards Frank

    Hello Frank,
    You can import the Certificate into your SAP system via T-Code STRUST.
    On SAP J2EE Portal you can import the certificate via ....
    First login to the portal at .....
    http://HOSTNAME:HTTPPORT/irj/portal
    then go to System administration --> system configuration --> Key Store.

  • Is there a way to use Apple Mail/Address Book/Calendar with a Microsoft Exchange Server that requires a client certificate ?

    I have an Exchange server configured to require a client certificate. Is there a way to configure a certificate for Apple Mail/Address Book/Calendar ? There seems to be no option in the account settings to do that (in contrast to for example the IMAP settings).
    Any help highly appreciated !

    I don't know. Try downloading the certificate and installing it in your keychain. See what happens.

  • How to use an existing certificate for the ABAP SSL setup using STRUST

    Hi
    All the documentation say to Create certificate Request and subsequently import the Certificate response from a CA.
    In our case, the company has a certificate from a valid CA root and we would like to use this when creating the SSL PSE files, in particular, the SSL Server PSE.
    Should I use sapgenpse instead of strust??
    What are the steps to apply the certificate (www.company.com.au) to this instance (host.dom.internal)??????
    Thanks
    Doug

    Hi Dough,
    pls chk out this for SSL certificate
    http://help.sap.com/saphelp_nw04/helpdata/en/20/37c33ae8361838e10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/20/37c33ae8361838e10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/16/1bb23bdb0d0156e10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/16/1bb23bdb0d0156e10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/c1/96b13b6e95b72ce10000000a114084/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/c1/96b13b6e95b72ce10000000a114084/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/e1/b6b13bd0ac933ae10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/e1/b6b13bd0ac933ae10000000a11402f/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/aa/a8463c6796e61ce10000000a114084/frameset.htm
    pls reward points
    Thanx
    Metha

  • How to use ipod touch when I already own an iphone on one computer?

    I have a dilemma. when I try to setup my brand new ipod touch I got for xmas, it says i must setup it up as new device or restore from backup. the problem is I use this computer to sync to my iphone 3gs.
    itunes wont let me sync to an ipod touch and an iphone on the same computer, its one or the other.
    if i choose to setup as new device, then when I sync my iphone it says itunes is synced to another device and must wipe my iphone clean or restore from backup???
    how do i use itunes so I can put movies n music on my ipod touch without it affecting my iphone?

    "Note: iTunes for Windows does not support syncing multiple iPod devices at the same time."
    exactly what do they mean when they say at same time? like i can not connect one device, sync it then connect another device and sync that one??
    hence my dilemma. this is from that link i read.
    i tried this and itunes fails
    what a terrible dilemma, sigh
    i connect the ipod touch and tell it to setup as new device.
    i sync some movies and playlists.
    easy enough
    then i connect my iphone...guess what? it says this is a new device, would you like to setup as new or restore from backup!!!
    if i restore from backup it puts the ipod touch playlists and all my contacts are gone
    it seems the only way to do this is, from reading that link, to create a new user in windows, and use this new user profile to manage ipod touch.
    so now i'm gonna have to siwtch back and forth between 2 windows accounts.
    what a royal pain in the butt
    why can't itunes just let me sync what i want to the device and not care what it has, so i can just add regardless if new or not.
    god i hate itunes.
    Message was edited by: ninja_pimp

  • PI own ps 6, have discontinued ps cc. now I can't use ps 6 which I already own. I'm on deadline and am not loving adobe for all this nonsense

    please adobe, just let me use my software. I've purchased every single ps product since ps 2, and am hating you right now.

    This is a user to user Forum, so you are not really addressing Adobe here, even though some Adobe employees thankfully have been dropping by.
    Do you have a Photoshop CS6 perpetual license?
    What exactly happens or does not happen?
    Please read these and proceed accordingly:
    http://blogs.adobe.com/crawlspace/2012/07/photoshop-basic-troubleshooting-steps-to-fix-mos t-issues.html
    http://forums.adobe.com/docs/DOC-2325

  • PKI setup using 3rd party certificates

    I want to configure SCCM in our environment using are existing certificate creation infrastructure. I do not want to use Microsoft Certificate services. Instead I'd rather use our OpenSSL solution. However I cannot find good documentation to work with using
    3rd party certificates. Everything is related around Microsoft's certificate services.
    Has anyone had any luck implementing SCCM in this manor? Documentation available to aid?

    So we are planning to setup https across the board and going through the blogs and TechNet article - I see that internal PKI is a requirement and you just cannot do away with 3rd party/external certificate, correct ??
    I am working on a scenario where the customer does not want to implement internal PKI but use external certificate either by GoDaady or Thawte or VeriSign where possible at all times but looks like you can't use the external certificate to act as ConfigMgr
    Web Certificate or ConfigMgr DP Cert?
    given the following scenario
    https://social.technet.microsoft.com/Forums/en-US/ac34ebdf-c932-4075-b4a3-ebe572ffab0e/scenario-multi-tenant-configmgr-2012-r2-and-same-ip-address-range-for-multiple-customer?forum=configmanagerdeployment#868600a8-e8eb-471a-b767-761305636041
    for clients to communicate to DP's/Secondary Sites configured in HTTPS, we still need internal PKI ?
    I guess the answer is yes to all.. but just confirming :)

  • Communicator is looking to incorrect exchange server for security certificate

    We are running Exchange 2010 and retiring a 2007 Exchange server. They are both still on our network but all mail routes through the 2010 server. The ssl certificate on our 2007 server expired today and Communicator is coming up with a warning when launched
    warning that the 2007's cert expired. How do I get communicator to use the 2010 certificate instead? 

    Where do your Exchange autodiscover records point?  Are all users on Exchange 2010?
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • Exchange Server Affected by SSL Certificate Organization Name Change

    We recently underwent a name change of our company. We added a few new domain names for the new company to our Exchange Server 2007 and updated our address policy to include them and everything seemed to work okay for a while.  We subsequently reissued
    the SSL Certificate for our Exchange Server under the new organization name (per the CA's recommendation) .  Shortly thereafter we experienced all sorts of issues necessitating a rebuild of our Exchange Server.  Is there any dependency between
    the organization name in an SSL certificate and the organization name that Exchange Server stores it's info under in Active Directory (which still had the old name) that would cause Exchange to go haywire?

    Hi,
    Please confirm you were creating a new domain in your AD or creating an accepted domain in Exchange server.
    If you directly create an accepted domain in Exchange, the new domain would be
    considered authoritative when the Exchange organization hosts mailboxes for recipients in this SMTP domain. We don’t need to create a new Exchange certificate for this new accepted domain because the
    SRV records can be used to connect to Autodiscover service. And the Exchange services URLs are not changed and they can still be authenticated by the original certificate (mail.domain.com, autodiscover.domain.com).
    Certainly, we can reissue a new Exchange certificate, please make sure the new Exchange certificate has included all needed namespaces for your Exchange server such as:
    Mail.domain.com, autodiscover.domain.com, autodiscover.newdomain.com
    We can also run Get-ExchangeCertificate | fl to check it.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Trying to go from Entourage to Apple Mail using Exchange Server

    I am currently using Entourage and successfully connecting to my company's Exchange Server. I am sick of how Entourage wraps text and poorly handles HTML emails, and a host of other annoyances. However, I cannot for the life of me get Mail to work with my Exchange Server. The input fields on the account setup are not the same between Entourage and Mail. Any pointers would be much appreciated. Thanks.

    Same goes for me. I know IMAP is not enabled. Entourage WORKS within my workplace network but mail.app will not. Entourage is OK using IP addresses like 10.1.1.30 where mail.app doesn't know what to do with them. Again, all this is within the workplace network. Outside the network, Entourage does not work and all I have to use in Outlook Web Access. I am fine with the inside-outside situation. I just would like a workaround to be able to use my mail.app within my workplace Exchange environment.

  • Both my kids iPads are using my Apple ID if I give them both their own will they loose the existing apps they already have on their iPads?

    Both my kids iPads are using my Apple ID if I give them both their own will they loose the existing apps they already have on their iPads?

    Apps on a device are forever associated with the Apple ID that was used to purchase or download them. If the Apple ID on a device is changed the apps acquired with the original Apple ID will require that original Apple ID and password to be updated.
    My suggestion would be to erase your kids' iPads and set them up new, each with their own Apple ID. Then turn on Family Sharing with you as the Organizer. This will allow any of the Family members to share apps as long a those apps allow Family Sharing. Turn on Family Sharing in the Settings app.
    Settings > iCloud > Family

  • I already own iWork, and do not want to have to pay for it again,  How do I get the installer using my existing licence

    I already own iWork, and do not want to have to pay for it again,  How do I get the installer using my existing licence.  It will not migrate from one computer to another, perhaps because of the recent system upgrade.

    How did you pay for it?
    Through the Mac App Store or as alicence for a DL?
    Peter

  • If I already Own LR 5 and Elements 12, how will my subscription to Photoshop CC effect my existing programs?

    If I already Own LR 5 and Elements 12, how will my subscription to Photoshop CC effect my existing programs?

    No effect on your existing licenses,if you cancel your subscription some day ,you can use your licenses .

  • This email address is already in use or you may already have an Apple ID associated with this email address. Please try again or sign in using your existing Apple ID.

    My current Apple ID, for which all of my content has been downoaded (e.g., music, apps) is associated with a work email address that I will no longer have access to in the near future.  In my Apple ID account, I noticed I had two alternate emails listed, one is my .me account and the other is my .gmail account.  I use my .gmail account, and it is the primary email I use with friends and family.  I noticed both were not verified, and when I tried to, it said they were both associated with other accounts.  I was able to log into a separate Apple ID account I must have set up at tone point with my .gmail, and I changed the email address to a new one I created.  I also deleted the gmail account from any other Apple-relted account I could think of.  I am still gettgin the same error message when I try to add it to my current Apple ID: "This email address is already in use or you may already have an Apple ID associated with this email address. Please try again or sign in using your existing Apple ID."
    My concern is this: with FaceTime and now iMessage, it seems more important than ever that I am able to use my correct email address.  With iOS5 beta, I cannot enter either my .gmail or.me accounts under "You can be reached for messages at:" as I get an error stating: Unable to verify email because it is already in use."
    How can I remedy this issue and assign my .gmail account to my Apple ID?

    Re: Cant verify Apple ID
    created by kelly218 in iTunes Store - View the full discussion
    I just spoke with a technician at Apple.  I hsven't been able to verify because the wife has the phone.  but he said all that you need to do is:
    1) Go to Settings --> iTunes Store and login with your Apple ID and pwd
    2) Go to Settings --> iCloud and login with your Apple ID and pwd
    seems that the phone requires you to login to the store first...

Maybe you are looking for