Today we will look at How to create certificate for exchange 2010 servers using windows CA. (You can use this article for set up Active directory certificate server)
To Create certificate for exchange 2010 servers using windows CA follow steps below:
1. First we need to create certificate on TCAS1 server and then export that certificate and import to TCAS2 server.
To start certificate click on New Exchange Certificate…
2. Type name for certificate and click Next:
3. Click Next:
4. Select required checkbox and click Next:
5. Add required all domains to certificate and click Next:
6. On this page specify required information, browse place for certificate and click Next:
7. Check all configuration about certificate, if all OK then click New:
8. Click Finish to complete process:
9. Request file for certificate ready.
Saved location open file with notepad and Copy all content:
10. Open Certificate Web page and click on Request a certificate:
11. Click on advanced certificate request:
12. Paste copied content and select Web server under Certificate Template, then click Submit:
13. Download certificate.
14. Right-click on pending request on EMC and click Complete Pending Request…:
15. Select certificate file and click Complete:
16. Click Finish:
So certificate successfully created.
17. So now we need to export this certificate and import to another server, So right click on that certificate and click Export Exchange Certificate:
18. Browse place for certificate and type password for certificate, click Export:
19. Click Finish:
20. Select 2nd server and import that certificate:
21. Browse exported certificate and type password and click Next:
22. Click Next:
23. Click Import:
24. Click Finish to complete:
25. After that we need to assign services to certificate. To do that right-click on certificate(both servers) and click Assign Services to Certificate…
26. Click Next:
27. Select required services and click Next:
28. See configuration and Click Assign:
29. Click YES to ALL :
30. Click Finish:
As you see services assigned to certificate:
If you try open OWA services you can see no certificate warning shows: