Exchange (Multirole + Edge) and certificate from local CA.

Pawel Jarosz 46 Reputation points
2021-03-19T13:50:17.307+00:00

Hi Everyone,

I am setting up certificates in really simple on-prem environment - 2 servers: 1st - multirole (no mailboxes, just for simple relay and O365 management), 2nd - edge role.

Everything works when I generate certificate directly in Exchange, however when trying to use the certificate from the local CA emails are stuck in the queue on multirole server. The root certificate is added to the trusted root store on the edge server. I do not really have any more ideas on what can be done, what I've done was:

  1. Generate new subscription file on edge
  2. Enabled local CA certificate on multirole server for all the services (IIS,SMTP,POP,IMAP)
  3. Imported build new subscription on multirole server based on the subscription file
  4. Started the synchronization
  5. Rebooted the servers

Synchronization seems to be ok - got susscesss state, however messages sit in the queue on multirole server with no willingness to go to the edge server, any ideas what step do I miss?

Cheers,
J

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,495 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Xzsssss 8,861 Reputation points Microsoft Vendor
    2021-03-22T06:50:44.773+00:00

    Hi @PawelJarosz-0356 ,

    Please first check the OWA and EAC(ECP), if they are good then we could bypass the cert.
    And what does the multirole means? Mailbox + ClientAccess? What's your Exchange server, is it 2013? And have you added the CA certificate to the trusted root store on Multirole server?
    Sorry I don't know how you sent the emails without mailboxes. Please share more info so we can know this issue better.

    Regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.