Exchange (Multirole + Edge) and certificate from local CA.

Pawel Jarosz 61 Reputation points
2021-03-19T13:50:17.307+00:00

Hi Everyone,

I am setting up certificates in really simple on-prem environment - 2 servers: 1st - multirole (no mailboxes, just for simple relay and O365 management), 2nd - edge role.

Everything works when I generate certificate directly in Exchange, however when trying to use the certificate from the local CA emails are stuck in the queue on multirole server. The root certificate is added to the trusted root store on the edge server. I do not really have any more ideas on what can be done, what I've done was:

  1. Generate new subscription file on edge
  2. Enabled local CA certificate on multirole server for all the services (IIS,SMTP,POP,IMAP)
  3. Imported build new subscription on multirole server based on the subscription file
  4. Started the synchronization
  5. Rebooted the servers

Synchronization seems to be ok - got susscesss state, however messages sit in the queue on multirole server with no willingness to go to the edge server, any ideas what step do I miss?

Cheers,
J

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management
The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2021-03-22T06:50:44.773+00:00

    Hi @PawelJarosz-0356 ,

    Please first check the OWA and EAC(ECP), if they are good then we could bypass the cert.
    And what does the multirole means? Mailbox + ClientAccess? What's your Exchange server, is it 2013? And have you added the CA certificate to the trusted root store on Multirole server?
    Sorry I don't know how you sent the emails without mailboxes. Please share more info so we can know this issue better.

    Regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.