A pubblic certificate is needed to test a connector?

Marc 631 Reputation points
2021-08-07T17:39:18.453+00:00

I am trying to setup a M365 outbound connector with the corresponded one on the on-prem exchange 2010 inbound. I am using a public IP (not associated to a CA) but I am receiveing erros evaluating it.
I read some documents on that argument and it seems is needed (not confirmed) to use a TLS securty option associated with a pubblic certificate to make it works.
Do I really need - mandatory- use a public certificate if I want to test a connector?

What is the best way to test a connector then?

Thanks

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Exchange | Hybrid management
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 158K Reputation points MVP Volunteer Moderator
    2021-08-07T21:40:00.417+00:00

    a third party cert is not needed if this is not a hybrid connection.

    You can buy a 3rd party cert anywhere though.

    Follow this for an example from Digicert. You can use the Exhcange 2013 guide - it still applies
    https://www.digicert.com/kb/exchange-ssl-certificate.htm

    0 comments No comments

10 additional answers

Sort by: Most helpful
  1. KyleXu-MSFT 26,396 Reputation points
    2021-08-09T02:02:24.577+00:00

    @Marc

    Are you using a hybrid environment?

    If you aren't using a hybrid environment, you could create send connector without a trusted CA certificate. Try to modify send connector connector to:
    121522-qa-kyle-09-58-45.png
    121503-qa-kyle-10-03-44.png
    121502-qa-kyle-10-03-30.png
    121430-qa-kyle-10-05-30.png
    Indeed, if you aren't in hybrid, you don't need to create any send connector, Exchange online could send email to Internet without send connector.

    If you are using a hybrid environment, a trusted CA certificate is needed. You don't need to create connector manually, just need to run HCW, this program will configurate connector for your directly.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Marc 631 Reputation points
    2021-08-09T11:43:11.443+00:00

    About hybryd.

    If users will be added to on-prem to M365 (AD Azure connect) can I consider we are in Hybrid mode?

    The validation has been solved removing from bothend the TLS security.

    QUESTIONS: This setting worked because we are not in hybrid mode or because uncheck TLS we don't need a certificate (even we are in hybrid)?

    Thanks


  3. Andy David - MVP 158K Reputation points MVP Volunteer Moderator
    2021-08-09T11:47:18.92+00:00

    No, hybrid mode is when you have run the hybrid wizard and you require mail flow between on-prem and Exchange Online mailboxes to be treated as trusted.
    As I mentioned above, that requires a third party certificate

    0 comments No comments

  4. Marc 631 Reputation points
    2021-08-09T12:20:30.847+00:00

    Thank you.

    then we are not in hybrid mode as the mailboxes are on-prem and not moved to Exchange Online. We moved all users to use some service as Teams and we are implementing EOP antispam.

    Probably this is why it worked in that way.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.