Exchange Server 2016 UCC certificate

raj a 316 Reputation points
2021-09-13T13:34:48.36+00:00

Hi,

Greetings.

Our Exchange UCC cert (Multiple alternative names are included in the cert) is going to be expired in 15 days but I have renewed & installed the new cert on server & also assigned services like IIS,POP,IMAP & SMTP to it.

But that old certificate is still valid & I can see IIS,POP,IMAP & SMTP services also still checked in that certificate & can't deselect those services from that certificate.

I checked by accessing ECP console & found the new SSL certificate over there (In address bar) but in SMTP receive logs I can still see the OLD cert is in used.

How can I fix this? what will happen when my OLD cert is expired in this scenario?

Thanks in advance.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,438 questions
{count} votes

2 answers

Sort by: Most helpful
  1. raj a 316 Reputation points
    2021-09-17T12:41:27.737+00:00

    It has been fixed, I needed to set the new TLS certificate to Send & Receive Connectors where the old certificate was attached.

    2 people found this answer helpful.

  2. Jade Liang-MSFT 9,961 Reputation points Microsoft Employee
    2021-09-14T03:04:20.987+00:00

    Hi @raj a ,

    but I have renewed & installed the new cert on server & also assigned services like IIS,POP,IMAP & SMTP to it

    How did you renew and install your certificate? By those steps as the official document mentioned or others? We recommend you follow the steps above to renew your certificate.

    found the new SSL certificate over there (In address bar)

    Do you mean you could find the new certificate in your certificate list? If so, what's the status of your new certificate? Please ensure that your certificate is valid after you complete the renewal.

    In order to further ensure the services were assigned normally, we could try to re-assign them via EAC or Exchange management shell as the document mentioned to check if the issue has any difference after that.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments