Multiple certificates on Exchange 2019 server

FNU LNU 21 Reputation points
2021-10-25T19:57:05.83+00:00

At the moment, one servtificate has been installed, which contains all domain names for the excahgne server and for other services using this certificate.

We would like to simplify this certificate and issue a cheaper one.

The server now has a certificate for the following domain names:

smtp.domainA.com
mail.domainA.com
autodiscover.domainA.com
exchange01.domainA.com

siteA.domainA.com
siteB.domainA.com
siteC.domainA.com
othersiteA.domainA.com
othersiteB.domainA.com
othersiteC.domainA.com

autodiscover.domainB.com this is SRV record -> mail.domainB.com
mail.domainB.com this is CNAME record -> mail.domainA.com

autodiscover.domainC.com this is SRV record -> mail.domainC.com
mail.domainC.com this is CNAME record -> mail.domainA.com

autodiscover.domainD.com this is SRV record -> mail.domainD.com
mail.domainD.com this is CNAME record -> mail.domainA.com

So there is no sense to have such a certificate, if I'm right, one wilecard *.domainA.com certificate will be enough.

Hmm, users will get an error like untrusted cetificate becouse it will not contain autodiscover.domain Bcom, autodiscover.domain.com, autodiscover.domainD.com :( what can I do in this case?

Thank you.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,332 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 141K Reputation points MVP
    2021-10-25T21:26:59.653+00:00

    Its just one certificate, some Cert Authorities issue those.
    I wouldnt do that though. I would just have a regular SAS Certificate with the all the subject names needed.

    You probably dont need:

    smtp.domainA.com ( You can set the connector FQDNs to mail.domaina.com

    and you probably dont need:

    exchange01.domainA.com

    2 people found this answer helpful.

3 additional answers

Sort by: Most helpful
  1. Andy David - MVP 141K Reputation points MVP
    2021-10-25T20:22:54.057+00:00

    That wont work.
    You need a cert with subject names that cover:

    Clients will connect to the CNAMEs.

    mail.domainB.com
    mail.domainC.com
    mail.domainD.com


  2. Andy David - MVP 141K Reputation points MVP
    2021-10-25T21:14:50.85+00:00

    If the autodiscover record is:
    mail.domainB.com/autodiscover
    mail.domainC.com/autodiscover
    mail.domainD.com/autodiscover

    then you need

    mail.domainB.com
    mail.domainC.com
    mail.domainD.com

    I would also add the domainA.com records if they are needed
    You can have a Wildcard + SAN Certificate, but that may be pretty expensive


  3. Andy David - MVP 141K Reputation points MVP
    2021-10-26T11:50:15.24+00:00

    Yes, I would go wit that :)

    0 comments No comments