SSL Cert/Exchange question

AFurryReptile

Golden Member
Nov 5, 2006
1,998
1
76
Hopefully a quick question here:

My company will be moving our Exchange server from one colocation provider to another in the coming month, and I am curious to know how this will affect the SSL certificate. My understanding is that SSL certificates from a root provider are created per-domain, and indeed we have it set up as such: mail.****.com, ****.com, autodiscover.****.com, and exch.local.

Because of this, all I should need to do is forward my domains to the new IP address, correct? There should be no need to re-key the cert? This will be the first time I have done such a thing and I would like to make the transition as smooth as possible.

Thanks for any help guys
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
The cert is tied to the fully qualified domain name, not the IP. You'll be fine cert wise.
 

Lithium381

Lifer
May 12, 2001
12,458
2
0
The cert is tied to the fully qualified domain name, not the IP. You'll be fine cert wise.

Be careful, you *CAN* tie a cert to an IP address, if you use that as the hostname/CN when getting it signed. . . which can cause some issues with trust
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Be careful, you *CAN* tie a cert to an IP address, if you use that as the hostname/CN when getting it signed. . . which can cause some issues with trust

LOL! Will the public cert authorities even allow you to? That would be dumb.
 

drebo

Diamond Member
Feb 24, 2006
7,035
1
81
LOL! Will the public cert authorities even allow you to? That would be dumb.

Probably not, but you could add an IP address to the SAN on a cert, similarly to how you'd add a non-public TLD. Either way, cert authorities will reissue SAN changes very easily.
 

Jamsan

Senior member
Sep 21, 2003
795
0
71
Don't forget to also export the private key(s) when exporting the certificates. Those will be required to decrypt the traffic on the new provider.
 

AFurryReptile

Golden Member
Nov 5, 2006
1,998
1
76
Don't forget to also export the private key(s) when exporting the certificates. Those will be required to decrypt the traffic on the new provider.

It's the same server, same cert provider. I'm literally just moving the the server from one location to another. Even the internal IP will stay the same.

And yeah, no IP addresses in my FQDN
 

Lithium381

Lifer
May 12, 2001
12,458
2
0
LOL! Will the public cert authorities even allow you to? That would be dumb.

Don't think i've ever tried with the big cert-houses . . . but I've run across this when people use an internal company CA or whatnot and accidentally type in the IP instead of the FQDN
 

AFurryReptile

Golden Member
Nov 5, 2006
1,998
1
76
Hey guys,

Sorry to bump but I have a second, related question:

I kindof inherited the server, but had to purchase a firewall and spam filter. My understanding is that since Exchange is already configured to use RPC, I should be able to simply forward port 443 to the server and client access won't be affected.

However, I believe that I will need to modify the send connector to point at the spam firewall on port 25, and the spam firewall outbound on port 25. Similarly, my receive connectors should accept mail from the spam firewall, which in turn is accepting mail from the outside (port 587 for client, 25 for default). I'm a little confused about this, because some things I've read lead me to believe that mail is received on 443 as well.

Hopefully this makes sense. If there are any ports I'm forgetting, or if I'm opening up too much, I'd appreciate any advice. Unfortunately, I do not currently have access to the firewall in use, so I can't just check the port mappings.

Thanks guys!

Edit: I should note that we are using Outlook Anywhere. So essentially, I need to forward port 25 inbound/outbound, 443 inbound for client access, and (possibly) 587 for the 'client' receive connector. Is this all?
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |