1) Log on to the Exchange server as a domain administrator.
2) Open the Exchange Management Console and select Server Configuration---New Exchange certificate.
650) this.width=650; "title=" clip_image002 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image002 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiom1elis7igpqcaadbdfghnfa008.jpg "" 644 "height=" 337 "/>
Enter the certificate name "Mail.lsx.com", Next
650) this.width=650; "title=" clip_image004 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image004 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiol1elis-coqspaacshmhodc0483.jpg "" 580 "height=" 484 "/>
Do not enable "Start a wildcard certificate", the next step
650) this.width=650; "title=" clip_image006 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image006 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiom1elitdqjwmxaacsqdplcka512.jpg "" 593 "height=" 484 "/>
Tick the option and then next.
650) this.width=650; "title=" clip_image008 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image008 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiol1elitdte3ydaaedlvtinjo296.jpg "" 644 "height=" 460 "/>
650) this.width=650; "title=" clip_image010 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; margin:0px; padding-right:0px "border=" 0 "alt=" clip_image010 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1elitgi9nusaaa2mx0emwk776.jpg "" 244 "height=" 174 "/>
Set the common name to "mail.lsx.com", and then next.
Note: If there are other extranet addresses, be sure to select Add to add the extranet address or other ex servers to the certificate domain.
650) this.width=650; "title=" clip_image012 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image012 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiol1elitlx0obfaacmpj7kr2k880.jpg "" 598 "height=" 484 "/>
Enter the organization and location information, and then select the certificate holding path is "C:\ca" and the name is "Exchange.reg" and the next step
650) this.width=650; "title=" clip_image014 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image014 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiol1elitoankhvaaed1mek8ng727.jpg "" 639 "height=" 484 "/>
Select New to create a new certificate.
650) this.width=650; "title=" clip_image016 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image016 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiom1elitsxhtgsaadnzmhrpmi824.jpg "" 644 "height=" 459 "/>
No problem done
650) this.width=650; "title=" clip_image018 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image018 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1elitwg20ipaaea0wvzbs0716.jpg "" 586 "height=" 484 "/>
Open IE, in the Internet Explorer address bar, enter the Web page of the CA request, request a certificate
https://Certificate Server address/certsrv
650) this.width=650; "title=" clip_image020 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image020 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiol1elitayyvxzaadgy21eslm139.jpg "" 644 "height=" 445 "/>
Select "Request a certificate"
650) this.width=650; "title=" clip_image022 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image022 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiom1elitbqckktaacewxmuq9a181.jpg "" 644 "height="/>
Select "Advanced Request Certificate"
650) this.width=650; "title=" clip_image024 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image024 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1elitfzjnczaabwluhw3v4641.jpg "" 644 "height=" 203 "/>
Select "Use base64 encoding"
650) this.width=650; "title=" clip_image026 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; margin:0px; padding-right:0px "border=" 0 "alt=" clip_image026 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiom1elitjdckwzaaayqbwsuta241.jpg "" 244 "height=" "/>
Use Notepad to open the file C:\ca\exchange.req file you just exported and copy the blue font text down
650) this.width=650; "title=" clip_image028 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image028 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiol1elitmzp3qlaaevczpiwu4538.jpg "" 644 "height=" 303 "/>
Copy the text content of the certificate request file, then select [Web Server] from the [Certificate template] drop-down menu and click the [Submit] button.
650) this.width=650; "title=" clip_image030 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image030 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiol1elitrixcptaactinakcae208.jpg "" 644 "height=" 336 "/>
Web Access Confirmation
650) this.width=650; "title=" clip_image032 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image032 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiom1elitvhswcyaacaivo-rvc136.jpg "" 644 "height=" 257 "/>
When you click Submit, the page appears, select the DER encoding option here, and then click the Download Certificate option. A dialog box prompts you to enter the location where you want the certificate file to be stored in the C:\certnew.cer
650) this.width=650; "title=" clip_image034 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image034 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiom1elitvzikdnaabtjv4izrq053.jpg "" 644 "height=" 217 "/>
Next, we go back to the Exchange Management Console interface, in the Server Configuration node, select the new certificate project that you just newly created, and choose "Complete shelve request" in the actions window to continue as shown in:
650) this.width=650; "title=" clip_image036 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image036 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1elitzwbzhdaacf3wrlufu073.jpg "" 644 "height=" 308 "/>
After you open the complete Shelve Request Setup Wizard, browse to open the new certificate file that you just saved, as shown in
Select Done
650) this.width=650; "title=" clip_image038 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image038 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiol1elit3j6p6oaackiwsmrjw199.jpg "" 587 "height=" 484 "/>
Complete the Import
650) this.width=650; "title=" clip_image040 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image040 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiol1elit7q61ppaac54r2raks458.jpg "" 582 "height=" 484 "/>
View Certificate Status
650) this.width=650; "title=" clip_image042 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image042 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiol1elit6zbimwaabxmacfpce132.jpg "" 644 "height=" 133 "/>
Open the Exchange Management Console, select Server Configuration---Exchange certificate, right-click the Exchange certificate, and select Assign service for certificate.
650) this.width=650; "title=" clip_image044 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image044 "src=" http://s3.51cto.com/wyfs02/M02/84/45/wKioL1eLIT_ Degdvaab2s6fkq4c723.jpg "" 644 "height=" 249 "/>
The Setup Wizard to assign services to certificates appears, confirming that the Exchange Server 2010 server that is ready to assign the service to the certificate has joined
650) this.width=650; "title=" clip_image046 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image046 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1eliudwrbceaacwwuwjboo805.jpg "" 585 "height=" 484 "/>
In the Assign service interface, tick all service items that will be used to the certificate, in this case the Unified Messaging service is not used, there is no choice to create the certificate earlier, and there is no need to select Unified Messaging.
650) this.width=650; "title=" clip_image048 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image048 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiol1eliudtgtm9aacgtvckgjs144.jpg "" 644 "height=" 443 "/>
Select Assign.
650) this.width=650; "title=" clip_image050 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image050 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiol1eliugbfiwaaacxl4mhkm4882.jpg "" 598 "height=" 484 "/>
Tip "Overwrite existing Default SMTP certificates" and select "All Is." Note: When the exchange2010 installation is complete, a certificate is automatically generated that asks whether to overwrite exchange2010 to generate the certificate automatically.
650) this.width=650; "title=" clip_image052 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image052 "src=" Http://s3.51cto.com/wyfs02/M02/84/45/wKioL1eLIULTHdJEAADXU _s0yyo434.jpg "" 644 "height=" 479 "/>
Select "Finish"
650) this.width=650; "title=" clip_image054 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image054 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiol1eliuojsf2uaacxanlykdq188.jpg "" 588 "height=" 484 "/>
Remove invalid certificates and Exchange self-signed certificates
650) this.width=650; "title=" clip_image056 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image056 "src=" http://s3.51cto.com/wyfs02/M01/84/45/ Wkiol1eliutd92kyaabh2yp8xtm042.jpg "" 644 "height=" 199 "/>
The test certificate is valid, the browser enters Https://mail.lsx.com/owa, and no longer prompts for the certificate error.
650) this.width=650; "title=" clip_image058 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image058 "src=" http://s3.51cto.com/wyfs02/M02/84/45/ Wkiom1eliusz73fvaadewu_sgri256.jpg "" 644 "height=" 470 "/>
650) this.width=650; "title=" clip_image060 "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image060 "src=" http://s3.51cto.com/wyfs02/M00/84/45/ Wkiom1eliuwavflhaadevbow6um111.jpg "" 644 "height=" 282 "/>
Deployment exchange2010 Triad: Eight: Request a certificate