Multiple SSL certificates on Exchange 2010 with single IP?

Discussion in 'Software' started by thernes, Oct 10, 2011.

  1. thernes

    thernes New Member

    4
    0
    1
    Hi all

    We are hosting an Exchange 2010 server for a client and now this client has contacted us and wants to move all of his 400 email-users over to us. Currently, this client only has one domain hosted on the server and is using a UC SSL certificate and this is working just fine. My question is what do we do when he wants to move 8 more domains over? Is it possible for us to install 1 certificate per domain on the server, without having a dedicated IP per SSL?

    Any help will be highly appreciated.

    Thanks.

    Thomas
     
  2. Theprof

    Theprof Petabyte Poster

    4,607
    83
    211
    I believe you might be able to use something like a wild card certificate....
     
    Certifications: A+ | CCA | CCAA | Network+ | MCDST | MCSA | MCP (270, 271, 272, 290, 291) | MCTS (70-662, 70-663) | MCITP:EMA | VCA-DCV/Cloud/WM | VTSP | VCP5-DT | VCP5-DCV
    WIP: VCAP5-DCA/DCD | EMCCA
  3. dales

    dales Terabyte Poster

    2,005
    51
    142
    *.com :biggrin

    I guess it depends if they are sub domains or not?
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing
  4. thernes

    thernes New Member

    4
    0
    1
    No. These are "regular" domains and not sub-domains.
    I have read about the possibility of using host headers and 1 wildcard certificate, but I would actually prefer, if possible, to have the certificate report the actual domain it was used on, instead of using host headers and redirecting the domains.
     
  5. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Why do you need a certificate for each domain?

    In answer to your question you would need one IP address per SSL cert.
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  6. thernes

    thernes New Member

    4
    0
    1
    As far as I know, it is only possible to have one common name per certificate and if you use UC certificates, you can then add sudomains and internal domain names and IP's

    Roger that
     
  7. craigie

    craigie Terabyte Poster

    3,020
    174
    155
    If you are hosting there domain then I would hope that you know that you can have oudles of sub domains and one primary domain.

    You then only need a SAN SSL for the primary domain to work with Exchange 2010 for example I could have the following:

    craigie.com (Primary)
    craigie.co.uk
    craigie.biz
    craigie.org

    You would still recieve emails from the other domains but when you reply, it would come from craigie.com unless otherwise specified on the individuals malibox policy.

    Also, end users would go to https://mail.craigie.com/owa to access emails and setup iPhones etc.
     
    Certifications: CCA | CCENT | CCNA | CCNA:S | HP APC | HP ASE | ITILv3 | MCP | MCDST | MCITP: EA | MCTS:Vista | MCTS:Exch '07 | MCSA 2003 | MCSA:M 2003 | MCSA 2008 | MCSE | VCP5-DT | VCP4-DCV | VCP5-DCV | VCAP5-DCA | VCAP5-DCD | VMTSP | VTSP 4 | VTSP 5
  8. thernes

    thernes New Member

    4
    0
    1
    Well, this is a rather large company and they own several smaller compaies, so all the smaller companies have their own domain names;

    E.g

    companyone.com
    anothercompany.net
    wejustboughtthiscompany.com
    shortcompany.com
    etc., etc.
     
  9. craigie

    craigie Terabyte Poster

    3,020
    174
    155
    Doesn't matter, same principal applies.
     
    Certifications: CCA | CCENT | CCNA | CCNA:S | HP APC | HP ASE | ITILv3 | MCP | MCDST | MCITP: EA | MCTS:Vista | MCTS:Exch '07 | MCSA 2003 | MCSA:M 2003 | MCSA 2008 | MCSE | VCP5-DT | VCP4-DCV | VCP5-DCV | VCAP5-DCA | VCAP5-DCD | VMTSP | VTSP 4 | VTSP 5

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.