Natalia Merzlyakova - Fotolia
An expired Exchange certificate can bring your messaging platform to a halt, but it's easy enough to check and replace the expired certificate.
When mail stops flowing, Outlook access breaks and the Exchange Management Console/Shell gives errors, then it might be time to see if an Exchange certificate renewal is in order.
Exchange adds a certificate by default with your protocols during its installation, including Simple Mail Transfer Protocol and Internet Information Services (IIS). Many companies do not allow access to Outlook on the web, so mail is only accessible internally. This limits the Exchange Server capabilities as Microsoft designed it to be accessible from anywhere on any device.
For companies that choose to limit Exchange's functionality, the IT staff often opts to use the default certificate, which has a five-year life span. In five years, IT might forget about the Exchange certificate renewal until they receive countdown emails warning that it will expire. If nobody sees these emails and the certificate expires, then problems will start, as Exchange services that require a valid certificate might not work.
To check a certificate's status, run the following PowerShell command:
Get-ExchangeCertificate | fl
Assign a new certificate for Exchange 2010
If Exchange breaks due to an expired certificate, then you might want to push for a quick fix by issuing a certificate to an internal certificate authority. This won't work because the certificate authority will not sign the certificate.
If you start to panic as help desk tickets start to flood in, this is when trouble typically happens. You might try to adjust the settings in IIS, but this can break Exchange. However, the fix is simple.
Run the New-ExchangeCertificate command to initiate the Exchange certificate renewal process. This PowerShell cmdlet will create a new self-signed certificate for Exchange 2010. The command prompts you to replace the existing certificate. Click Yes to proceed.
Next, assign the services from the old certificate to the new one and perform an IISReset from an elevated command prompt to get Exchange services running again.
Finally, ensure the bindings in IIS are set to use the new certificate.
Dig Deeper on Exchange Server setup and troubleshooting
Related Q&A from Edward van Biljon
Exchange Server log files tend to chew up a lot of space, particularly on the later versions. Here's how to keep the mail flowing when a hard drive ... Continue Reading
When applying security updates or cumulative updates to Exchange Server, it's important to take your time and use maintenance mode to avoid ... Continue Reading
Microsoft changed its release model after Exchange 2010, which has caused some confusion for administrators who work on newer versions of the ... Continue Reading