Ssl – Wildcard SSL Certificates with Exchange 2010

certificateexchangesslwildcard

Is anyone using a Wildcard Cert with Exchange 2010 please?

We currently have a bunch of individual whatever.domain.com SSL certificates and as several are expiring soon it would be an ideal opportunity to move to a wildcard certificate.

At some point though we will be moving from Exchange 2003 to Exchange 2010, and I've read conflicting reports over whether wildcard certs work with Exchange 2010 as many guides seem to recommend a UCC/SAN certificate.

Our internal DNS domain name is the same as our external domain name.

Godaddy look like good VFM given they allow use on unlimited physical servers.

Thanks in advance.

Best Answer

Certs and exchange 2010 are a headache from what I've seen so far.

We have 2010 in the lab right now and think we will be able to get away with a wildcard SSL cert for device access from the internet, and then an Enterprise CA signed machine cert (Issued by ADCS), for each 2010 server for internal access.

We are using TMG 2010 as an edge transport server, so the SSL cert will sit on there, then the connection between TMG and Ex2010 CAS will be inside the domain, so secured by the Enterprise CA.

Only got this working this morning, but I think that will work. If your CAS is handling connections from the internet then ymmv. I'll be watching this question though!