Question : Renewal of SSL Certificate for webmail

my exchange webmail ssl certificate is getting expired next week. im presently using IPSca certitifcate, but i don't want to renew the same authority. infact i want to renew with verisign.

my question is that , if i generate new CSR (not renewal) for same subdomain to have certificate from different certificate authority (not IPSca) , will i have any issue with my webmail during wait time (i.e generating CSR and receipt of Certificate from certificate authority) as i understand maybe it will take day or two for the process.

Will my webmail have any missing certificate during this wait time? can my existing IPSca certificate will be valid till its expiry?

Answer : Renewal of SSL Certificate for webmail

You will need to generate the request somewhere.
If you use the existing site that will mean the current certificate will have to be removed, and left off until the certificate request arrives. You cannot do the request then put the old certificate back.

The usual method is to create a second site in IIS manager, using another port. Run the request and response through that. Once complete you can then run through the Default Web Site and choose to remove the existing certificate and then replace it with another existing certificate (because your new certificate is in place).

Although I wouldn't use Verisign unless you are getting a massive discount. Overpriced in my opinion. When you can get a certificate with almost the same level of acceptance for US$30/year, paying Verisign's prices to protect Exchange is madness.

Simon.
Random Solutions  
 
programming4us programming4us