1.生成新證書請求
New-ExchangeCertificate -GenerateRequest -DomainName mail.abc.com, autodiscover.abc.com, ex2k7.abc.local, autodiscover.abc.local -Path c:\certreq.txt -PrivateKeyExportable $true
注:紅色字體替換自己實際企業(yè)的DNS主機名稱
2.把生成的certreq.txt在企業(yè)自己的證書機構申請證書(如:http://dc01.abc.local/certsrv)
注:在saved request中,在certificate template中選擇web server,點擊submit,選擇Base 64 encoded,點擊download certificate,生成certnew.cer
3.導入證書
Import-ExchangeCertificate -path c:\certnew.cer
4.查找指紋
Get-ExchangeCertificate | fl
查看里面的thumbprint參數(shù)
5.啟用證書
enable-ExchangeCertificate -thumbprint 6B6A7C9A2661D3D2BA40DDBFF724DC998A8A71B5 -services "IIS,SMTP,IMAP"
注:紅色字體替代之前看到的thumbprint參數(shù)
New-Exchangecertificate -generaterequest -path c:\certrequest.txt -domainname <公網FQDN>, <Exchange的內部FQDN>, <Exchange2007的NETBIOS名>, autodiscover.domain.com, autodiscover.domain.local, autodiscover, domain.com, domain.local -PrivatekeyExportable:$True -force
例如,您公司的公網FQDN為"mail.contoso.com", 內部EXCHANGE2007服務器的FQDN是"server.contoso.local" NetBIOS名是"server". 上述命令即為:
New-Exchangecertificate -generaterequest -path c:\certrequest.txt -domainname mail.contoso.com, server.contoso.local, server, autodiscover.contoso.com, autodiscover.contoso.local, autodiscover, contoso.com, contoso.local -PrivatekeyExportable:$True -force
通過執(zhí)行此條命令,即為mail.contoso.com申請了一張證書,而其余的名稱也被涵蓋在了SAN(Subject Alternative Name)區(qū)域中。