Unable to remove Exchange 2007 CAS default certificate
Hi Everyone, I am trying to install Exchange 2007 with SP3 in Exchange 2003 environment. There are 2 Exchange 2003 Back-end server and 1 front End server. I have installed Exchange 2007SP3 CAS, HUB and Mailbox Role. Each role is installed on a separate server. Also I have installed third party certificate on CAS and enabled the same for IIS, POP and IMAP. Now I want to remove default certificate on CAS. While removing the default certificate I am getting following error: "Remove-ExchangeCertificate : The internal transport certificate cannot be removed because that would cause the Microsoft Exchange Transport service to stop. To replace the internal transport certificate, create a new certificate. The new certificate will automatically become the internal transport certificate. you can then remove the existing certificate." Now my doubt is Transport service is on HUB server. Why I am getting this error while removing default certificate on CAS server? Any Idea? Thanks, Mukesh Mukesh
December 6th, 2010 11:56pm

Hello, You need to change the FQDN on the Receive Connector, change the name of it to server name and try restarting the transport server then you can try to remove the exchange certificate. That is because it is assigned to the SMTP service. You need to create a new internal certificate and assign it to SMTP so your transport service can use it. Thanks Mhussain
Free Windows Admin Tool Kit Click here and download it now
December 7th, 2010 2:22am

Hello, You need to change the FQDN on the Receive Connector, change the name of it to server name and try restarting the transport server then you can try to remove the exchange certificate. That is because it is assigned to the SMTP service. You need to create a new internal certificate and assign it to SMTP so your transport service can use it. Thanks Mhussain
December 7th, 2010 10:21am

The self signed certificate can't be removed, but it can be replaced with another self-signed certificate and then you can remove the old one, as it's used for securing exchange servers internal communications. Note: A self-signed certificate is installed on every Exchange 2007 server role except for the Mailbox server role. Further reading: http://technet.microsoft.com/en-us/library/bb851554%28EXCHG.80%29.aspIbrahim Al Masry http://www.ibra.me/
Free Windows Admin Tool Kit Click here and download it now
December 8th, 2010 7:12am

Thanks for the clarification.Mukesh
February 7th, 2011 12:28am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics