Extenal Access: Private key exportable ???

I've read this on TechNet:

Microsoft Lync Server 2010 supports the use of a single public certificate for all external interfaces. The certificate's private key must be exportable, if it is used with multiple Edge Servers, and we recommend that you use an exportable key with a single Edge Server. The key must also be exportable if you request the certificate from any computer other than the Edge Server.

Exportable key is secured ???

May 2nd, 2015 2:31am

It is recommended to keep the key exportable so that you can assign it to multiple edge servers even if you created the request just from one server. If you don't keep the key exportable, you won't be able to assign it on any edge server other than the one you created the request from.
Free Windows Admin Tool Kit Click here and download it now
May 3rd, 2015 10:03am

Hi carlosdlra,

If you want to create a backup copy of the certificate or use it on another computer, you must first export the certificate and private key.

In Lync Server 2013, the OAuthTokenIssuer certificate is a global certificate, this means that the same OAuthTokenIssuer certificate needs to be used by all of the Lync Server 2013 servers.


 

Best regards,

Eric

May 4th, 2015 2:09am

Hi Carlosdlra,

Just to understand that you're concerned is IF the certificate can be exported, it is no longer secured?

Basically the exported certificate is usually protected with a password (usually in PFX format) - so even someone else manage to get hold of the file, they'll still need the password to import into the local certificate store.

Hope this clarifies your con

Free Windows Admin Tool Kit Click here and download it now
May 4th, 2015 3:12am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics