Hi Ross, a great article there.
I am clear on the mail.contoso.com and autodiscover.contoso.com names that should be in my SAN cert but i am a little bit confused on the legacy namespace. The first time i came across the legacy namespace, i assumed that it was the FQDN of my Exchange 2007 server, so my SAN cert contains the following namespace - mail.contoso.com, autodiscover.contoso.com and FQDNofE2k7.mydomain.com. If what you are saying now is that the legacy namespace is not the FQDN of my E2K7 server that it should actually be "Legacy" as in Legacy.contoso.com, then will i need to tie a public ip address to legacy.contoso.com as i have for mail.contoso.com.
Please i will appreciate the clarifications