SOLVED
Home

If you receive the warning Overwrite the existing default SMTP certificate?, click No.

%3CLINGO-SUB%20id%3D%22lingo-sub-92331%22%20slang%3D%22en-US%22%3EIf%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92331%22%20slang%3D%22en-US%22%3E%3CP%3ERunning%20through%20the%20Exchange%20Server%20Deployment%20Assistant%20for%20a%20Hybrid%202007%2F2013%20%26nbsp%3B%20Configuration%20there%E2%80%99s%20a%20section%20on%20assigning%20services%20to%20the%20certificate.%20Specifically%20assigning%20the%20certificate%26nbsp%3Bto%20smtp%20for%20secure%20mail%20transport%20it%20says%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%E2%80%9CIf%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%E2%80%9C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20advice%20correct%2C%20shouldn%E2%80%99t%20it%20actually%20say%20..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%E2%80%9CIf%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20Yes%E2%80%9D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-92331%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-92582%22%20slang%3D%22en-US%22%3ERe%3A%20If%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92582%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-92544%22%20slang%3D%22en-US%22%3ERe%3A%20If%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92544%22%20slang%3D%22en-US%22%3E%3CP%3EExactly!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-92542%22%20slang%3D%22en-US%22%3ERe%3A%20If%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92542%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Andy%2C%20confirms%20what%20I%20was%20thinking.%20Given%20that%20we%20have%20probably%20overwritten%20the%20default%20smtp%20certificate%20we%20can%20just%20regenerate%20this%20with%20New-ExchangeCertificate%20on%20the%202013%20server%20and%20make%20it%20default%20for%20SMTP%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-92530%22%20slang%3D%22en-US%22%3ERe%3A%20If%20you%20receive%20the%20warning%20Overwrite%20the%20existing%20default%20SMTP%20certificate%3F%2C%20click%20No.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92530%22%20slang%3D%22en-US%22%3E%3CP%3EActually%20that's%20correct.%20You%20dont%20want%20to%20overwrite%20the%20default%20cert.%26nbsp%3BThe%20certificate%20you%20are%20using%20for%20Hybrid%20is%20going%20to%20be%20a%203rd%20party%20cert%20with%20a%20subject%20name%20that%20will%20match%20the%20FQDN%20you%20have%20set%20on%20the%20receive%20and%20send%20connector%20used%20for%20SMTP%20traffic%20betwwen%20Office%20365%20and%20on-prem.%20The%20FQDN%20matching%20the%20cert%20subject%20is%20what%20binds%20them%20together.%3C%2FP%3E%3CP%3EThe%20default%20SMTP%20cert%20is%20the%20self-generated%20one%20in%20Exchange.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Ian Moran
Regular Contributor

Running through the Exchange Server Deployment Assistant for a Hybrid 2007/2013   Configuration there’s a section on assigning services to the certificate. Specifically assigning the certificate to smtp for secure mail transport it says 

 

“If you receive the warning Overwrite the existing default SMTP certificate?, click No.“

 

Is this advice correct, shouldn’t it actually say ..

 

“If you receive the warning Overwrite the existing default SMTP certificate?, click Yes”

 

 

 

4 Replies
Solution

Actually that's correct. You dont want to overwrite the default cert. The certificate you are using for Hybrid is going to be a 3rd party cert with a subject name that will match the FQDN you have set on the receive and send connector used for SMTP traffic betwwen Office 365 and on-prem. The FQDN matching the cert subject is what binds them together.

The default SMTP cert is the self-generated one in Exchange.

Thanks Andy, confirms what I was thinking. Given that we have probably overwritten the default smtp certificate we can just regenerate this with New-ExchangeCertificate on the 2013 server and make it default for SMTP ?

Related Conversations