Last Updated:

Renewing Exchange SSL Certificate with PowerShell

Mike
Mike Exchange Server

This post covers how to renew a 3rd party SSL certificate for Microsoft Exchange 2016 and later. At some point in time, this process left EAC and shifted to requiring Powershell via Exchange Management Shell (EMS). Here's how to approach this.

Creating the CSR

Get-ExchangeCertificate | Where {$_.IsSelfSigned -eq $false} | Format-List FriendlyName, CertificateDomains, Thumbprint, NotAfter

This returns certificates that are not self-signed. Locate the certificate that you want to renew and record its certificate thumbprint as you'll need it later. 

Next, we need to generate a new CSR using the thumbprint that was gathered above. 

$certrequest = Get-ExchangeCertificate -Thumbprint <thumbprint-here> | New-ExchangeCertificate -GenerateRequest -PrivateKeyExportable:$tru

With the CSR stored as a variable, you'll need to convert that to a file that you can submit to your 3rd party CA.

[System.IO.File]::WriteAllBytes('\\SERVERNAME\C$\Users\<user>\Desktop\certrequest.txt', [System.Text.Encoding]::Unicode.GetBytes($certrequest))

At this point, if you run the following command, you can confirm the pending request for the new certificate. 

Get-ExchangeCertificate | Format-Table Subject, Status

Submit the CSR to your 3rd party CA and come back when you get your signed certificate. 

Complete the Renewal

You're ready to import the signed certificate that you received from the issuing 3rd party CA.

Import-ExchangeCertificate -FriendlyName mail.domainname.com -FileData ([System.IO.File]::ReadAllBytes('\\SERVERNAME\C$\Users\<user>\Desktop\certrequest.txt')) -PrivateKeyExportable $true

Next, you will need to assign services to the new certificate. To do this, you need the thumbprint of the new certificate that you just imported above. Make sure you get the thumbprint for the renewed certificate by looking at the NotAfter column. Run below to get the thumbrint of the new certificate.

Get-ExchangeCertificate | Format-Table Subject, Thumbprint, NotAfter

With correct thumbprint on hand, you can assign the certificate to services by running the following.

Enable-ExchangeCertificate -Server <Exchange-Server-Name> –Thumbprint <new-certificate-thumbprint> –Services IIS,SMTP

You may be prompted to overwrite the default SMTP certificate. If so, answer Yes.

Validation

Validate that the active certificate is present with services assigned to it by running the following command.

Get-ExchangeCertificate | where {$_.IsSelfSigned -eq $false} | Format-List FriendlyName,Thumbprint,NotAfter,Services

I think a good test at this point is to navigate to your EAC using a web browser. Once you land on the login page, check out the SSL certifiate to make sure that the new one presents itself and that you don't see any browser warnings. 

One more thing, if you are in an Exchange hybrid configuration, it's time to re-run the HCW.

Cleanup

Once you confirm that everything is good, you should probably ditch the old certificate using the thumbprint of the old certificate using the command below. 

Remove-ExchangeCertificate -Server <Exchange-Server-Name> -Thumbprint <old-certificate-thumbprint>