1-概述

因为exchange提供了多种客户端服务,比如自动发现,MAPI POP3 SMTP等,所以默认exchange2010提供了自签名的证书加密邮件服务,但这个证书没有客户端能信任自己颁发自己的证书

因此 想利用exchange 证书服务,所以必须申请多域名的证书.

如果直接在IIS上去申请域证书是错误的做法

Lesson3 – exchange 2010 Certification Services_target

2-新建exchange证书

Lesson3 – exchange 2010 Certification Services_target_02

Lesson3 – exchange 2010 Certification Services_证书服务_03

Lesson3 – exchange 2010 Certification Services_exchange_04

Lesson3 – exchange 2010 Certification Services_target_05

Lesson3 – exchange 2010 Certification Services_exchange_06

Lesson3 – exchange 2010 Certification Services_客户端_07

Lesson3 – exchange 2010 Certification Services_exchange_08

Lesson3 – exchange 2010 Certification Services_target_09

Lesson3 – exchange 2010 Certification Services_target_10

点下载证书,保存到桌面

完成搁置请求

Lesson3 – exchange 2010 Certification Services_target_11

找到刚保存到桌面上的证书

Lesson3 – exchange 2010 Certification Services_exchange_12

为证书分配服务

Lesson3 – exchange 2010 Certification Services_exchange_13

可以为不同的服务器配服务

Lesson3 – exchange 2010 Certification Services_证书服务_14

Lesson3 – exchange 2010 Certification Services_exchange_15

直到完成

最后可以把以前自签名的证书给删除掉

Lesson3 – exchange 2010 Certification Services_exchange_16

最后一步在DNS上添加Ahost

Lesson3 – exchange 2010 Certification Services_exchange_17

3-验证

3.1-OWA验证

Lesson3 – exchange 2010 Certification Services_target_18

Lesson3 – exchange 2010 Certification Services_证书服务_19

3.2-MAPI验证

Lesson3 – exchange 2010 Certification Services_target_20

3.3-POP3测试

因为已使用证书,所以我们POP3 属性里的身份验证 我们必须选”安全登入”

最后重新启动下pop3服务

Lesson3 – exchange 2010 Certification Services_target_21

Smtp默认是加密的

我们用alice帐号来做pop3的access

Lesson3 – exchange 2010 Certification Services_target_22

Lesson3 – exchange 2010 Certification Services_证书服务_23

Lesson3 – exchange 2010 Certification Services_证书服务_24

Lesson3 – exchange 2010 Certification Services_客户端_25

4-启用outlook anywhere

启动公共,link到CAS,启动outlook anywhere 功能

Lesson3 – exchange 2010 Certification Services_客户端_26

重启服务器立马生效,同时我们可以到日志中 应用程序—3006事件可以确认已开启该功能

Lesson3 – exchange 2010 Certification Services_证书服务_27

测试:

用peter帐号在内网测试

Lesson3 – exchange 2010 Certification Services_证书服务_28

Lesson3 – exchange 2010 Certification Services_exchange_29

Lesson3 – exchange 2010 Certification Services_客户端_30

Lesson3 – exchange 2010 Certification Services_证书服务_31