前沿拓展:
exchange服务
Exchange服务包含很多宁受开,用我目前的EXCHANGE2010举例:
例如
MSExchangeFBA, 是FORM 认证服务
MSExchangeImap4 是 IMAP服务
最重要的当然是POP3服务了
其他可以百度一下。
Exchange Server从2021年9月累积更新(Exchange2016cu21/Exchange2019cu11)开始,将无法在ECP上通过向导界面进行证书上的安装配置,只能通过Exchange Management Shell用命令的方式安装配置证书,以下是安装内部 CA 颁发的证书的全过程1.新建Exchange 证书:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看证书:Get-ExchangeCertificate删除证书:Remove-ExchangeCertificate 输入后会提示需要删除证书的指纹,输入指纹回车删除。查看创建的证书:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint证书请求文件发送到证书颁发机构,下载证书
2. 完成挂起的Exchange Server证书请求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 将证书分配给 Exchange Server 服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.证书的导出和导入:导出证书:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一台服务器上导入证书:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再给新导入的证书分配服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知识:
exchange服务
Exchange服务是一种收发邮件的协议。
前沿拓展:
exchange服务
Exchange服务包含很多宁受开,用我目前的EXCHANGE2010举例:
例如
MSExchangeFBA, 是FORM 认证服务
MSExchangeImap4 是 IMAP服务
最重要的当然是POP3服务了
其他可以百度一下。
Exchange Server从2021年9月累积更新(Exchange2016cu21/Exchange2019cu11)开始,将无法在ECP上通过向导界面进行证书上的安装配置,只能通过Exchange Management Shell用命令的方式安装配置证书,以下是安装内部 CA 颁发的证书的全过程1.新建Exchange 证书:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看证书:Get-ExchangeCertificate删除证书:Remove-ExchangeCertificate 输入后会提示需要删除证书的指纹,输入指纹回车删除。查看创建的证书:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint证书请求文件发送到证书颁发机构,下载证书
2. 完成挂起的Exchange Server证书请求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 将证书分配给 Exchange Server 服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.证书的导出和导入:导出证书:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一台服务器上导入证书:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再给新导入的证书分配服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知识:
exchange服务
Exchange服务是一种收发邮件的协议。
前沿拓展:
exchange服务
Exchange服务包含很多宁受开,用我目前的EXCHANGE2010举例:
例如
MSExchangeFBA, 是FORM 认证服务
MSExchangeImap4 是 IMAP服务
最重要的当然是POP3服务了
其他可以百度一下。
Exchange Server从2021年9月累积更新(Exchange2016cu21/Exchange2019cu11)开始,将无法在ECP上通过向导界面进行证书上的安装配置,只能通过Exchange Management Shell用命令的方式安装配置证书,以下是安装内部 CA 颁发的证书的全过程1.新建Exchange 证书:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看证书:Get-ExchangeCertificate删除证书:Remove-ExchangeCertificate 输入后会提示需要删除证书的指纹,输入指纹回车删除。查看创建的证书:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint证书请求文件发送到证书颁发机构,下载证书
2. 完成挂起的Exchange Server证书请求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 将证书分配给 Exchange Server 服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.证书的导出和导入:导出证书:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一台服务器上导入证书:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再给新导入的证书分配服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知识:
exchange服务
Exchange服务是一种收发邮件的协议。
前沿拓展:
exchange服务
Exchange服务包含很多宁受开,用我目前的EXCHANGE2010举例:
例如
MSExchangeFBA, 是FORM 认证服务
MSExchangeImap4 是 IMAP服务
最重要的当然是POP3服务了
其他可以百度一下。
Exchange Server从2021年9月累积更新(Exchange2016cu21/Exchange2019cu11)开始,将无法在ECP上通过向导界面进行证书上的安装配置,只能通过Exchange Management Shell用命令的方式安装配置证书,以下是安装内部 CA 颁发的证书的全过程1.新建Exchange 证书:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看证书:Get-ExchangeCertificate删除证书:Remove-ExchangeCertificate 输入后会提示需要删除证书的指纹,输入指纹回车删除。查看创建的证书:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint证书请求文件发送到证书颁发机构,下载证书
2. 完成挂起的Exchange Server证书请求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 将证书分配给 Exchange Server 服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.证书的导出和导入:导出证书:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一台服务器上导入证书:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)检查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再给新导入的证书分配服务:Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知识:
exchange服务
Exchange服务是一种收发邮件的协议。
原创文章,作者:九贤生活小编,如若转载,请注明出处:http://www.wangguangwei.com/28801.html