Forum Discussion
ssandoval_87293
Nimbostratus
Aug 02, 2010Exchange 2007 - What Type of SSL certificate required (single domain or UCC)
We are planing on installing an F5 load balancer in front of our Exchange 2007 environment with has two CAS/HUB servers. We would like to load balance and SSL offload OWA, Outlook Anywhere, and ActiveSync traffic. According to the f5-exchange07-dg0.dpf development guide it looks like we can use a single virtual server to support all three of these services. Now to my questions: What type of commercial SSL certificate do we need to purchase and install on the F5? Will a single domain SSL certificate work or do we need to purchase a UCC multiple domain certificate? If a UCC multiple domain certificate is required, what names do we need to have assigned to it? Do we need to install any SSL certificates on the CAS/HUB servers?
Thanks
4 Replies
- Helen_Johnson_1Historic F5 AccountHi Ssandoval,
- ssandoval_87293
Nimbostratus
Thanks for the quick response Helen. We are planing on using the same external domain name (http:/mail.ourcompany.com/..service..) and public IP for all three services if possible. Thus, It sounds like a single domain certificate will work. - Helen_Johnson_1Historic F5 AccountHi Ssandoval,
- hoolio
Cirrostratus
As Helen suggested, if you have a single host name for all three services, you will only need an explicit SSL cert for that host name. If you're doing SSL offloading (without re-encrypting the LTM to pool connection) the behavior you're seeing on redirects to https:// is what you'll need the application to do as the client will expect references to the application to be made via https://.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects