{"id":4751,"date":"2025-12-07T15:05:31","date_gmt":"2025-12-07T15:05:31","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4751"},"modified":"2025-12-07T15:05:31","modified_gmt":"2025-12-07T15:05:31","slug":"microsoft-exchange-server-certificate-replacement","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4751","title":{"rendered":"Microsoft Exchange Server &#8211; Certificate Replacement"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The time of on-premise Microsoft Exchange servers is beginning to draw to a close, although the Microsoft Exchange Server SE will continue, its feature complete essentially as of Exchange Server 2019, although there may be the odd minor changes here and there. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Based on that replacing the certificate is a common task, the following instructions give you some guidance on how to do this, although specific to Exchange, it may be helpful for other certificate replacement tasks on Microsoft Windows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;m are assuming that you already have the replacement certificate (Private and Public Key) within a compatible PFX file. See <a href=\"https:\/\/geekmungus.co.uk\/?p=4743\">https:\/\/geekmungus.co.uk\/?p=4743<\/a> if you need to convert it!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Microsoft Exchange Server &#8211; Import Certificate and Determine Thumbprint<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We first need to import the new certificate onto\u00a0all\u00a0of the on-premise Microsoft Exchange Servers so it can be used with various Exchange services. The certificate is to be installed into the Personal Certificates Store for the Computer Account of each of the Microsoft Exchange Servers. It is recommended to set a nice Friendly Name for the certificate so you can easily identify it in future, if you do not perform this at import time you can retrospectively change the name later.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-ImportCertificate\">Import Certificate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Next we need to import the certificate into each of the Microsoft Exchange Servers, so this import step will need to be repeated on each and every Exchange Server which needs to utilise the certificate for securing communications.&nbsp;From an Administrator PowerShell session on the server run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Import-PfxCertificate -FilePath \"c:\\users\\user\\desktop\\legacy-email.p12\" -CertStoreLocation Cert:\\LocalMachine\\My -Password (Read-Host \"Enter password\" -AsSecureString) -Exportable<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ll be prompted for the password (if there is one set), then all being well you should see an output like:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"107\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-8-1024x107.png\" alt=\"\" class=\"wp-image-4752\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-8-1024x107.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-8-300x31.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-8-768x80.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-8.png 1399w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, if you love the GUI, you&#8217;ll see it within the &#8220;Local Computer&#8221; Personal Certificate store within MMC (with the Certificates snap-in):<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"273\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-9-1024x273.png\" alt=\"\" class=\"wp-image-4753\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-9-1024x273.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-9-300x80.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-9-768x205.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-9.png 1197w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">These show that it has been imported successfully.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you see an error such as this upon import, then this means that the certificate which by default is created with AES256-SHA256 encryption is not supported on your version of Microsoft Windows, meaning you&#8217;ll need to convert it to something supported, see the section above entitled: &#8220;Convert the Certificate for Microsoft Windows Server 2016&#8221; for how to do this.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"87\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-10-1024x87.png\" alt=\"\" class=\"wp-image-4754\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-10-1024x87.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-10-300x25.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-10-768x65.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-10.png 1462w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-DetermineThumbprintofImportedCertificate\">Determine Thumbprint of Imported Certificate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now the certificate has been imported into the Personal (Computer) certificate store on each of the Microsoft Exchange Servers we can now obtain the thumbprint, which will be needed later on, the Thumbprint will be the same on each of the Microsoft Exchange Servers because the certificate is the same!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Run the following command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-ChildItem -Path Cert:\\LocalMachine\\My | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ll get an output such as the following, as you can then see the newly imported certificate listed, and its Thumbprint, take a copy of the Thumbprint we&#8217;ll need this in a moment.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"673\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-11-1024x673.png\" alt=\"\" class=\"wp-image-4755\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-11-1024x673.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-11-300x197.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-11-768x505.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-11.png 1096w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Or, you can run the following command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-ExchangeCertificate | where {$_.Status -eq \"Valid\"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The thumbprint is shown in the attribute called &#8220;Thumbprint&#8221;, you&#8217;ll need to find the specific one you are interested in. Which in our case is the one we have just imported.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-RenameImportedCertificate(OptionalbutRecommended)\">Rename Imported Certificate (Optional but Recommended)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As an optional, but strongly recommended task, you should update the Friendly Name of the imported certificate to ensure its got a name that makes sense to you, for example if its a certificate for September 2025 to January 2026, then you could name it: &#8220;Q425-Q126 &#8211; www.mydomain.com&#8221; for example. As an example, we can see the friendly name is not set, let&#8217;s fix that.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"412\" height=\"103\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-12.png\" alt=\"\" class=\"wp-image-4756\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-12.png 412w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-12-300x75.png 300w\" sizes=\"auto, (max-width: 412px) 100vw, 412px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-ShowCurrentFriendlyName\">Show Current Friendly Name<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To show the current friendly name with the following command, substituting in the thumbprint you obtained in the previous step.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>(Get-ChildItem -Path Cert:\\LocalMachine\\My\\7A46B8F6DDA3F258A498F78A9C3280ECE2E9D847).FriendlyName<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Unsurprisingly we&#8217;ll get nothing output!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"50\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-13.png\" alt=\"\" class=\"wp-image-4757\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-13.png 864w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-13-300x17.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-13-768x44.png 768w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-RenameFriendlyName\">Rename Friendly Name<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s add a suitable Friendly Name, something like\u00a0<strong><em>&#8220;www.mydomain.com &#8211; Oct25-Jan26&#8221;<\/em><\/strong>\u00a0would seem sensible in this case.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>(Get-ChildItem -Path Cert:\\LocalMachine\\My\\7A46B8F6DDA3F258A498F78A9C3281234232).FriendlyName = 'www.mydomain.com - Oct25-Jan26'<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You won&#8217;t get any output indicating its worked.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-VerifyFriendlyNameChanged\">Verify Friendly Name Changed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To check if its worked, we just repeat the earlier command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>(Get-ChildItem -Path Cert:\\LocalMachine\\My\\7A46B8F6DDA3F258A498F78A9C3281234232).FriendlyName<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And we now see:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"34\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-14.png\" alt=\"\" class=\"wp-image-4758\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-14.png 867w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-14-300x12.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-14-768x30.png 768w\" sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"206\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-15-1024x206.png\" alt=\"\" class=\"wp-image-4759\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-15-1024x206.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-15-300x60.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-15-768x155.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-15.png 1334w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Step4-MicrosoftExchangeServer-IISServices(HTTP\/HTTPS,IMAP,POPandSMTP)\">Microsoft Exchange Server &#8211; IIS Services (HTTP\/HTTPS, IMAP, POP and SMTP)<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">We now need to assign the certificate to Exchange, the command needs to be run on each Exchange server individually to assign the new certificate and replace the old one for the specific services, POP, IMAP, IIS (HTTP\/HTTPS) and SMTP.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Enable-ExchangeCertificate -Thumbprint \"7A46B8F6DDA3F258A498F78A9C3281234232\" -Services POP,IMAP,IIS,SMTP -Server SERVER1\nEnable-ExchangeCertificate -Thumbprint \"7A46B8F6DDA3F258A498F78A9C3281234232\" -Services POP,IMAP,IIS,SMTP -Server SERVER2\nEnable-ExchangeCertificate -Thumbprint \"7A46B8F6DDA3F258A498F78A9C3281234232\" -Services POP,IMAP,IIS,SMTP -Server SERVER3\nEnable-ExchangeCertificate -Thumbprint \"7A46B8F6DDA3F258A498F78A9C3281234232\" -Services POP,IMAP,IIS,SMTP -Server SERVER4\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You may then need to perform an IISRESET, by running &#8220;IISRESET&#8221;, however, this may not be required. Verify by checking if the new certificate is being presented.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Step5-MicrosoftExchangeServer-SMTPSendandRecieveConnectors\">Microsoft Exchange Server &#8211; SMTP Send and Recieve Connectors<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">For the communication to work correctly with Microsoft 365 Exchange Online, TLS must be enabled on the Send and Receive Connectors which use the certificate for the purposes of authenticating the SMTP connections to and from the on-premise Exchange Server(s).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-SetTLSCertNameVariable\">Set TLSCertName Variable<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Get hold of the thumbprint from the GUI, then:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$TLSCert = Get-ExchangeCertificate -Thumbprint \"7A46B8F6DDA3F258A498F78A9C3280ECE2E9D847\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Get the certificate Issuer and Subject and load into a variable for use when applying the certificate to the Send and Receive Connectors.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$TLSCertName = \"&lt;I>$($TLSCert.Issuer)&lt;S>$($TLSCert.Subject)\"<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-SetTLSCertificateonSendConnector(SEND)\">Set TLS Certificate on Send Connector (SEND)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Send Connector called &#8220;SEND&#8221; is used to send email to the EXIM Mail Relay Servers (which are authoritative for the SMTP namespace). The connector is considered &#8220;global&#8221;, i.e. they are not server specific and apply to all routing in the Exchange organisation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Note we don&#8217;t set a TLS Certificate on the connector called &#8220;SEND&#8221; which is used to send to the EXIM Mail Relay servers, therefore there are no steps to complete.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-SetTLSCertificateonSendConnector(Microsoft365-OutboundtoOffice365-37b7454e-3cd0-49d6-b8d7-a4baf80d9b37)\">Set TLS Certificate on Send Connector (Microsoft 365 &#8211; Outbound to Office 365 &#8211; 12345567-1234-49d6-b8d7-a4baf80d9b37)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Send Connector called &#8220;Outbound to Office 365 &#8211; 12345567-1234-49d6-b8d7-a4baf80d9b37&#8221; is used to send emails to mailboxes hosted in Microsoft 365, it is a scoped send connector, which means only emails to particular domains (i.e. those within the Exchange organisation) will use it. The connector is considered &#8220;global&#8221;, i.e. they are not server specific and apply to all routing in the Exchange organisation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-FindSendConnectorName\">Find Send Connector Name<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We first need to find the name of the scoped send connector, used to send to emails to mailboxes that are hosted in Microsoft 365, so we do the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>get-sendconnector<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ll get an output such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;PS] C:\\Windows\\system32>get-sendconnector\n\nIdentity \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0AddressSpaces \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0Enabled\n-------- \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0------------- \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0-------\nSEND \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0{SMTP:*;1} \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 True\nOutbound to Office 365 -12345567-1234-49d6-b8d7-a4baf80d9b37 {smtp:MYDOMAIN.mail.onmicrosoft.com;1} True<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">We are looking for the one called:\u00a0<em>&#8220;Outbound to Office 365 &#8211; 12345567-1234-49d6-b8d7-a4baf80d9b37&#8221;<\/em>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Configure\">Configure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You now configure the TLS Certificate for the Microsoft 365 Send Connector using the variable we populated earlier.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Set-SendConnector \"Outbound to Office 365 - <em>12345567-1234-49d6-b8d7-a4baf80d9b37<\/em>\" -TlsCertificateName $TLSCertName<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You may then need to perform an IISRESET, by running &#8220;IISRESET&#8221;, however, this may not be required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Verify\">Verify<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verify its changed by checking with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;PS] C:\\Windows\\system32>get-sendconnector \"Outbound to Office 365 - <em>12345567-1234-49d6-b8d7-a4baf80d9b37<\/em>\" | Format-List Name,TlsCertificateName\n\n\nName               : Outbound to Office 365 - <em>12345567-1234-49d6-b8d7-a4baf80d9b37<\/em>\nTlsCertificateName : &lt;I>CN=R13, O=Let's Encrypt, C=US&lt;S>CN=www.mydomain.com<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-SetTLSCertificateonReceiveConnector\">Set TLS Certificate on Receive Connector<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Receive Connectors are used by the on-premise Exchange Servers to receive email from the other email servers, this might be Microsoft 365 or it may be the on-premise EXIM Mail Relay Servers, either way they need to be TLS secured. The Receive Connectors however are not &#8220;global&#8221;, they are specific to each Exchange Server, so therefore need to be configured individually.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-FindReceiveConnectorNames\">Find Receive Connector Names<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Run the following command to find all the receieve connectors within the Exchange Organisation.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>get-receiveconnector<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">We are interested only in the ones called: &#8220;&lt;Exchange Server Name>\\Default FrontEnd &lt;Exchange Server Name>&#8221;.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Configure.1\">Configure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now we have all the names of the receive connectors, we update the TLS Certificate on all of these by running the following commands, these commands can be run from one Microsoft Exchange Server.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Set-ReceiveConnector \"SERVER1\\Default Frontend SERVER1\" -TlsCertificateName $TLSCertName\nSet-ReceiveConnector \"SERVER2\\Default Frontend SERVER2\" -TlsCertificateName $TLSCertName\n...<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You may then need to perform an IISRESET, by running &#8220;IISRESET&#8221;, however, this may not be required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Verify.1\">Verify<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verify its changed by checking with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;PS] C:\\Windows\\system32>get-receiveconnector \"SERVER1\\Default Frontend SERVER1\" | Format-List Name,TLSCertificateName\n\n\nName               : Default Frontend SERVER1\nTlsCertificateName : &lt;I>CN=R13, O=Let's Encrypt, C=US&lt;S>CN=www.mydomain.com<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Repeat for each of the Receive Connectors for each of your Microsoft Exchange Servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also possible to verify that the changes have been successful by from another machine running the following command, and repeat this for each of the Exchange Servers in turn.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl s_client -starttls smtp -connect www.mydomain.com:25<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You will get an output like the following, here just look for the expected start and expiry dates of the certificate to verify it has been replaced and is in use as expected.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"342\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-16.png\" alt=\"\" class=\"wp-image-4760\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-16.png 867w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-16-300x118.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-16-768x303.png 768w\" sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-Step6-MicrosoftExchangeServer-DeleteLegacyCertificate\">Microsoft Exchange Server &#8211; Delete Legacy Certificate<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">To avoid confusion we now need to delete the legacy certificate, doing that can be done by first identifying the old certificate, then by issuing a command to remove it, this will need to be repeated on all of the Microsoft Exchange Servers that are using the certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is recommended to export the certificate to a file before removal, so it could be recovered if required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-FindLegacyCertificate\">Find Legacy Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We first need to find the certificate we want to remove by running this to obtain the Thumbprint value.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-ChildItem Cert:\\LocalMachine\\My | Select-Object Subject,Thumbprint,NotAfter<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ll see an output such as the following:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"161\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-17-1024x161.png\" alt=\"\" class=\"wp-image-4761\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-17-1024x161.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-17-300x47.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-17-768x121.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/12\/image-17.png 1447w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s say we want to remove the highlighted certificate, we&#8217;ll need to copy the\u00a0<strong>Thumbprint\u00a0<\/strong>attribute, in this example it is: C5000AC8BC98C46E70FFAB1CCAB897D606112345<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-RemoveCertificate\">Remove Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To remove the certificate by running the following, it is strongly recommended to use Thumbprint, rather than the Subject because the Subject can be the same, but the Thumbprint will be unique.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$thumbprint = \"C5000AC8BC98C46E70FFAB1CCAB897D606112345\"\n\nRemove-Item \"Cert:\\LocalMachine\\My\\$thumbprint\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Re-running the Get-ChildItem command should now show the certificate has been removed successfully.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"InstallingandReplacingCertificatesonMicrosoftExchange2016Servers(includingKempLoadMastersandMicrosoft365Considerations)-AdditionalInformation\">Additional Information<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.alitajran.com\/renew-certificate-exchange-hybrid\/\">https:\/\/www.alitajran.com\/renew-certificate-exchange-hybrid\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/renew-certificates\">https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/renew-certificates<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/import-certificates\">https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/import-certificates<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/assign-certificates-to-services\">https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/assign-certificates-to-services<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/blog.admindroid.com\/how-to-create-self-signed-certificate-using-powershell\/\">https:\/\/blog.admindroid.com\/how-to-create-self-signed-certificate-using-powershell\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/import-certificates\">https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/import-certificates<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/pki\/import-certificate?view=windowsserver2025-ps\">https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/pki\/import-certificate?view=windowsserver2025-ps<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/pki\/import-pfxcertificate?view=windowsserver2025-ps\">https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/pki\/import-pfxcertificate?view=windowsserver2025-ps<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The time of on-premise Microsoft Exchange servers is beginning to draw to a close, although the Microsoft Exchange Server SE will continue, its feature complete essentially as of Exchange Server 2019, although there may be the odd minor changes here and there. Based on that replacing the certificate is a common task, the following instructions &#8230; <a title=\"Microsoft Exchange Server &#8211; Certificate Replacement\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4751\" aria-label=\"Read more about Microsoft Exchange Server &#8211; Certificate Replacement\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":4361,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,14],"tags":[],"class_list":["post-4751","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-exchange","category-microsoft-windows"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4751","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4751"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4751\/revisions"}],"predecessor-version":[{"id":4762,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4751\/revisions\/4762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/4361"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4751"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}