{"id":4791,"date":"2026-01-12T18:18:49","date_gmt":"2026-01-12T18:18:49","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4791"},"modified":"2026-01-18T14:46:59","modified_gmt":"2026-01-18T14:46:59","slug":"expired-microsoft-exchange-2016-self-signed-certificate","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4791","title":{"rendered":"Expired Microsoft Exchange 2016 Self Signed Certificate"},"content":{"rendered":"\n<p>What to do when your self-signed certificate for Microsoft Exchange 2016 expires, Microsoft provide some good guidance about this:<\/p>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/renew-certificates?view=exchserver-2019\">https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/renew-certificates?view=exchserver-2019<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"395\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1024x395.png\" alt=\"\" class=\"wp-image-4792\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1024x395.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-300x116.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-768x296.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1536x592.png 1536w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image.png 1541w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>You might see errors such as this when you&#8217;re trying to administer via PowerShell:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;PS] C:\\Windows\\system32>set-mailbox myaccount -type shared\nActive Directory operation failed on DC-02.internal.sanger.ac.uk. This error is not retriable. Additional\ninformation: Insufficient access rights to perform the operation.\nActive directory response: 00002098: SecErr: DSID-031514A0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0\n    + CategoryInfo          : NotSpecified: (:) &#91;Set-Mailbox], ADOperationException\n    + FullyQualifiedErrorId : &#91;Server=SERVER1,RequestId=6336ceb6-c37c-413e-ba36-d65112b69786,TimeStamp=14\/01\/2\n   026 16:29:26] &#91;FailureCategory=Cmdlet-ADOperationException] 404D2B85,Microsoft.Exchange.Management.RecipientTasks.\n  SetMailbox\n    + PSComputerName        : server1.mydomain.com<\/code><\/pre>\n\n\n\n<p>You&#8217;ll have permissions so the error is a red herring, what is actually happening is you&#8217;re attempting to perform an operation on a mailbox which is hosted on an Exchange Server which is not the one you are using PowerShell from. It uses a Back End connection on TCP 444 (SSL\/HTTPS) to make the calls between the Exchange Servers, and if the certificate used for this has expired, you&#8217;ll see issues such as this.&nbsp;<\/p>\n\n\n\n<p>You won&#8217;t likely see any operational issues to the Exchange Server for clients or mail flow.<\/p>\n\n\n\n<p>Ali Tajran has a great article on how to replace the certificate: <a href=\"https:\/\/www.alitajran.com\/renew-microsoft-exchange-certificate\/\">Renew Microsoft Exchange Certificate<\/a>.<\/p>\n\n\n\n<p>In our case however we were not using a default self-signed certificate, instead we had a third-party certificate which has all the hostnames of the Exchange servers within it (as SANs).<\/p>\n\n\n\n<p>But the process is the same, install the new (third-party) certificate onto all your Exchange Servers, give it a sensible name like &#8220;Exchange Back End&#8221; to make it easy to identify.<\/p>\n\n\n\n<p>Using the IIS Manager (MMC Snap-in), edit the site bindings on the &#8220;Exchange Back End&#8221; site running on port 444.<\/p>\n\n\n\n<p>Select the new SSL certificate from the drop down, and click on &#8220;OK&#8221;.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"805\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1-1024x805.png\" alt=\"\" class=\"wp-image-4801\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1-1024x805.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1-300x236.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1-768x604.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2026\/01\/image-1.png 1112w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>You should not need to restart IIS services for the change to take effect.<\/p>\n\n\n\n<p>Your issues with PowerShell saying permissions issues should be resolved.<\/p>\n\n\n\n<p>If you wish to confirm if port 444 is using the correct certificate you can use an OpenSSL connection to verify the correct certificate is being used.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl s_client -connect server1.mydomain.com:444<\/code><\/pre>\n\n\n\n<p>Although not directly relevant to us, because we&#8217;re not using a self-signed certificate be aware of this from his post:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>No, (the command that sets the certificate) it will not automatically update the \u201cMicrosoft Exchange\u201d certificate to the other Exchange Servers, and you have to do the steps on the other Exchange Servers too.<br>Every Exchange Server will have a unique self-signed \u201cMicrosoft Exchange\u201d certificate.<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>What to do when your self-signed certificate for Microsoft Exchange 2016 expires, Microsoft provide some good guidance about this: https:\/\/learn.microsoft.com\/en-us\/exchange\/architecture\/client-access\/renew-certificates?view=exchserver-2019 You might see errors such as this when you&#8217;re trying to administer via PowerShell: You&#8217;ll have permissions so the error is a red herring, what is actually happening is you&#8217;re attempting to perform an operation &#8230; <a title=\"Expired Microsoft Exchange 2016 Self Signed Certificate\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4791\" aria-label=\"Read more about Expired Microsoft Exchange 2016 Self Signed Certificate\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":3999,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,14],"tags":[],"class_list":["post-4791","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-exchange","category-microsoft-windows"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4791"}],"version-history":[{"count":3,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4791\/revisions"}],"predecessor-version":[{"id":4802,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4791\/revisions\/4802"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/3999"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}