Q

Setting up an SSL certificate for OWA without a public IP address

Learn how to set up a Secure Sockets Layer (SSL) certificate for Outlook Web Access (OWA) without having a public IP address.

We want to set up a Secure Sockets Layer (SSL) certificate for Outlook Web Access (OWA), and we do not have a public IP address assigned for our firewall. Can we use Dynamic Domain Name System (DDNS) to allow external access to our Exchange server? Or, will we need a fixed public address to get this to work? I have set up the certificate and OWA works internally, but not externally.
VIEW MEMBER FEEDBACK TO THIS ASK THE EXPERT Q&A.

It is possible to use DDNS. However, the certificate's common name must match the fully qualified domain name (FQDN) you use with DDNS. Using the IP address will not work unless the common name of the certificate is the IP address.

By the way, there are varying degrees of the word "works" when it comes to Web server certificates. The first level is to establish an SSL session. The next level is to get it to work without any certificate errors. The most common error is that you are not using a "Trusted CA." If this is the error you are getting, then you can simply publish the Root Certificate so that users can import it into their Web browser's trust list. If these are Active Directory (AD) members, I would recommend using a Group Policy Object (GPO) to perform this task.

MEMBER FEEDBACK TO THIS ASK THE EXPERT Q&A:

Depending on your purpose, there is a way to possibly accomplish this. I support Windows Small Business Server (SBS). Several clients have Windows Mobile phones that "require" a Root level certificate, but self-signed certificates created by SBS are not Root level.
—Kevin K.

Do you have comments on this Ask the Expert Q&A? Let us know.

Related information from SearchExchange.com:

  • Expert Advice: How enabling SSL for OWA affects bandwidth
  • Expert Advice: Securing a front-end certificate server
  • Tutorial: How to set up a front-end Exchange Server cluster
  • Tip: ActiveSync and front-end DNS aliases
  • Reference Center: Exchange Server authentication resources
  • This was first published in August 2006

    Dig deeper on Outlook Web Access

    Pro+

    Features

    Enjoy the benefits of Pro+ membership, learn more and join.

    Have a question for an expert?

    Please add a title for your question

    Get answers from a TechTarget expert on whatever's puzzling you.

    You will be able to add details on the next page.

    0 comments

    Oldest 

    Forgot Password?

    No problem! Submit your e-mail address below. We'll send you an email containing your password.

    Your password has been sent to:

    -ADS BY GOOGLE

    SearchWindowsServer

    SearchEnterpriseDesktop

    SearchCloudComputing

    SearchSQLServer

    Close