前沿拓展:
exchange服務(wù)
Exchange服務(wù)包含很多寧受開,用我目前的EXCHANGE2010舉例:
例如
MSExchangeFBA, 是FORM 認(rèn)證服務(wù)
MSExchangeImap4 是 IMAP服務(wù)
最重要的當(dāng)然是POP3服務(wù)了
其他可以百度一下。
Exchange Server從2021年9月累積更新(Exchange2016cu21/Exchange2019cu11)開始,將無法在ECP上通過向?qū)Ы缑孢M(jìn)行證書上的安裝配置,只能通過Exchange Management Shell用命令的方式安裝配置證書,以下是安裝內(nèi)部 CA 頒發(fā)的證書的全過程1.新建Exchange 證書:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看證書:Get-ExchangeCertificate刪除證書:Remove-ExchangeCertificate 輸入后會提示需要刪除證書的指紋,輸入指紋回車刪除。查看創(chuàng)建的證書:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint證書請求文件發(fā)送到證書頒發(fā)機(jī)構(gòu),下載證書
2. 完成掛起的Exchange Server證書請求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 將證書分配給 Exchange Server 服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.證書的導(dǎo)出和導(dǎo)入:導(dǎo)出證書:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一臺服務(wù)器上導(dǎo)入證書:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再給新導(dǎo)入的證書分配服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知識:
exchange服務(wù)
Exchange服務(wù)是一種收發(fā)郵件的協(xié)議。
前沿拓展:
exchange服務(wù)
Exchange服務(wù)包含很多寧受開,用我目前的EXCHANGE2010舉例:
例如
MSExchangeFBA, 是FORM 認(rèn)證服務(wù)
MSExchangeImap4 是 IMAP服務(wù)
最重要的當(dāng)然是POP3服務(wù)了
其他可以百度一下。
Exchange Server從2021年9月累積更新(Exchange2016cu21/Exchange2019cu11)開始,將無法在ECP上通過向?qū)Ы缑孢M(jìn)行證書上的安裝配置,只能通過Exchange Management Shell用命令的方式安裝配置證書,以下是安裝內(nèi)部 CA 頒發(fā)的證書的全過程1.新建Exchange 證書:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看證書:Get-ExchangeCertificate刪除證書:Remove-ExchangeCertificate 輸入后會提示需要刪除證書的指紋,輸入指紋回車刪除。查看創(chuàng)建的證書:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint證書請求文件發(fā)送到證書頒發(fā)機(jī)構(gòu),下載證書
2. 完成掛起的Exchange Server證書請求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 將證書分配給 Exchange Server 服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.證書的導(dǎo)出和導(dǎo)入:導(dǎo)出證書:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一臺服務(wù)器上導(dǎo)入證書:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再給新導(dǎo)入的證書分配服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知識:
exchange服務(wù)
Exchange服務(wù)是一種收發(fā)郵件的協(xié)議。
前沿拓展:
exchange服務(wù)
Exchange服務(wù)包含很多寧受開,用我目前的EXCHANGE2010舉例:
例如
MSExchangeFBA, 是FORM 認(rèn)證服務(wù)
MSExchangeImap4 是 IMAP服務(wù)
最重要的當(dāng)然是POP3服務(wù)了
其他可以百度一下。
Exchange Server從2021年9月累積更新(Exchange2016cu21/Exchange2019cu11)開始,將無法在ECP上通過向?qū)Ы缑孢M(jìn)行證書上的安裝配置,只能通過Exchange Management Shell用命令的方式安裝配置證書,以下是安裝內(nèi)部 CA 頒發(fā)的證書的全過程1.新建Exchange 證書:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看證書:Get-ExchangeCertificate刪除證書:Remove-ExchangeCertificate 輸入后會提示需要刪除證書的指紋,輸入指紋回車刪除。查看創(chuàng)建的證書:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint證書請求文件發(fā)送到證書頒發(fā)機(jī)構(gòu),下載證書
2. 完成掛起的Exchange Server證書請求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 將證書分配給 Exchange Server 服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.證書的導(dǎo)出和導(dǎo)入:導(dǎo)出證書:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一臺服務(wù)器上導(dǎo)入證書:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再給新導(dǎo)入的證書分配服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知識:
exchange服務(wù)
Exchange服務(wù)是一種收發(fā)郵件的協(xié)議。
前沿拓展:
exchange服務(wù)
Exchange服務(wù)包含很多寧受開,用我目前的EXCHANGE2010舉例:
例如
MSExchangeFBA, 是FORM 認(rèn)證服務(wù)
MSExchangeImap4 是 IMAP服務(wù)
最重要的當(dāng)然是POP3服務(wù)了
其他可以百度一下。
Exchange Server從2021年9月累積更新(Exchange2016cu21/Exchange2019cu11)開始,將無法在ECP上通過向?qū)Ы缑孢M(jìn)行證書上的安裝配置,只能通過Exchange Management Shell用命令的方式安裝配置證書,以下是安裝內(nèi)部 CA 頒發(fā)的證書的全過程1.新建Exchange 證書:$txtrequest = New-ExchangeCertificate -PrivateKeyExportable $True -GenerateRequest -FriendlyName "Exchange2019Cert" -SubjectName "C=CN,CN=mail.starting-tech.cn" -DomainName mail.starting-tech.cn,autodiscover.starting-tech.cn,starting-tech.cn[System.IO.File]::WriteAllBytes('\192.168.0.44certcert2019.req', [System.Text.Encoding]::Unicode.GetBytes($txtrequest))查看證書:Get-ExchangeCertificate刪除證書:Remove-ExchangeCertificate 輸入后會提示需要刪除證書的指紋,輸入指紋回車刪除。查看創(chuàng)建的證書:Get-ExchangeCertificate | where {$_.Status -eq "PendingRequest" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint證書請求文件發(fā)送到證書頒發(fā)機(jī)構(gòu),下載證書
2. 完成掛起的Exchange Server證書請求:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certcertnew.cer'))
檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid" -and $_.IsSelfSigned -eq $false} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint
3. 將證書分配給 Exchange Server 服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
4.證書的導(dǎo)出和導(dǎo)入:導(dǎo)出證書:$cert = Export-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -BinaryEncoded -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)[System.IO.File]::WriteAllBytes('d:certexportcert.pfx', $cert.FileData)在另一臺服務(wù)器上導(dǎo)入證書:Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('\192.168.0.44certexportcert.pfx')) -Password (ConvertTo-SecureString -String 'abcd1234*' -AsPlainText -Force)檢查**作是否成功:Get-ExchangeCertificate | where {$_.Status -eq "Valid"} | Format-List FriendlyName,Subject,CertificateDomains,Thumbprint,NotBefore,NotAfter最后再給新導(dǎo)入的證書分配服務(wù):Enable-ExchangeCertificate -Thumbprint 5B144C35080C7AF0A2A20605E920BE67CEF74847 -Services POP,IMAP,IIS,**TP
拓展知識:
exchange服務(wù)
Exchange服務(wù)是一種收發(fā)郵件的協(xié)議。
原創(chuàng)文章,作者:九賢生活小編,如若轉(zhuǎn)載,請注明出處:http://xiesong.cn/28801.html