Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 01, 2007

Certificates and Exchange, Part 3

RSS
Subscribe to Windows IT Pro | See More Certificates Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Back in September I wrote a pair of columns about how Exchange Server 2007 uses certificates ("Certificates and Exchange, Part 1," September 7, 2006, and "Certificates and Exchange, Part 2," September 14, 2006). I pointed out the utility of having multiple subject names, or subjectAltNames, in a single certificate; this ability allows you to have a single certificate that works with, for example, autodiscover.yourdomain.com, mail.yourdomain.com, and the underlying Fully Qualified Domain Name (FQDN). Unfortunately, as far as I could tell at the time, no commercial Certificate Authorities (CAs) were issuing such certificates.

However, circumstances seem to be changing; there are now several CAs that issue certificates that allow multiple subjectAltNames. For example, last week I got an email message from Andrew Codrington at Entrust. His company just introduced Entrust Unified Communications Certificates as part of its partnership with Microsoft. The certificate includes 10 subjectAltNames for $599 per year, with the option of adding three more subjectAltNames for an additional $99.

Entrust isn’t the only CA offering these certificates, either. GeoTrust sells the Power Server ID certificate with as many as four subjectAltNames for $599.

Are these certificates good deals? Maybe. The price is certainly steep when compared to lower-cost (and, arguably, lower-security) certificates from smaller CAs such as GoDaddy.com (which, to my knowledge, still doesn’t sell multiple subjectAltNames certificates). The price difference is even more dramatic when you compare these certificates to the cost of using the self-generated certificates that Exchange 2007 installs. However, there are two things you should keep in mind when evaluating these certificates.

The first thing to think about, of course, is security. You can certainly use self-signed certificates (either the ones Exchange 2007 generates or ones generated by your CA) with Exchange, but users will see certificate warnings unless you also configure their browsers and mobile devices with your root certificates. If you don’t do so, users will have to dismiss security warnings to use Office Outlook 2007 or OWA 2007, which essentially trains them to ignore those warnings—not something you want to do.

The second factor to consider is the combination of cost and hassle. Say you want to set up Autodiscover, OWA, and SSL-protected SMTP. Buying a single certificate for $599 might seem like an extravagance until you factor in the time it would take to purchase, install, and configure separate certificates for each of these services. A high-security certificate from a major CA might cost anywhere from $75 to $200 per year, depending on the renewal term and the level of validation you purchase; buying four or five such certificates might end up costing you more than a single certificate with multiple subjectAltNames attached. You’ll have to evaluate how much time it would take to deploy multiple certificates to figure out whether the cost/benefit ratio makes sense.

One interesting aspect to the appearance of CAs that sell certificates with multiple subjectAltNames attributes is that I expect the demand for wildcard certificates to drop significantly. Most organizations don’t want certificates that will match any host on their network, only a subset. Windows Mobile 5.0 can’t handle wildcard certificates, making it impractical to use them for securing Exchange ActiveSync and OWA.

I’ll be testing Entrust’s certificate and will report back on what I find. In the meantime, drop me a note to let me know what certificate services you anticipate needing for your Exchange 2007 deployment plans.

End of Article



Reader Comments
So now we need Windows Certificate Services to have the ability to do AltSubjectName properties.

brainier February 02, 2007 (Article Rating: )


No; you can use 3rd-party CAs provided you pick one that supports multiple SANs.

paulrobichaux February 02, 2007 (Article Rating: )


Do I understand this correctly--the cert can contain different domain names as well as hostnames? Your example is very close to a wildcard cert.

sfrank8734 February 06, 2007 (Article Rating: )


It's like a wildcard cert but for a fixed set of names. That makes it more trustworthy than a wildcard cert in terms of being able to validate the originating host name, and it works with Windows Mobile, which doesn't support wildcard certs.

paulrobichaux February 06, 2007 (Article Rating: )


This sounds great to me. Some of my certs need renewing later in the year and I'll definitely look into this route instead, it'll be a lot less hassle.

cstenson February 07, 2007 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Related Articles Securing Exchange Server 2007 Services with ISA Server 2006

Exchange Server and Outlook Whitepapers Take Control of Your Email: Understand the Business Reasons for Email Storage Management

Continuous Data Protection and Recovery for Microsoft Exchange

Related Events WinConnections and Microsoft® Exchange Connections

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement