Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 01, 2007

Certificates and Exchange, Part 3

RSS
Subscribe to Windows IT Pro | See More Certificates Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Back in September I wrote a pair of columns about how Exchange Server 2007 uses certificates ("Certificates and Exchange, Part 1," September 7, 2006, and "Certificates and Exchange, Part 2," September 14, 2006). I pointed out the utility of having multiple subject names, or subjectAltNames, in a single certificate; this ability allows you to have a single certificate that works with, for example, autodiscover.yourdomain.com, mail.yourdomain.com, and the underlying Fully Qualified Domain Name (FQDN). Unfortunately, as far as I could tell at the time, no commercial Certificate Authorities (CAs) were issuing such certificates.

However, circumstances seem to be changing; there are now several CAs that issue certificates that allow multiple subjectAltNames. For example, last week I got an email message from Andrew Codrington at Entrust. His company just introduced Entrust Unified Communications Certificates as part of its partnership with Microsoft. The certificate includes 10 subjectAltNames for $599 per year, with the option of adding three more subjectAltNames for an additional $99.

Entrust isn’t the only CA offering these certificates, either. GeoTrust sells the Power Server ID certificate with as many as four subjectAltNames for $599.

Are these certificates good deals? Maybe. The price is certainly steep when compared to lower-cost (and, arguably, lower-security) certificates from smaller CAs such as GoDaddy.com (which, to my knowledge, still doesn’t sell multiple subjectAltNames certificates). The price difference is even more dramatic when you compare these certificates to the cost of using the self-generated certificates that Exchange 2007 installs. However, there are two things you should keep in mind when evaluating these certificates.

The first thing to think about, of course, is security. You can certainly use self-signed certificates (either the ones Exchange 2007 generates or ones generated by your CA) with Exchange, but users will see certificate warnings unless you also configure their browsers and mobile devices with your root certificates. If you don’t do so, users will have to dismiss security warnings to use Office Outlook 2007 or OWA 2007, which essentially trains them to ignore those warnings—not something you want to do.

The second factor to consider is the combination of cost and hassle. Say you want to set up Autodiscover, OWA, and SSL-protected SMTP. Buying a single certificate for $599 might seem like an extravagance until you factor in the time it would take to purchase, install, and configure separate certificates for each of these services. A high-security certificate from a major CA might cost anywhere from $75 to $200 per year, depending on the renewal term and the level of validation you purchase; buying four or five such certificates might end up costing you more than a single certificate with multiple subjectAltNames attached. You’ll have to evaluate how much time it would take to deploy multiple certificates to figure out whether the cost/benefit ratio makes sense.

One interesting aspect to the appearance of CAs that sell certificates with multiple subjectAltNames attributes is that I expect the demand for wildcard certificates to drop significantly. Most organizations don’t want certificates that will match any host on their network, only a subset. Windows Mobile 5.0 can’t handle wildcard certificates, making it impractical to use them for securing Exchange ActiveSync and OWA.

I’ll be testing Entrust’s certificate and will report back on what I find. In the meantime, drop me a note to let me know what certificate services you anticipate needing for your Exchange 2007 deployment plans.

End of Article



Reader Comments
So now we need Windows Certificate Services to have the ability to do AltSubjectName properties.

brainier February 02, 2007 (Article Rating: )


No; you can use 3rd-party CAs provided you pick one that supports multiple SANs.

paulrobichaux February 02, 2007 (Article Rating: )


Do I understand this correctly--the cert can contain different domain names as well as hostnames? Your example is very close to a wildcard cert.

sfrank8734 February 06, 2007 (Article Rating: )


It's like a wildcard cert but for a fixed set of names. That makes it more trustworthy than a wildcard cert in terms of being able to validate the originating host name, and it works with Windows Mobile, which doesn't support wildcard certs.

paulrobichaux February 06, 2007 (Article Rating: )


This sounds great to me. Some of my certs need renewing later in the year and I'll definitely look into this route instead, it'll be a lot less hassle.

cstenson February 07, 2007 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Anti-Virus Vendors Prepare for War with Microsoft ... Again

When Microsoft announced its Windows Live OneCare security and PC health product over five years (as MSN OneCare), Symantec, McAfee, and the other consumer-oriented security vendors reacted with stunning vigor. ...

What You Need to Know About Microsoft's x64 Server Product Plans

What do Longhorn Server, Windows Compute Cluster Server, and Windows Vista have in common? The x64 platform. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Related Articles Securing Exchange Server 2007 Services with ISA Server 2006

Exchange Server and Outlook Whitepapers The IT Guidebook To Evaluating Hosted Exchange Providers

Continuous Data Protection and Recovery for Microsoft Exchange

Related Events WinConnections and Microsoft® Exchange Connections

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Test Drive IT Solutions and Get Free Music Downloads
Solve your toughest IT problems with these free downloads and receive 5 free music downloads!

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing