none
请教各位前辈关于EXCHANGE证书配置 SSL 证书以使用多个客户端访问服务器主机名称问题 RRS feed

  • 问题

  •  

    各位高手:

     

    我参考了

    如何配置 SSL 证书以使用多个客户端访问服务器主机名称

    http://technet.microsoft.com/zh-cn/library/aa995942(EXCHG.80).aspx

    重新生成了证书,并将证书运用到"IIS POP3 IMAP4"

     

    但是我使用客户端,打开OWA后,想将新的证书安装到客户端,可是证书提示"无法将这个证书验证到一个受信任的证书颁发机构"

     

    我用客户端OFFICE OUTLOOK 2003收发邮件还是提示如下:

    您连接到的服务器正在使用一个无法验证的安全证书.

    已处理证书链,但是在不受信任提供程序信任的根证书中终止.

    您想继续使用这个服务器吗?

           是                 否

     

    我的EXCHANGE2007配置使用POP3服务.

    客户端的POP3和服务端X509CertificateName 是保持一致的.

     

     

    求助各位前辈

    是不是我哪里做的不妥!!!!

     

    2008年6月26日 14:08

答案

  • 您好!

     

    您可以通过下面的命令来查看证书的指纹。

     

    get-exchangecertificate | fl thumbprint,services

     

    在找到对应的证书后,使用下面的命令,检查该证书的CertificateDomains是否包含了runsun-service.com.如果没有的话,请修改过来然后在测试一下,看结果如何。

     

    get-exchangecertificate -thumbprint <一串字符> | fl CertificateDomains

     

    谢谢!

     

    Rock Wang 望正茂

     

    2008年7月8日 8:36
    版主

全部回复

  •  

    您好!

     

    根据您的描述,该问题可能和客户端不信任您颁发的证书有关。为了更好地分析您的问题,我想跟您确认下面这些信息:

     

    1、          请在Exchange 2007 服务器上运行下面的命令,然后将生成的结果发送到论坛中。

     

    Get-exchangecertificate | fl *

    Get-popsettings | fl

     

    2、          您使用的证书是自签名的还是通过Windows CA服务器颁发的?

    3、          检查Outlook POP3 服务器的设置的截图发送到我的邮箱:v-rocwan@microsoft.com

     

    如果通过CA颁发的话,在缺省情况下,客户端不信任该证书,您可以参考下面的链接将该证书添加到客户端的信任根存储列表中,然后在测试一下OWAPOP3登录。

     

    Add a trusted root certification authority to a Group Policy object

    http://technet2.microsoft.com/windowsserver/en/library/4b7ea7f9-311a-479b-aecc-c856165b97c11033.mspx?mfr=true

     

    谢谢!

     

    Rock Wang 望正茂

    2008年6月27日 3:07
    版主
  •  

    [PS] C:\Documents and Settings\Administrator>Get-exchangecertificate | fl *


    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {runsunad.runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : False
    KeyIdentifier        : 024A2EC4DB496EE784F2DF4E727F35821CD6565B
    RootCAType           : Registry
    Services             : None
    Status               : Valid
    PrivateKeyExportable : False
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Crypt
                           ography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security
                           .Cryptography.Oid}
    FriendlyName         :
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2009-6-26 21:23:20
    NotBefore            : 2008-6-26 21:23:20
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 6, 16, 48, 130, 4, 248, 160, 3, 2, 1, 2, 2, 10, 97...}
    SerialNumber         : 610295DD00000000000A
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : DE890D82D14B89293CE6CFDB3B3444FD26752315
    Version              : 3
    Handle               : 62795512
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=runsunad.runsun-service.com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {runsun-service.com, runsunad, runsunad.exchange.corp.runsun-service.com, autodiscover.runsun-se
                           rvice.com}
    CertificateRequest   :
    IisServices          : {IIS://runsunad/W3SVC/1}
    IsSelfSigned         : False
    KeyIdentifier        : 34D18FCA8420A6CBDC4E7563140CFDD352D9B0E1
    RootCAType           : Registry
    Services             : IMAP, POP, IIS
    Status               : Valid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Crypt
                           ography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid}
    FriendlyName         : runsun-service runsunad
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2010-6-26 20:50:40
    NotBefore            : 2008-6-26 20:50:40
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 6, 182, 48, 130, 5, 158, 160, 3, 2, 1, 2, 2, 10, 17...}
    SerialNumber         : 1109A1C5000000000009
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : B3382E2348A4416D757983ABDDD80D7442BFDDAB
    Version              : 3
    Handle               : 113474664
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=runsun-service.com, O=runsun-service Corporation, DC=runsun-service, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {exchange.runsun-service.com, runsunad, runsunad.exchange.corp.runsun-service.com, autodiscover.
                           runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : False
    KeyIdentifier        : 5710ED3E301620869A0BBD32D755892D5838E23F
    RootCAType           : Registry
    Services             : None
    Status               : Valid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Crypt
                           ography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid}
    FriendlyName         : runsun-service runsunad
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2010-6-26 20:29:04
    NotBefore            : 2008-6-26 20:29:04
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 6, 201, 48, 130, 5, 177, 160, 3, 2, 1, 2, 2, 10, 97...}
    SerialNumber         : 61F5DBE1000000000008
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : 0DED0C6B524D47484847FAFD149FA0A84CF2D132
    Version              : 3
    Handle               : 113928104
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=exchange.runsun-service.com, O=runsun-service Corporation, DC=runsun-service, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {runsun-service.com, runsunad, runsun-service, mail.runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : False
    KeyIdentifier        : 8AB20865EB806439D9A61B551704A5F6FDCB0D71
    RootCAType           : Registry
    Services             : IMAP, POP
    Status               : Valid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Crypt
                           ography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid}
    FriendlyName         : runsun-service runsunad
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2010-6-26 17:30:40
    NotBefore            : 2008-6-26 17:30:40
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 6, 147, 48, 130, 5, 123, 160, 3, 2, 1, 2, 2, 10, 97...}
    SerialNumber         : 61528398000000000007
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : 26B04F08EF82F6A0FC75ADF48D0E8010690E19B8
    Version              : 3
    Handle               : 113474744
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=runsun-service.com, O=runsun-service Corporation, DC=runsun-service, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {runsun-service.com, runsunad, mail.runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : False
    KeyIdentifier        : 1F0713447050ECEB021CE4EABE629EF860C1F313
    RootCAType           : Registry
    Services             : IMAP, POP
    Status               : Valid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Crypt
                           ography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid}
    FriendlyName         : runsun-service runsunad
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2010-6-26 17:21:26
    NotBefore            : 2008-6-26 17:21:26
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 6, 131, 48, 130, 5, 107, 160, 3, 2, 1, 2, 2, 10, 97...}
    SerialNumber         : 614A1073000000000006
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : B216793F07E6EF392D72EAC033D37541C1C01466
    Version              : 3
    Handle               : 114292496
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=runsun-service.com, O=runsun-service Corporation, DC=runsun-service, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {exchange.contoso.com}
    CertificateRequest   : MIIE+jCCA+ICAQAwazETMBEGCgmSJomT8ixkARkWA2NvbTEXMBUGCgmSJomT8ixk
                           ARkWB2NvbnRvc28xHDAaBgNVBAoTE0NvbnRvc28gQ29ycG9yYXRpb24xHTAbBgNV
                           BAMTFGV4Y2hhbmdlLmNvbnRvc28uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
                           MIIBCgKCAQEA0LVbcXSPiVG00stWmjtVhLoJ8s3TGm6yiZI/FTdPds56qf69BpWr
                           Y5IY6Cprb5gLZddf25ZoiVaS7K6rjVYDK9ZKNU4zXBbDS17gDIdb4k828tfLXZOL
                           93fHRQhmw7FziL8PHthwjO1GW5Ho4ROnhAEnp70sKYemSJo16nsWafg/MRTVVNDK
                           7GnIUjC6cxN5DuBmMUug4+WV4WWbe2aaSrVv670hvrAEinD4ppbYyzVn/lKcHSCY
                           Rr9NJTJZ2xpkNh9cM8bKPBnQhImIes+/gdtZ4+syW+g4iE8iEiQLShBoHa82tmUe
                           y2jkd9BbUjrZfBLEhdW8doFmRcad+W5L0wIDAQABoIICSDAaBgorBgEEAYI3DQID
                           MQwWCjUuMi4zNzkwLjIwXQYJKwYBBAGCNxUUMVAwTgIBAQwbcnVuc3VuYWQucnVu
                           c3VuLXNlcnZpY2UuY29tDBxSVU5TVU4tU0VSVklDRVxBZG1pbmlzdHJhdG9yDA5w
                           b3dlcnNoZWxsLmV4ZTCBygYJKoZIhvcNAQkOMYG8MIG5MB0GA1UdDgQWBBSlmyaR
                           g7IKEpIJZbsg1sclC7NDHDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8E
                           AjAAMGUGA1UdEQEB/wRbMFmCFGV4Y2hhbmdlLmNvbnRvc28uY29tggVDQVMwMYIg
                           Q0FTMDEuZXhjaGFuZ2UuY29ycC5jb25zdG9zby5jb22CGGF1dG9kaXNjb3Zlci5j
                           b250b3NvLmNvbTAOBgNVHQ8BAf8EBAMCBaAwgf0GCisGAQQBgjcNAgIxge4wgesC
                           AQEeWgBNAGkAYwByAG8AcwBvAGYAdAAgAFIAUwBBACAAUwBDAGgAYQBuAG4AZQBs
                           ACAAQwByAHkAcAB0AG8AZwByAGEAcABoAGkAYwAgAFAAcgBvAHYAaQBkAGUAcgOB
                           iQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                           AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                           AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMA0GCSqG
                           SIb3DQEBBQUAA4IBAQCe5wrh7DDEp1F/E33WkG3v2tO7cnNgoJ6oP9z0Wxb/ANTs
                           Ulle5eioo5Kin1iHs684K8ll+CFbmKmd+W8Gvz7Fz5S+f0Zn1WlzzRP04iiIL8cB
                           PgbE4FNvAm84mqGF4xtWOkP1QiX3ylhHfepp1wjiCFlwpLvYkwfGJvKzflEo8ghf
                           Ye9xA8cvoOVJljjM2L+3c1DOv3KDueX5XSho8hR9rdSei/UfmTvxuS45CcwCC8Mq
                           cRE/ewcN0qp7wil8oVsKIX8e2cTwZrznMWtTBIVqiOBJ2mUXEboI0CWmxm1Bhg9T
                           PSzAEiuNLEEJJkeMXsCJXdkgJo9tPXOlmcRcLQVx
    IisServices          : {}
    IsSelfSigned         : True
    KeyIdentifier        : 1D50B45D9A1422C52C02F63A34BE376265D5A900
    RootCAType           : Unknown
    Services             : None
    Status               : Invalid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {}
    FriendlyName         : Microsoft Exchange
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2009-6-26 23:18:32
    NotBefore            : 2008-6-26 17:18:32
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 2, 85, 48, 130, 2, 66, 160, 3, 2, 1, 2, 2, 16, 219...}
    SerialNumber         : DB7E3EB640206D88432830C07010E800
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : EA98EEFBD5E4777545D93E7C59BB67005A0179D7
    Version              : 3
    Handle               : 114301696
    Issuer               : CN=exchange.contoso.com, O=Contoso Corporation, DC=contoso, DC=com
    Subject              : CN=exchange.contoso.com, O=Contoso Corporation, DC=contoso, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {exchange.contoso.com}
    CertificateRequest   : MIIE+jCCA+ICAQAwazETMBEGCgmSJomT8ixkARkWA2NvbTEXMBUGCgmSJomT8ixk
                           ARkWB2NvbnRvc28xHDAaBgNVBAoTE0NvbnRvc28gQ29ycG9yYXRpb24xHTAbBgNV
                           BAMTFGV4Y2hhbmdlLmNvbnRvc28uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
                           MIIBCgKCAQEAngtCF9mJ+RXYFJdtICMJde8PWOE30/8LIsI69rSTbFzIypxDFTVe
                           FJApMntZRytZTyJLW9pI/j5nJvAF3hnrmjQi1PVAqK37fodA+iNrInrO3EzJEuux
                           jmJIyHFJm3gYKjTpHt5xPYg4DJSKh/FRXdCQoyVsaoCVCvf7Hc89deQ0sJfOxw+x
                           9F3MrQ4z78nS/MIbcZHq0uye9gYQVACnXsA3LdS3bDpB/8pSBmd2ipvG/a9IVOkh
                           vwE88x89WHOzoxmecZM9lJxmYV+MdxYKEu9FEjzvYr2c4qkCvIQA7O6B+pkk67b3
                           gT73GRX3b1Tqy3V9f8CM7dM0vqoxDzLM3QIDAQABoIICSDAaBgorBgEEAYI3DQID
                           MQwWCjUuMi4zNzkwLjIwXQYJKwYBBAGCNxUUMVAwTgIBAQwbcnVuc3VuYWQucnVu
                           c3VuLXNlcnZpY2UuY29tDBxSVU5TVU4tU0VSVklDRVxBZG1pbmlzdHJhdG9yDA5w
                           b3dlcnNoZWxsLmV4ZTCBygYJKoZIhvcNAQkOMYG8MIG5MB0GA1UdDgQWBBQKI/z+
                           u0+UOqxcqo4QgRkNkWb58zATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8E
                           AjAAMGUGA1UdEQEB/wRbMFmCFGV4Y2hhbmdlLmNvbnRvc28uY29tggVDQVMwMYIg
                           Q0FTMDEuZXhjaGFuZ2UuY29ycC5jb25zdG9zby5jb22CGGF1dG9kaXNjb3Zlci5j
                           b250b3NvLmNvbTAOBgNVHQ8BAf8EBAMCBaAwgf0GCisGAQQBgjcNAgIxge4wgesC
                           AQEeWgBNAGkAYwByAG8AcwBvAGYAdAAgAFIAUwBBACAAUwBDAGgAYQBuAG4AZQBs
                           ACAAQwByAHkAcAB0AG8AZwByAGEAcABoAGkAYwAgAFAAcgBvAHYAaQBkAGUAcgOB
                           iQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                           AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                           AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMA0GCSqG
                           SIb3DQEBBQUAA4IBAQCB66uk4lcaFzW7+yj9BFXl/hx1C2NLC3fs4PLDhgAI7bo7
                           Ycn7A+Zk4QEk1L1dE3fyHr7DucrJU6j0zaLfpxPPOAeaAI9XGeP+/2reDxRI8BK7
                           ZYUV3ms95GBqnjwXhyvyjcSPOhsxIWL8g3FWe4loCiL6uTALAC6TEs69QE12v8sU
                           gjrJ7Ba1Cr5TtZEU6pSI/DFWBsvAhTkxbKJVcDTp+QkhUGKzE9PxGDpzbV66jveA
                           hQXlS2y5MzpUWkG04FaVp9HtgHxU3t0JMa3i1mcT7K8iWEhlBhFTLTNJ5Mwt1Cum
                           SSr1hAWSxkT6w7pAk11cMZ28fTxMli4TO/hqqMYn
    IisServices          : {}
    IsSelfSigned         : True
    KeyIdentifier        : 0EA37C3BB44FC8AD921B2A6EEF69A0028372E94E
    RootCAType           : Unknown
    Services             : None
    Status               : Invalid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {}
    FriendlyName         : Microsoft Exchange
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2009-6-26 23:14:32
    NotBefore            : 2008-6-26 17:14:32
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 2, 85, 48, 130, 2, 66, 160, 3, 2, 1, 2, 2, 16, 65...}
    SerialNumber         : 41AAB8D609EBEFB241B1E46B1A876004
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : 4CF807C62EE87304052DC4EC946E133279971746
    Version              : 3
    Handle               : 113867984
    Issuer               : CN=exchange.contoso.com, O=Contoso Corporation, DC=contoso, DC=com
    Subject              : CN=exchange.contoso.com, O=Contoso Corporation, DC=contoso, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule}
    CertificateDomains   : {runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : True
    KeyIdentifier        : 7B8DE584347718B57051F62C399B65D5B9EE0915
    RootCAType           : Registry
    Services             : IMAP, POP
    Status               : Valid
    PrivateKeyExportable : True
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid}
    FriendlyName         :
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2013-6-26 16:29:33
    NotBefore            : 2008-6-26 16:21:35
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 4, 170, 48, 130, 3, 146, 160, 3, 2, 1, 2, 2, 16, 41...}
    SerialNumber         : 2979946C7C6307A64A0AE9EB84675F9F
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : 2C15D8628A5772A77224F9DCC3091310DC1A7E4D
    Version              : 3
    Handle               : 113813424
    Issuer               : CN=runsun-service.com, DC=runsun-service, DC=com
    Subject              : CN=runsun-service.com, DC=runsun-service, DC=com

    AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, System.Security.AccessControl.CryptoKeyAcces
                           sRule, System.Security.AccessControl.CryptoKeyAccessRule}
    CertificateDomains   : {runsunad, runsunad.runsun-service.com}
    CertificateRequest   :
    IisServices          : {}
    IsSelfSigned         : True
    KeyIdentifier        : C60F04B19380AC1BE65A809D5DFEDCAB95C2D3F9
    RootCAType           : Unknown
    Services             : SMTP
    Status               : Valid
    PrivateKeyExportable : False
    Archived             : False
    Extensions           : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptograph
                           y.Oid, System.Security.Cryptography.Oid}
    FriendlyName         : Microsoft Exchange
    IssuerName           : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    NotAfter             : 2009-6-25 18:29:06
    NotBefore            : 2008-6-25 18:29:06
    HasPrivateKey        : True
    PrivateKey           : System.Security.Cryptography.RSACryptoServiceProvider
    PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
    RawData              : {48, 130, 3, 23, 48, 130, 1, 255, 160, 3, 2, 1, 2, 2, 16, 35...}
    SerialNumber         : 2373F97D5E8B39A14550EE2C5D9A3234
    SubjectName          : System.Security.Cryptography.X509Certificates.X500DistinguishedName
    SignatureAlgorithm   : System.Security.Cryptography.Oid
    Thumbprint           : 62DAC0B7AAE8A539326CCBC94CD4D655B82D4F3D
    Version              : 3
    Handle               : 114204344
    Issuer               : CN=runsunad
    Subject              : CN=runsunad

     

    [PS] C:\Documents and Settings\Administrator>

     

     

     

     

     

     

     

     

    [PS] C:\Documents and Settings\Administrator>Get-popsettings | fl


    Name                              : 1
    ProtocolName                      : POP3
    MaxCommandSize                    : 45
    MessageRetrievalSortOrder         : Descending
    UnencryptedOrTLSBindings          : {0000:0000:0000:0000:0000:0000:0.0.0.0:110, 0.0.0.0:110}
    SSLBindings                       : {0000:0000:0000:0000:0000:0000:0.0.0.0:995, 0.0.0.0:995}
    X509CertificateName               : runsun-service.com
    Banner                            : The Microsoft Exchange POP3 service is ready.
    LoginType                         : SecureLogin
    AuthenticatedConnectionTimeout    : 00:30:00
    PreAuthenticatedConnectionTimeout : 00:01:00
    MaxConnections                    : 2000
    MaxConnectionFromSingleIP         : 2000
    MaxConnectionsPerUser             : 16
    MessageRetrievalMimeFormat        : BestBodyFormat
    ProxyTargetPort                   : 110
    CalendarItemRetrievalOption       : iCalendar
    OwaServerUrl                      :
    AdminDisplayName                  :
    ExchangeVersion                   : 0.1 (8.0.535.0)
    DistinguishedName                 : CN=1,CN=POP3,CN=Protocols,CN=RUNSUNAD,CN=Servers,CN=Exchange Administrative Group (
                                        FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Runsun Organization,CN=Microsoft Excha
                                        nge,CN=Services,CN=Configuration,DC=runsun-service,DC=com
    Identity                          : RUNSUNAD\1
    Guid                              : cf297fac-68a4-486f-95b6-de1efa332c0f
    ObjectCategory                    : runsun-service.com/Configuration/Schema/ms-Exch-Protocol-Cfg-POP-Server
    ObjectClass                       : {top, protocolCfg, protocolCfgPOP, protocolCfgPOPServer}
    WhenChanged                       : 2008-6-26 21:01:11
    WhenCreated                       : 2008-6-25 18:34:02
    OriginatingServer                 : runsunad.runsun-service.com
    IsValid                           : True

     

    [PS] C:\Documents and Settings\Administrator>

    2008年6月30日 13:55
  •  您好!

     

    根据您提供的Get-exchangecertificate.txt文件,我发现您一共有七张证书,还有两个证书请求。请删除不需要的证书和证书请求。然后在运行Get-exchangecertificate | fl * >c:\cer.txt,将生成的txt文件发送到我的邮箱。同时,请将应用给POP3服务的证书的指纹发送到论坛中。

     

    为了避免您的邮件和其他用户的混淆,请在邮件标题栏填写您发的帖子的标题

     

    谢谢!

     

    Rock Wang 望正茂

     

    2008年7月2日 12:08
    版主
  •  

    -----BEGIN NEW CERTIFICATE REQUEST-----
    MIIFFzCCA/8CAQAwdzETMBEGCgmSJomT8ixkARkWA2NvbTEeMBwGCgmSJomT8ixk
    ARkWDnJ1bnN1bi1zZXJ2aWNlMSMwIQYDVQQKExpydW5zdW4tc2VydmljZSBDb3Jw
    b3JhdGlvbjEbMBkGA1UEAxMScnVuc3VuLXNlcnZpY2UuY29tMIIBIjANBgkqhkiG
    9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2ShZA7fLVpcob3JV1rrGU6mw/BhOnBmZW7P
    wa15sn1qm2J70IqUGeIEE/GjCfg2xfKDxa89uz7qX2nEE0F8Y7Srs4XtumOS17aa
    J/+S1wDXDalnUgcOT2DFt+lsB46bFzLzhd+tcfNt6WpsrQ4rbVLh42Jx2i1vYluq
    ZpJBEAOztmBFnNyz7xd8mRJEnX69hoZnNItsL/UjdcbZEJ+VA9KPoNpqPoY38B0J
    dlgY2MOmFon0ZmKBR7JSUJCUuvZMPXJlsriVGiCsubEITCuWeZTfx7m40Y4pMtYR
    Oumi6yhtQ59mL/ROrxO2YPaSP11414HFqmVMKMFndUz4pD93QwIDAQABoIICWTAa
    BgorBgEEAYI3DQIDMQwWCjUuMi4zNzkwLjIwXQYJKwYBBAGCNxUUMVAwTgIBAQwb
    cnVuc3VuYWQucnVuc3VuLXNlcnZpY2UuY29tDBxSVU5TVU4tU0VSVklDRVxBZG1p
    bmlzdHJhdG9yDA5wb3dlcnNoZWxsLmV4ZTCB2wYJKoZIhvcNAQkOMYHNMIHKMB0G
    A1UdDgQWBBQusOEBd4Wem7F897/PWpmE3ZlAOzATBgNVHSUEDDAKBggrBgEFBQcD
    ATAMBgNVHRMBAf8EAjAAMHYGA1UdEQEB/wRsMGqCEnJ1bnN1bi1zZXJ2aWNlLmNv
    bYIIcnVuc3VuYWSCKXJ1bnN1bmFkLmV4Y2hhbmdlLmNvcnAucnVuc3VuLXNlcnZp
    Y2UuY29tgh9hdXRvZGlzY292ZXIucnVuc3VuLXNlcnZpY2UuY29tMA4GA1UdDwEB
    /wQEAwIFoDCB/QYKKwYBBAGCNw0CAjGB7jCB6wIBAR5aAE0AaQBjAHIAbwBzAG8A
    ZgB0ACAAUgBTAEEAIABTAEMAaABhAG4AbgBlAGwAIABDAHIAeQBwAHQAbwBnAHIA
    YQBwAGgAaQBjACAAUAByAG8AdgBpAGQAZQByA4GJAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwDQYJKoZIhvcNAQEFBQADggEBAIhJRAFi
    kMIItpdderqkQUqOrhIOk1gNt+AEX4JH8zlHFZ9ffbcr28/VMWLnRjaBHOmw83Wo
    /4WEEODjufHjQCygtjhunyeuhsI7E4d/YPxjMUZi+47j8QnX20y1Hmz7LFc8ScEf
    MtXQR+zoOmffS+tToWwPvs0Ns07RbDVCndqmPxPvsX6L17LnESOt7qiShpTP/rLf
    9cR/gu81EPsq2AplfPQ+sFM8+Ih5t76w+HSqedx/xzh4C8gGici7niL158pxoAOo
    Mcxlf0avZUgtubaw4WSK2wU7Gnwzk9uCg6xYMW/Nsx/BosDE812EzkaEhHkJqTol
    FkiS/wOhbPJpusU=
    -----END NEW CERTIFICATE REQUEST-----
    2008年7月4日 3:35
  • 您好!

     

    您可以通过下面的命令来查看证书的指纹。

     

    get-exchangecertificate | fl thumbprint,services

     

    在找到对应的证书后,使用下面的命令,检查该证书的CertificateDomains是否包含了runsun-service.com.如果没有的话,请修改过来然后在测试一下,看结果如何。

     

    get-exchangecertificate -thumbprint <一串字符> | fl CertificateDomains

     

    谢谢!

     

    Rock Wang 望正茂

     

    2008年7月8日 8:36
    版主