tarian 发表于 2008-8-26 15:03:46

是啊.再把这个CA证书导进去吗?就像在客户端一样导入,对吗?

导入了,在EX服务器上再看IIS上的证书,没有问题了.在certmgr中也看到新导入的证书啦.
你说的指纹是什么东东呢?

[ 本帖最后由 tarian 于 2008-8-26 15:07 编辑 ]

tdk 发表于 2008-8-26 15:06:15

对,导入后再看看 还有没有问题
再看看 get-exchangecer |fl * 状态时候还是无效

tarian 发表于 2008-8-26 15:09:48

C:\>Get-ExchangeCertificate | fl * >aa.txt

AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, Syst
                     em.Security.AccessControl.CryptoKeyAccessRule, System.Se
                     curity.AccessControl.CryptoKeyAccessRule}
CertificateDomains   : {taihu.test.com, mail.test.com, suzhou.test.com, auto
                     discover.test.com}
CertificateRequest   :
IisServices          : {IIS://mail/W3SVC/1}
IsSelfSigned         : False
KeyIdentifier      : 1522C62121D92EBA1F402FA21405B2AA583F16A4
RootCAType         : Unknown
Services             : IMAP, POP, IIS, SMTP
Status               : Unknown
PrivateKeyExportable : False
Archived             : False
Extensions         : {System.Security.Cryptography.Oid, System.Security.Crypt
                     ography.Oid, System.Security.Cryptography.Oid, System.Se
                     curity.Cryptography.Oid, System.Security.Cryptography.Oi
                     d, System.Security.Cryptography.Oid, System.Security.Cry
                     ptography.Oid, System.Security.Cryptography.Oid}
FriendlyName         : test.com
IssuerName         : System.Security.Cryptography.X509Certificates.X500Distin
                     guishedName
NotAfter             : 8/26/2010 10:30:26 AM
NotBefore            : 8/26/2008 10:30:26 AM
HasPrivateKey      : True
PrivateKey         : System.Security.Cryptography.RSACryptoServiceProvider
PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
RawData            : {48, 130, 6, 5, 48, 130, 4, 237, 160, 3, 2, 1, 2, 2, 10,
                        16...}
SerialNumber         : 102BFD18000000000003
SubjectName          : System.Security.Cryptography.X509Certificates.X500Distin
                     guishedName
SignatureAlgorithm   : System.Security.Cryptography.Oid
Thumbprint         : 423CC2EE51214813DE3D24073E5BACC755614C05
Version            : 3
Handle               : 122018056
Issuer               : CN=taihu, DC=test, DC=com
Subject            : CN=taihu.test.com, O=Qinghe Tech, DC=test, DC=com

AccessRules          : {System.Security.AccessControl.CryptoKeyAccessRule, Syst
                     em.Security.AccessControl.CryptoKeyAccessRule}
CertificateDomains   : {mail.test.com}
CertificateRequest   :
IisServices          : {}
IsSelfSigned         : False
KeyIdentifier      : 4237099FB01E2FDF50A2717EF06146F95006DD28
RootCAType         : Unknown
Services             : None
Status               : Invalid
PrivateKeyExportable : False
Archived             : False
Extensions         : {System.Security.Cryptography.Oid, System.Security.Crypt
                     ography.Oid, System.Security.Cryptography.Oid, System.Se
                     curity.Cryptography.Oid, System.Security.Cryptography.Oi
                     d, System.Security.Cryptography.Oid, System.Security.Cry
                     ptography.Oid, System.Security.Cryptography.Oid, System.
                     Security.Cryptography.Oid}
FriendlyName         :
IssuerName         : System.Security.Cryptography.X509Certificates.X500Distin
                     guishedName
NotAfter             : 8/12/2009 7:02:34 PM
NotBefore            : 8/12/2008 7:02:34 PM
HasPrivateKey      : True
PrivateKey         : System.Security.Cryptography.RSACryptoServiceProvider
PublicKey            : System.Security.Cryptography.X509Certificates.PublicKey
RawData            : {48, 130, 5, 102, 48, 130, 4, 78, 160, 3, 2, 1, 2, 2, 10
                     , 17...}
SerialNumber         : 11BA316A000000000005
SubjectName          : System.Security.Cryptography.X509Certificates.X500Distin
                     guishedName
SignatureAlgorithm   : System.Security.Cryptography.Oid
Thumbprint         : 8D74E18C1F73E50825CE530445FE1EDF7582971C
Version            : 3
Handle               : 121581320
Issuer               : CN=taihu, DC=test, DC=com
Subject            : CN=mail.test.com

tarian 发表于 2008-8-26 15:16:54

好像还没有对啊.状态是未知.
从返回的内容来看,有两个证书.一个是多域证书,一个是单域证书.
多域证书的状态是未知,而单域的证书是无效.

[ 本帖最后由 tarian 于 2008-8-26 15:18 编辑 ]

akin520 发表于 2008-8-27 12:44:29

恩,证书我们从命令行导入的,而不是在IIS那里面导入

tarian 发表于 2008-8-27 14:09:22

现在的证书我都是使用命令导入了.
依然有问题啊.
页: 1 2 3 4 [5]
查看完整版本: Exchange 2k7's outlook Anywhere证书问题