Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 01, 2007

Certificates and Exchange, Part 3


RSS
Subscribe to Windows IT Pro | See More Certificates Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Back in September I wrote a pair of columns about how Exchange Server 2007 uses certificates ("Certificates and Exchange, Part 1," September 7, 2006, and "Certificates and Exchange, Part 2," September 14, 2006). I pointed out the utility of having multiple subject names, or subjectAltNames, in a single certificate; this ability allows you to have a single certificate that works with, for example, autodiscover.yourdomain.com, mail.yourdomain.com, and the underlying Fully Qualified Domain Name (FQDN). Unfortunately, as far as I could tell at the time, no commercial Certificate Authorities (CAs) were issuing such certificates.

However, circumstances seem to be changing; there are now several CAs that issue certificates that allow multiple subjectAltNames. For example, last week I got an email message from Andrew Codrington at Entrust. His company just introduced Entrust Unified Communications Certificates as part of its partnership with Microsoft. The certificate includes 10 subjectAltNames for $599 per year, with the option of adding three more subjectAltNames for an additional $99.

Entrust isn’t the only CA offering these certificates, either. GeoTrust sells the Power Server ID certificate with as many as four subjectAltNames for $599.

Are these certificates good deals? Maybe. The price is certainly steep when compared to lower-cost (and, arguably, lower-security) certificates from smaller CAs such as GoDaddy.com (which, to my knowledge, still doesn’t sell multiple subjectAltNames certificates). The price difference is even more dramatic when you compare these certificates to the cost of using the self-generated certificates that Exchange 2007 installs. However, there are two things you should keep in mind when evaluating these certificates.

The first thing to think about, of course, is security. You can certainly use self-signed certificates (either the ones Exchange 2007 generates or ones generated by your CA) with Exchange, but users will see certificate warnings unless you also configure their browsers and mobile devices with your root certificates. If you don’t do so, users will have to dismiss security warnings to use Office Outlook 2007 or OWA 2007, which essentially trains them to ignore those warnings—not something you want to do.

The second factor to consider is the combination of cost and hassle. Say you want to set up Autodiscover, OWA, and SSL-protected SMTP. Buying a single certificate for $599 might seem like an extravagance until you factor in the time it would take to purchase, install, and configure separate certificates for each of these services. A high-security certificate from a major CA might cost anywhere from $75 to $200 per year, depending on the renewal term and the level of validation you purchase; buying four or five such certificates might end up costing you more than a single certificate with multiple subjectAltNames attached. You’ll have to evaluate how much time it would take to deploy multiple certificates to figure out whether the cost/benefit ratio makes sense.

One interesting aspect to the appearance of CAs that sell certificates with multiple subjectAltNames attributes is that I expect the demand for wildcard certificates to drop significantly. Most organizations don’t want certificates that will match any host on their network, only a subset. Windows Mobile 5.0 can’t handle wildcard certificates, making it impractical to use them for securing Exchange ActiveSync and OWA.

I’ll be testing Entrust’s certificate and will report back on what I find. In the meantime, drop me a note to let me know what certificate services you anticipate needing for your Exchange 2007 deployment plans.

End of Article



Reader Comments
So now we need Windows Certificate Services to have the ability to do AltSubjectName properties.

brainier February 02, 2007 (Article Rating: )


No; you can use 3rd-party CAs provided you pick one that supports multiple SANs.

paulrobichaux February 02, 2007 (Article Rating: )


Do I understand this correctly--the cert can contain different domain names as well as hostnames? Your example is very close to a wildcard cert.

sfrank8734 February 06, 2007 (Article Rating: )


It's like a wildcard cert but for a fixed set of names. That makes it more trustworthy than a wildcard cert in terms of being able to validate the originating host name, and it works with Windows Mobile, which doesn't support wildcard certs.

paulrobichaux February 06, 2007 (Article Rating: )


This sounds great to me. Some of my certs need renewing later in the year and I'll definitely look into this route instead, it'll be a lot less hassle.

cstenson February 07, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...

Microsoft Delivers Service Pack 2 Beta 2 for Vista, Server 2008

Microsoft on Tuesday announced the availability of the Beta 2 version of Service Pack 2 (SP2) for Windows Vista and Windows Server 2008. Since both operating systems were developed from the same code base, they have a common servicing structure and thus ...


Related Articles Securing Exchange Server 2007 Services with ISA Server 2006

Exchange Server and Outlook Whitepapers Protecting (You and) Your Data with Exchange Server 2007

StoreVault SnapManagers for Microsoft Exchange and SQL Server

Related Events Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

The Myths & Truths of Email Management with SharePoint

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing