Skip to content

← All integrations

Windows · Mail server

Replaces the certificate on Exchange services, IIS bindings and send and receive connectors.

The service agent on the server fetches the task from the appliance over outbound HTTPS on port 443 and installs the certificate locally on the server. The appliance never connects to the server.

What happens

  1. The service agent on the server fetches the task from the appliance over outbound HTTPS, port 443.
  2. The certificate is imported into the Windows certificate store. If its names do not cover the names the server answers to, it is not bound.
  3. The certificate is enabled for the chosen Exchange services. IIS bindings and connectors that used the previous one are moved over. If it fails: Rollback puts services, IIS bindings and connectors back as they were.
  4. Verification: the package checks the binding per service and connector, and that the names cover the server.

Technical details

Connection
The package runs through the service agent on the server. The agent connects over outbound HTTPS to the appliance, port 443 by default. You open no port into the server.
Service ports
25, 443, 465, 587, 993, 995
You need
The service agent installed on the server.
Platform
Exchange 2013 and 2016 from CU23, 2019 from CU13 and Subscription Edition, Windows Server 2012 R2 and later
Actions
Discovery, Installation, Verification, Rollback
Packages
exchange2013-2019windows-exchange
Note
  • Risky changes such as the Auth certificate are off by default. The Edge subscription certificate is left alone.

Get started