In Exchange 2019, you can generate a new CSR and then import the signed certificate from your registrar like Digicert or RapidSSL or Godaddy etc.
To generate a CSR in Exchange 2019, you can run the following command from the Exchange Management Shell (EMS):
- $cert = New-ExchangeCertificate -GenerateRequest -SubjectName “C=ZA,o=thexchangelab,cn=thexchangelabcert” -DomainName “thexchangelab.com” -PrivateKeyExportable $true
data:image/s3,"s3://crabby-images/02c8b/02c8b2c7bce0773bcf00fe012d53b0c3a25499c3" alt="Exchange 2019 - create a new mailbox with powershell Exchange 2019 - create a new mailbox with powershell"
Once the command has run, you can now run the following command to export the information to a text file:
- $cert | out-file c:\Installs\certreq.txt
data:image/s3,"s3://crabby-images/38f02/38f02f7df9aab5dbb395912b87693e7a8e026fe3" alt="Exchange 2019 - create a new mailbox with powershell Exchange 2019 - create a new mailbox with powershell"
Now if we head over to the location that we specified in the second command we will see the generated CSR:
data:image/s3,"s3://crabby-images/99509/9950993bc5f2aaff1cfc259f15641654861f9cbd" alt="Exchange 2019 - create a new mailbox with powershell Exchange 2019 - create a new mailbox with powershell"
Once we have received our new file from our provider, we can complete the request by running the following command:
- Import-ExchangeCertificate -FileName “C:\Location\CertName.cer”
data:image/s3,"s3://crabby-images/f70cd/f70cd11b67cb48c4eb656abaf508963e290d3193" alt="Exchange 2019 - create a new mailbox with powershell Exchange 2019 - create a new mailbox with powershell"
As you can see, it is now imported, the last step is to assign services to the certificate which you can achieve by running this command:
- Enable-ExchangeCertificate -Thumbprint “xxxx” -Services SMTP,IIS
data:image/s3,"s3://crabby-images/45de4/45de4384974911f753a43a9e0d2111ed3897d8a0" alt="Exchange 2019 - create a new mailbox with powershell Exchange 2019 - create a new mailbox with powershell"
You will be prompted if you want to overwrite the default certificate, you can choose yes and all will be completed.
Hope it helps.