Lync 2010 – Part 5 – Front End SSL Certificate

Hello.  I don't know if I'll ever actually finish this series.  I just haven't had time to sort through all my documentation, but, as people ask me questions, I'm looking closely for those pieces/parts to blog through them.

For those of you that have paid attention:

In Part 1 – We discussed the goals and prepped the environment

In Part 2 – We focused on Topology

In Part 3 – We discussed CA/PKI

In Part 4 – We finished DNS Prep and installed Lync

Then I fell off the face of the earth for a few months…

Lately, I have been asked how to use the CA/PKI environment setup in Part 3 to actually request / assign an SSL Certificate for the Front End.  Let's do that now…

Go back to your Lync 2010 Front End Server.  Launch the Lync Server 2010 Deployment Wizard.

A

Click Install or Update Lync Server System

B

Choose Request, Install or Assign Certificate

C

Click Request

1

Send the request immediately.  Click Next.

2

Select your CA.  TMGAD02 is the right one here.  Click Next.

3

No special credentials needed.  Click Next.

4

No special template needed.  Click Next.

5

Friendly Name for the certs… 2048 bit… Mark key for exportable.  Click Next.

6

Org info.  Click Next.

7

Geo info.  Click Next.

8

These names were pulled from the topology.  Click Next.

9

Which SIP domains to include?  Click Next.

10

Any any other SANs based on your topology.  Click Next.

11

Review.  Click Next.

12

Request completed.  Click Next.

13

CA Responded with a cert.  Assign.  Click Finish.

14

Yes please.  Click View Details.

15

Verify Common Name & SANs.  Click OK.  Click Next.

16

Yup.  Click Next.

17

Completed.  Click Finish.

18

Good work.  All assigned.  Time to move on.  Click Close.

So, that's how you request & assign your Front End SSL Certificate.  The key points to remember are – each URL you input in your Topology for Dialin, Admin, Meetings, etc. – each of those need to be included as a Subject Alternative Name (SAN) on your SSL Certificate.  If any of them are missing, you'll get warnings and popups when going to the Control Panel, when launching Lync, etc.

I guess next it would make sense if I actually showed you how to activate a user for Lync.  Let's see if I can do that by Christmas…