Integrations

Microsoft Exchange Certificate Automation

First-Party Windows Target

SSLNexus uses the existing WinRM/PowerShell provisioner and Exchange certificate cmdlets. Exchange generates and retains its private key; SSLNexus retrieves the CSR and returns the signed certificate.

Workflow

  1. Register the Exchange server as a Windows target.
  2. Select the Exchange services SSLNexus may bind: IIS, SMTP, POP and/or IMAP.
  3. SSLNexus runs New-ExchangeCertificate -GenerateRequest with a non-exportable private key.
  4. The target-bound CA signs the CSR.
  5. SSLNexus runs Import-ExchangeCertificate, followed by Enable-ExchangeCertificate for the explicitly selected services.
  6. Get-ExchangeCertificate verifies the resulting certificate state.
Key custody: the private key remains in the Exchange certificate store.

Related Documentation

Deployment targets · CA connectors · Dependency & Impact