unable to delete old exchange SSL certificate

Dilan Nanayakkara 1,111 Reputation points
2020-09-26T07:18:54.527+00:00

Hi All,

I have imported and installed a new ssl certificate in our Exchange server and then ran a HCM wizard and select a new certificate for the send connector. however when I tried to delete the previous certificate below error message has popped up. one thing is the previous certificate also vaild till 25/11/2020 and we have renewed early. but I think it won't be a problem with deleting a previous one since we already installed a new certificate. we have only one exchange server in our environment.

appreciate any one can help here to resolve this.

28410-image01.jpg

28386-image02.jpg

28329-image03.jpg

28387-image04.jpg

28388-image05.jpg

Thanks,
Dilan

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,335 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,875 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 141K Reputation points MVP
    2020-09-26T11:51:27.51+00:00

    Hi there, I have seen that many times!

    The solution is to open the local certificate store on the Exchange server for the local computer.
    Type at the RUN Menu:
    certlm.msc

    28504-image.png

    https://learn.microsoft.com/en-us/dotnet/framework/wcf/feature-details/how-to-view-certificates-with-the-mmc-snap-in

    Find the OLD cert that you want to remove under the "Personal" container and delete it from there by right-clicking on it and choosing delete. Make sure you choose the old one ( verify by date and thumbprint.
    After that , do an IIRESET to ensure its removed and you are good.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Lydia Zhou - MSFT 2,371 Reputation points Microsoft Employee
    2020-09-28T06:10:50.693+00:00

    @Dilan Nanayakkara

    Agree with AndyDavid. Since you have assigned the new certificate to POP, IMAP, IIS, SMTP services, and if you also have re-run HCW, the mail flow should work well with the new certificate. You can remove the old cert from Personal store, then try to delete the old certificate again.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments