programming4us
programming4us
ENTERPRISE

Exchange Server 2010 : Installing OCS 2007 R2 (part 4) - Configuring the Server & Configuring Certificates for OCS

2/27/2011 10:04:29 AM

Configuring the Server

After the server software has been installed, OCS services are not started by default. Instead, the Deployment Wizard encourages administrators to configure certain settings first before doing so. To configure these settings, follow this procedure:

1.
From the Deployment Wizard, click Run under Step 2 (Configure Server).

2.
Click Next at the welcome screen.

3.
Select the appropriate pool from the drop-down list shown in Figure 13, and click Next to continue.

Figure 13. Configuring the OCS server.

4.
If any additional SIP domains are needed in the environment, enter them in the subsequent dialog box. If not, accept the default of the domain name (for example, corp-events.com), and click Next.

5.
Under Client Logon Settings, select that all clients will use DNS SRV records for auto logon, and click Next to continue.

6.
Check the domain or domains that will be used for SIP automatic logon, such as that shown in Figure 14, and click Next to continue.

Figure 14. Selecting SIP domains for automatic logon.

7.
In the External User Access Configuration dialog box, select to not configure external user access now. External user access can be configured at a later date from the Admin tool. Click Next to continue.

8.
Click Next at the Verification dialog box.

9.
Click Finish.

Configuring Certificates for OCS

Communications to and from the OCS server should ideally be encrypted and the user should also be able to trust that they are actually accessing the server that they expect. For this reason, Microsoft made it part of the installation process to install certificates onto the OCS server. To start the process of installing a certificate on the server, perform the following steps:

1.
From the Deployment Wizard, click Run under Step 3 (Configure Certificate).

2.
Click Next at the welcome screen.

3.
From the list of available tasks, shown in Figure 15, select Create a New Certificate, and click Next.

Figure 15. Creating a new certificate for the OCS server.

4.
Select Send the Request Immediately to an Online Certification Authority, and click Next to continue.

Note

This step assumes that a trusted Windows Enterprise certificate authority exists in the organization. If not, the request must be sent to a globally trusted third-party certificate authority.

5.
Type a descriptive name for the certificate; leave the bit length at 1024 and the certificate as exportable but select Include client EKU in the certificate request, and click Next to continue.

6.
Enter the organization and OU of your organization. It should exactly match what is on file with the CA. Click Next to continue.

7.
At the Your Server’s Subject Name dialog box, enter the subject name of the server (FQDN in which it will be accessed), such as that shown in Figure 16. Enter any subject alternate names as well, such as sip.domain.com and sipinternal.domain.com. It is recommended to check Automatically Add Local Machine Name to Subject Alt Name check box. Click Next to continue.

Figure 16. Entering the server’s subject name.

8.
Enter the appropriate country, state, and city information into the Geographical Information dialog box, bearing in mind that abbreviations cannot be used. Click Next to continue.

9.
Select the local CA from the drop-down list, and click Next to continue.

10.
Click Next at the Verification dialog box.

11.
In the Success dialog box, click Assign certificate immediately; click Next.

12.
Click Next to acknowledge that the settings were applied.

13.
Click Finish to exit the wizard.

14.
Next, assign the certificate in IIS using the IIS Manager Console.

After the certificate is installed, check to make sure that the changes have replicated.

Other  
  •  Integrating Office Communications Server 2007 in an Exchange Server 2010 Environment - Understanding Microsoft’s Unified Communications Strategy
  •  Protecting SharePoint 2010 from Viruses Using Forefront Protection 2010 for SharePoint
  •  Protecting SharePoint with Advanced Antivirus and Edge Security Solutions : Securing SharePoint Sites Using Forefront UAG
  •  Developing Applications for the Cloud on the Microsoft Windows Azure Platform : Accessing the Surveys Application - Geo-Location
  •  Developing Applications for the Cloud on the Microsoft Windows Azure Platform : DNS Names, Certificates, and SSL in the Surveys Application
  •  Securing SharePoint Sites with Forefront TMG 2010 (part 2) - Creating a SharePoint Publishing Rule Using Forefront TMG
  •  Securing SharePoint Sites with Forefront TMG 2010 (part 1) - Configuring the Alternate Access Mapping Setting for the External URL
  •  SharePoint 2010 : Outlining the Inherent Threat in SharePoint Web Traffic
  •  SharePoint 2010 : Outlining the Need for the Forefront Edge Line for SharePoint Environments
  •  Collaborating Within an Exchange Server Environment Using Microsoft Office SharePoint Server 2007 : Customizing and Developing MOSS Sites
  •  
    video
     
    Video tutorials
    - How To Install Windows 8

    - How To Install Windows Server 2012

    - How To Install Windows Server 2012 On VirtualBox

    - How To Disable Windows 8 Metro UI

    - How To Install Windows Store Apps From Windows 8 Classic Desktop

    - How To Disable Windows Update in Windows 8

    - How To Disable Windows 8 Metro UI

    - How To Add Widgets To Windows 8 Lock Screen

    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010
    programming4us programming4us
    programming4us
     
     
    programming4us