{"id":267,"date":"2014-06-20T18:41:34","date_gmt":"2014-06-21T00:41:34","guid":{"rendered":"http:\/\/blog.escarra.org\/?p=267"},"modified":"2014-07-15T19:46:33","modified_gmt":"2014-07-16T01:46:33","slug":"extending-lync-server-certificate-validity-periods","status":"publish","type":"post","link":"https:\/\/blog.escarra.org\/?p=267","title":{"rendered":"Extending Lync Server certificate validity periods"},"content":{"rendered":"<p>X.509 certs are annoying. You need to get them issued with the right names, or reissued if you make a mistake or forget a SAN, and they need to be cared for from time to time otherwise they expire and make your world hell.<\/p>\n<p>Wouldn&#8217;t it be great if you could make them last longer than the default of 2 years? Especially if you&#8217;ve installed them all over your Lync infrastructure, like:<\/p>\n<ul>\n<li>Front End servers<\/li>\n<li>Mediation servers<\/li>\n<li>Edge server&#8217;s Inside NIC<\/li>\n<li>Office Web App Server<\/li>\n<li>Reverse Proxy or HLB<\/li>\n<li>Voice Gateways<\/li>\n<li>Exchange UM<\/li>\n<\/ul>\n<p>Having to track and schedule downtime for cert renewal of all of the above components is quite the chore. So let&#8217;s extend it to 5 years using Microsoft Windows AD Certificate Services (AD CS)<\/p>\n<p>To start, we&#8217;ll duplicate the Web Server template. Open your Certification Authority MMC, go on your CA, and right click on <strong>Certificate Templates<\/strong>, then click <strong>Manage.<\/strong><\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection.png\"><img data-attachment-id=\"341\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=341\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection.png\" data-orig-size=\"351,173\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"2014-07-15 20_14_43-kratos.escarra.org &#8211; Remote Desktop Connection\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection-300x147.png\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection.png\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-341\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection.png\" alt=\"2014-07-15 20_14_43-kratos.escarra.org - Remote Desktop Connection\" width=\"351\" height=\"173\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection.png 351w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_14_43-kratos.escarra.org-Remote-Desktop-Connection-300x147.png 300w\" sizes=\"(max-width: 351px) 100vw, 351px\" \/><\/a><\/p>\n<p>Right click on <strong>Web Server<\/strong>, then go on <strong>Duplicate Template<\/strong>.<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection.png\"><img data-attachment-id=\"342\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=342\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection.png\" data-orig-size=\"342,167\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"2014-07-15 20_15_16-kratos.escarra.org &#8211; Remote Desktop Connection\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection-300x146.png\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection.png\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-342\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection.png\" alt=\"2014-07-15 20_15_16-kratos.escarra.org - Remote Desktop Connection\" width=\"342\" height=\"167\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection.png 342w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_15_16-kratos.escarra.org-Remote-Desktop-Connection-300x146.png 300w\" sizes=\"(max-width: 342px) 100vw, 342px\" \/><\/a><\/p>\n<p>Under <strong>General,<\/strong> we will need to give it a name and <strong>Validity Period.\u00a0<\/strong>I&#8217;ve chosen LyncServer but it can be anything. You will need the Template Name when getting certificates issued without auto-enrollment, like from an edge server, or from your voice gateway using a CSR.<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection.png\"><img data-attachment-id=\"343\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=343\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection.png\" data-orig-size=\"414,567\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"2014-07-15 20_19_04-kratos.escarra.org &#8211; Remote Desktop Connection\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection-219x300.png\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection.png\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-343\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection.png\" alt=\"2014-07-15 20_19_04-kratos.escarra.org - Remote Desktop Connection\" width=\"414\" height=\"567\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection.png 414w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_19_04-kratos.escarra.org-Remote-Desktop-Connection-219x300.png 219w\" sizes=\"(max-width: 414px) 100vw, 414px\" \/><\/a><\/p>\n<p>Under <strong>Request Handling<\/strong>, make sure to check\u00a0<strong>Allow private key to be exported<\/strong>, review the other tabs and options to satisfy your curiosity, then click <strong>OK.<\/strong><\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection.png\"><img data-attachment-id=\"344\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=344\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection.png\" data-orig-size=\"414,567\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"2014-07-15 20_22_13-kratos.escarra.org &#8211; Remote Desktop Connection\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection-219x300.png\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection.png\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-344\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection.png\" alt=\"2014-07-15 20_22_13-kratos.escarra.org - Remote Desktop Connection\" width=\"414\" height=\"567\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection.png 414w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_22_13-kratos.escarra.org-Remote-Desktop-Connection-219x300.png 219w\" sizes=\"(max-width: 414px) 100vw, 414px\" \/><\/a><\/p>\n<p>You can close the Certificate Templates Console and wait a bit for AD to replicate, or <a title=\"Replicating all Domain Controllers\" href=\"http:\/\/blog.escarra.org\/?p=139\">force it<\/a>.<\/p>\n<p>We will now enable the certificate so it can be issued. Right click on<strong> Certificate Templates<\/strong> again, then go on <strong>New,<\/strong> and <strong>Certificate Template to Issue.\u00a0<\/strong>Look for your new LyncServer template, then click OK.<\/p>\n<p><a href=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection.png\"><img data-attachment-id=\"345\" data-permalink=\"https:\/\/blog.escarra.org\/?attachment_id=345\" data-orig-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection.png\" data-orig-size=\"678,282\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"2014-07-15 20_27_06-kratos.escarra.org &#8211; Remote Desktop Connection\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection-300x124.png\" data-large-file=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection.png\" decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-345\" src=\"http:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection.png\" alt=\"2014-07-15 20_27_06-kratos.escarra.org - Remote Desktop Connection\" width=\"678\" height=\"282\" srcset=\"https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection.png 678w, https:\/\/blog.escarra.org\/wp-content\/uploads\/2014\/07\/2014-07-15-20_27_06-kratos.escarra.org-Remote-Desktop-Connection-300x124.png 300w\" sizes=\"(max-width: 678px) 100vw, 678px\" \/><\/a><\/p>\n<p>ONE LAST STEP!<\/p>\n<p>On the CA server, you will need to extend the limit on the validity period, otherwise it will remain at 2 years regardless of what our template says. To do this, run:<\/p>\n<blockquote><p><strong><span style=\"color: #2a2a2a;\">certutil -setreg ca\\ValidityPeriodUnits 5<\/span><\/strong><br style=\"color: #2a2a2a;\" \/><strong><span style=\"color: #2a2a2a;\">certutil -setreg ca\\ValidityPeriod years<\/span><\/strong><\/p><\/blockquote>\n<p>The <strong>restart the Active Directory Certificate Services<\/strong> service, and the CA is now ready to start issuing longer certs!<\/p>\n<p>When requesting certificates from Lync (or others), make sure to specify the template name when prompted. And if using a CSR for your gateway or edge servers, you can force the template attribute which is not included in the CSR, and is required by Windows to issue you a cert. To do that run:<\/p>\n<blockquote><p><strong>certreq -attrib &#8220;CertificateTemplate:LyncServer&#8221;<\/strong><\/p><\/blockquote>\n<p>Then pick the CSR, and then save the resulting signed certificate. BOOM!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>X.509 certs are annoying. You need to get them issued with the right names, or reissued if you make a mistake or forget a SAN, and they need to be cared for from time to time otherwise they expire and make your world hell. Wouldn&#8217;t it be great if you could make them last longer [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"footnotes":"","_jetpack_memberships_contains_paid_content":false,"jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[1],"tags":[],"jetpack_publicize_connections":[],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/267"}],"collection":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=267"}],"version-history":[{"count":4,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/267\/revisions"}],"predecessor-version":[{"id":350,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=\/wp\/v2\/posts\/267\/revisions\/350"}],"wp:attachment":[{"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.escarra.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}