El envío de formularios en el sitio de soporte no está disponible temporalmente para programar el mantenimiento. Si necesita asistencia inmediata, comuníquese con el soporte técnico. Disculpe las molestias ocasionadas.
How to update expiring TLS certificates in an ODM AD Domain Rewrite project
Descripción
Video explaining how to update the expiring TLS certificates when using On Demand Migration Active Directory (ODM AD) Domain Rewrite.
Causa
An ODM AD migration project that runs longer than a year for Domain Rewrite.
Resolución
Certificate Requirements — Required for TLS
One (1) SSL Certificate for each tenant
Associated with any accepted domain in the tenant
Cannot be a domain that is being moved if Domain Move is in scope
Saved in PFX Format
Contains private key (password)
Contains common name and friendly name
Valid for Server Authentication and Client authentication
No SAN certificates with multiple domains
No Wildcard certificates
Perform the following steps to apply the new certificate to Domain Rewrite.
Log into ODM AD Domain Rewrite project, then click on Settings and select the Rewrite Service tab.
From the dropdown list of domains, select the domain with the expiring certificate and click the Cert icon.
Browse to and choose the new .PFX file for the certificate and enter the password for it.
Note: To monitor its progress, click the hamburger button and select Certificates.
The new certificate should move from Pending to an Active state.
The old expiring certificate should then move from Expiring to an Inactive state.
For the certificate to take effect on the domain, please ensure to check the Checkbox for the domain under Seettings > Rewrite Services
Información adicional
Important: starting October 2025, all major Certificate Authorities can no longer generate certificates, containing both EKUs, Server and Client Authentication, together. Quest has deployed a code change on Nov 12/13 (for different regions) that will allow using certificate with Server Authentication only for Domain Rewrite.
Please note: that this requirement with both EKUs stems from Exchange Online requirements.
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Bienvenido al portal de soporte
Puede encontrar ayuda de soporte en línea para el *producto* Quest en un sitio de soporte afiliado. Haga clic en Continuar para ser dirigido al contenido de soporte y a la asistencia adecuados para el *producto*.
Buscar todos los artículos
IE 8, 9 y 10 ya no son compatibles
El portal de Quest Software ya no admite IE 8, 9 ni 10 y se recomienda actualizar el navegador a la última versión de Internet Explorer o Chrome.