aethercert
Microsoft and Windows Server

Automated certificate renewal for Microsoft Exchange Server

Replacing the Exchange certificate means Import-ExchangeCertificate, Enable-ExchangeCertificate for the right services, and remembering not to touch the auth certificate. The Exchange package does exactly that, on every renewal.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-exchange-target 3.0.0
Compatibility
Exchange Server >=2016 <2026
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyUpdate bindingVerify deploymentRemove old certificate
Deployment steps
import → enableServices → verifyServices → cleanup*
Rollback
None
Key usage
Server authentication

* conditional step

What it does

The agent on the Exchange server imports the renewed certificate through the Exchange Management Shell and enables it for the services you choose - IIS, SMTP, POP, IMAP, and UM, UMCallRouter or Federation where used. It then checks that those services are assigned to the new certificate.

Optionally, older certificates with the same subject whose services the new one now covers are removed. The Exchange auth certificate is never removed.

How it runs

  1. 01

    import

    The certificate is imported with Import-ExchangeCertificate.

  2. 02

    enableServices

    Enable-ExchangeCertificate assigns it to the configured services.

  3. 03

    verifyServices

    The package confirms the services now use the new certificate.

  4. 04

    cleanup

    Superseded certificates for the same subject are removed, if enabled - never the auth certificate.

What you configure

  • Services to enable: IIS, SMTP, POP, IMAP, UM, UMCallRouter, Federation
  • Whether the key may be exported later
  • Whether to remove superseded certificates

Prerequisites

  • A Windows agent on each Exchange server
  • Exchange Management Shell available to the agent service
  • A certificate whose SANs cover the namespaces clients use (for example mail and autodiscover)

Limitations

  • Each Exchange server in a DAG runs its own agent and deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Microsoft Exchange Server

Is the Exchange auth certificate affected?

No. The clean-up step explicitly never removes the Exchange auth certificate.

Can I use Let's Encrypt for Exchange?

Yes, for publicly resolvable names validated with DNS-01. Internal-only names can come from AD CS through the CA connector.

Automate Microsoft Exchange Server

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.