The certificate may be published in the Active Directory directory service for the purposes of direct trust by using mutual TLS if the following conditions are true:
-
The certificate is marked as a Simple Mail Transfer protocol (SMTP) TLS certificate.
-
The Subject Name on the certificate matches the fully qualified domain name (FQDN) of the local computer.
The certificate may be published in Active Directory by Edge Subscription if the following conditions are true:
-
You import the certificate to an Edge Transport server computer.
-
The certificate has a FQDN that matches the server FQDN.
The Import-ExchangeCertificate cmdlet imports either a certificate that is issued from an outstanding request or a PKCS #12 file.
To run the Import-ExchangeCertificate cmdlet, the account you use must be delegated the following:
-
Exchange Server Administrator role and local Administrators group for the target server
To run the Import-ExchangeCertificate cmdlet on a computer that has the Edge Transport server role installed, you must log on by using an account that is a member of the local Administrators group on that computer.
For more information about permissions, delegating roles, and the rights that are required to administer Microsoft Exchange Server 2007, see Permission Considerations.