When do you need SAN fields for the OCS Pool Certificate?

When do you need SAN fields for the OCS Pool Certificate?

When do you need SAN fields for the OCS Pool Certificate?

    Requires Free Membership to View

    SearchUnifiedCommunications.com members gain immediate and unlimited access breaking industry news, expert advice on UC, technical guides, and more -- all at no cost. Join me on SearchUnifiedCommunications.com today!

    Kate Gerwig, Editorial Director

    By submitting your registration information to SearchUnifiedCommunications.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchUnifiedCommunications.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

When planning for the deployment of certificates in an Office Communications Server (OCS) Pool, you should pay special attention to the use of the SAN (Subject Alternate Name) fields. There is no mention when deploying external web conferencing that you must include the FQDN of each FE server in the SAN field of the OCS Pool cert.

This is because the access edge servers connect directly to the FQDNs of the OCS FE servers when external users join a meeting. The OCS R2 Enterprise Edition Deployment Guide indicates that SAN fields are only required for multiple SIP domains.

In the recently released Microsoft Certificate deployment document, it states that wildcards are allowed in the SAN fields of OCS Pool certs. The truth is that if you are supporting web conferencing from the public internet then your OCS pool certificate must contain in the SAN fields the FQDNs of each FE server. If you use wildcards in the SAN fields, the OCS services won't even start.

This was first published in May 2010