Using SAN-enabled certificates for OCS and Unified Messaging

Analysis
Sep 19, 20071 min

I ran into an interesting situation with a client today regarding their LCS 2005 implementation. It was a great opportunity to discuss the use of SAN-enabled certificates. There seems to be a limited understanding of certificates that allow Subject Alternative Names.  SANs in your certificates allow for Enhanced Federation for your primary domain and Direct Federation for your secondary domains.  Only this year have major providers started offering SAN-enabled certificates. Verisign offers them only through their Enterprise SSL Managed PKI solution, Entrust offers a Unified Communications Certificate and GeoTrust offers a limited SAN-enabled cert called the Power Server ID.

In addition to LCS 2005 and OCS 2007, SAN-enabled certificates are often used with Exchange 2007. This allows for a single cert-set for Exchange, OCS and all unified messaging.  The downside however is ISA 2006 doesn’t yet support SAN-enabled certificates. So, although it makes a lot of scenarios easier, it drives out ISA as an option for some.