Create a Self-Signed Certificate for EXO Authentication
1 min
This document details the steps to create a self-signed certificate with the intended use to authenticate with Exchange Online.
- Logon to Activate Server
- Run PowerShell as Administrator
- Copy the script below to the server, modify the cert name, password and export path as required.
$certName = "Azure EXO Cert"
$certPath = "Cert:\LocalMachine\My"
$exportPath = "C:\Temp"
# Create export folder if it doesn't exist
if (!(Test-Path -Path $exportPath)) {
New-Item -Path $exportPath -ItemType Directory | Out-Null
}
# Create the self-signed certificate
$cert = New-SelfSignedCertificate `
-Subject "CN=$certName" `
-KeyAlgorithm RSA `
-KeyLength 2048 `
-KeyExportPolicy Exportable `
-KeySpec Signature `
-CertStoreLocation $certPath `
-NotAfter (Get-Date).AddYears(2) `
-HashAlgorithm SHA256 `
-FriendlyName $certName
# Export the public certificate (.cer) for Azure AD
Export-Certificate `
-Cert $cert `
-FilePath "$exportPath\$certName.cer" `
-Force
# Define and secure the password for the private key
$plainPassword = "<ENTER PASSWORD>"
$securePassword = ConvertTo-SecureString -String $plainPassword -Force -AsPlainText
# Export the private certificate (.pfx) with the secure password
Export-PfxCertificate `
-Cert $cert `
-FilePath "$exportPath\$certName.pfx" `
-Password $securePassword `
-Force- Run PowerShell as Administrator and run the above script.
- Browse to the export folder
- Double click the certificate PFX file to install it.
- Set Store Location to Local Machine, click Next
- Click Yes to UAC to run as Administrator in Windows
- Click Next
- Enter the password that was used to generate the certificate
- Click Next
- Place all certificates in the following store: Personal, click Next
- Finish