I have a machine running Server 2003 R2 and Exchange 2007. When it was originally set up (before my time) a self-signed certificate was installed, however, it's about to expire and now seems like a good time to fix it.
My question is - when buying a certificate, can I buy it for a single domain or do I need multiple domains? The machine itself is behind a hardware gateway, and it is the only Exchange server we have. We access OWA externally at https://webmail.example.org, however, that should be the only place we actually need a proper certificate, right? Shouldn't it suffice to just self-sign all the internal certificates that Exchange needs and buy a real cert for the external access? What about securing SMTP/IMAP connections externally?