

(The OAUthTokenIssuer certificate can also be any Web server certificate that includes the name of your SIP domain in the Subject field.) The primary two requirements for the certificate used for server-to-server authentication are these: 1)the same certificate must be configured as the OAuthTokenIssuer certificate on all of your Front End Servers and, 2) the certificate must be at least 2048 bits. As a general rule, any Lync Server 2013 certificate can be used as your OAuthTokenIssuer certificate for example, your Lync Server 2013 default certificate can also be used as the OAuthTokenIssuer certificate.

If no certificate information is returned you must assign a token issuer certificate before you can use server-to-server authentication. To determine whether or not a server-to-server authentication certificate has already been assigned to Microsoft Lync Server 2013, run the following command from the Lync Server 2013 Management Shell: Get-CsCertificate -Type OAuthTokenIssuer
