Direct Access IP HTTPS Certificate Auto Enrolment

Hi,

Is it possible instead of manually renewing the IPHTTPS server certificate every time it expires to configure auto enrollment so that it mitigates the risk of an unexpected outage should it be missed and not manually renewed.

Thanks,

Ranjit.

April 29th, 2015 3:39pm

Hi,

This certificate should be delivered by a public AC. So Auto Enrolment is not possible. Even if you use an internal AC, even if auto-enrollment is possible, the binding at HTTP.SYS level need to be updated. That can be done with the Remote Access Management Console or the Powershell commandlets. At last, since Windows Server 2012, you can rely on auto-signed certificate but the problem remain the same as it must be trusted by your DirectAccess clients that need a GPO refresh for that.

So it's not possible.

Free Windows Admin Tool Kit Click here and download it now
April 30th, 2015 3:38am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics