Jump to content

Recommended Posts

Posted

Hi all,

 

Looks like the self signed certificates on my 2012 R2 Direct Access server have expired while I was away, so i'm trying to renew them. I've been following the guide here https://directaccess.richardhicks.com/2019/05/02/renew-directaccess-self-signed-certificates/ but seem to get the following error “a parameter cannot be found that matches parameter name ‘-FriendlyName'” I'm not much of a powershell user so don't know how to get around this problem. Anyone have any idea what i'm doing wrong? does -friendlyname work on server 2012r2? Is there another way to replace/renew the certificates?

Posted
ok so i'm not getting anywhere with renewing self signed certs. Does anyone know how I would go about creating the right templates on my internal CA that I could generate certificates to use instead?
Posted
Managed to work out the type of cert I needed from my CA but the direct access server kept deleting the DNS record for the NLS every time I tried to apply the settings through the wizard and failed. I'm guessing it thinks it's clearing out the self cert DNS record, but with the new cert from my CA using the same DNS name, it then can't find a record for it. In the end I set up a seperate VM as the NLS instead of on the DA server, linked it to that and am back in business!
  • Thanks 1
Posted

You've gotten off lighter than I did, due to my firewall settings when my cert expired ALL laptops refused to work on the domain and GPO updates were impossible! laptops thought they were on a guest network so firewall was on full!

 

I wrote a warning about this a while ago :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...