jonbd Posted July 1, 2019 Posted July 1, 2019 Hi all, Looks like the self signed certificates on my 2012 R2 Direct Access server have expired while I was away, so i'm trying to renew them. I've been following the guide here https://directaccess.richardhicks.com/2019/05/02/renew-directaccess-self-signed-certificates/ but seem to get the following error “a parameter cannot be found that matches parameter name ‘-FriendlyName'” I'm not much of a powershell user so don't know how to get around this problem. Anyone have any idea what i'm doing wrong? does -friendlyname work on server 2012r2? Is there another way to replace/renew the certificates?
jonbd Posted July 1, 2019 Author Posted July 1, 2019 ok so i'm not getting anywhere with renewing self signed certs. Does anyone know how I would go about creating the right templates on my internal CA that I could generate certificates to use instead?
jonbd Posted July 2, 2019 Author Posted July 2, 2019 Managed to work out the type of cert I needed from my CA but the direct access server kept deleting the DNS record for the NLS every time I tried to apply the settings through the wizard and failed. I'm guessing it thinks it's clearing out the self cert DNS record, but with the new cert from my CA using the same DNS name, it then can't find a record for it. In the end I set up a seperate VM as the NLS instead of on the DA server, linked it to that and am back in business! 1
chazzy2501 Posted July 2, 2019 Posted July 2, 2019 You've gotten off lighter than I did, due to my firewall settings when my cert expired ALL laptops refused to work on the domain and GPO updates were impossible! laptops thought they were on a guest network so firewall was on full! I wrote a warning about this a while ago
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now