Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hello all,

 

We use Microsoft Direct Access, it's brilliant, I love it but I am new to the role and the previous Manager implemented and maintained this system.

 

He used certify the web to take advantage of free certificates. The downside being they only last 90 days. We have a few servers that need updating so I decided to invests in a 2 year domain wildcard.

 

The certificate has expired on the DA server and I need to import the new one. I am really struggling as I don't have a huge amount of experience with Powershell and have never used Server Core edition, I've only ever worked with a GUI.

 

I have the.cer certificate and have copied it to \\da1\c$\certificates and have tried to use the following commands as per the screenshot but it gives me an error that it can't create that file because it already exists.

 

I have also tried running Remove-NetIPHttpsCertBinding & netsh http delete sslcert ipport=0.0.0.0:443 to delete the existing certificate and remove the bindings then repeated but same problem.

 

One thing i'm not sure about is the Application ID. When I run netsh http show sslcert it shows me 4 certificates. When doing the new bind, I am using the application ID from the one that shows an ip port of 0.0.0.0:443 - is this the what I should be using?

 

bindings2.JPGHopefully someone can look at my screenshot and tell me where I am going wrong. Any help would be much appreciated as I've spent hours on this!

 

Many Thanks

Posted

Managed to get to the bottom of this.

 

I contacted the company who issued the certificate and they told me that it was because I had imported the .cer file provided originally by e-mail. I had to log in, download the bundle and convert to PKCS#12.

 

I couldn't import the new certificate using MMC as 'Importing a .pfx or p12 file to a remote certificate store is not supported' (the server is running core edition)

 

I imported using Powershell and the certiricate is now showing as secure. i still have issues but different ones!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...