Wildcard SSL Certificate Renewal Process
Create a certificate signing request (CSR):
-
Connect to CWMGR1
-
Open IIS Manager from Administrator Tools
-
Select CWMGR1 and open Server Certificates
-
Click on Create Certificate Request in the Actions pane
-
Fill out the Distinguished Name Properties in the Request Certificate Wizard and click Next:
-
Common Name: FQDN of Wildcard - *.domain.com
-
Organization: Your company’s legally registered name
-
Organizational unit: ‘IT’ works fine
-
City: City where company is located
-
State: State where company is located
-
Country: Country where company is located
-
-
On the Cryptographic Service Provider Properties page, verify the below appears and click Next:
-
Specify a file name and browse to a location where you want to save the CSR. If you do not specify a location, the CSR will be in C:\Windows\System32:
-
Click Finish when completed. You will use this text file to submit your order to certificate registrar
-
Reach out to registrar support to purchase a new Wildcard SSL for your certificate: *.domain.com
-
After receiving your SSL certificate, save the SSL certificate .cer file in a location on CWMGR1 and follow the below steps.
Installing and configuring CSR:
-
Connect to CWMGR1
-
Open IIS Manager from Administrator Tools
-
Select CWMGR1 and open ‘Server Certificates’
-
Click on Complete Certificate Request in the Actions pane
-
Complete the below fields in the Complete Certificate Request and click OK:
-
File Name: Select .cer file that was saved previously
-
Friendly name: *.domain.com
-
Certificate store: Select either Web Hosting or Personal
-
Assigning SSL certificate:
-
Verify that Migration Mode is not enabled. This can be found on the Workspace Overview page under Security Settings in VDS.
-
Connect to CWMGR1
-
Open IIS Manager from Administrator Tools
-
Select CWMGR1 and open ‘Server Certificates’
-
Click on Export in the Actions pane
-
Export the certificate in .pfx format
-
Create a password. Store password as it will be needed to import or re-use .pfx file in the future
-
Save .pfx file to the C:\installs\RDPcert directory
-
Click OK and close IIS Manager
-
Open DCConfig
-
Under Wildcard Certificate, update the Certificate path to new .pfx file
-
Enter .pfx password when prompted
-
Click Save
-
If the certificate is valid for 30 more days, allow automation to apply the new certificate during the morning Daily Actions task throughout the week
-
Periodically check the Platform servers to verify that the new certificate has propagated. Validate and test user connectivity to confirm.
-
On the server, go to Admin Tools
-
Select Remote Desktop Services > Remote Desktop Gateway Manager
-
Right click on gateway server name, select Properties. Click on the SSL Certificate tab to review expiration date
-
-
Periodically check the client VMs that are running the Connection Broker role
-
Go to Server Manager > Remote Desktop Services
-
Under Deployment Overview, select Tasks dropdown and choose Edit Deployment Properties
-
Click on Certificates, select certificate and click View Details. Expiration date will be listed.
-
-
If less than 30 days or you prefer to push out the new certificate immediately, force the update with TestVdcTools. This should be done during a maintenance window as connectivity for any users logged in and your connection to CWMGR1 will be lost.
-
Go to C:\Program Files\CloudWorkspace\TestVdcTools, click the Operations tab and select the Wildcard Cert-Install command
-
Leave the server field blank
-
Check the Force box
-
Click Execute Command
-
Verify certificate propagates using the steps listed above
-