Skip to content

← All integrations

Windows · Identity and remote access

Installs a new CA certificate in AD CS. Issuing certificates from your CA is the Windows CA source.

The service agent on the server fetches the task from the appliance over outbound HTTPS on port 443 and installs the certificate locally on the server. The appliance never connects to the server.

What happens

  1. The service agent on the server fetches the task from the appliance over outbound HTTPS, port 443.
  2. The new CA certificate is installed in AD CS and CertSvc is restarted. If it fails: Rollback puts the previous certificate back and restarts CertSvc.
  3. Verification: the package checks that AD CS uses the new CA certificate.

Technical details

Connection
The package runs through the service agent on the server. The agent connects over outbound HTTPS to the appliance, port 443 by default. You open no port into the server.
You need
The service agent installed on the server. The agent on the CA server itself, with the AD CS role installed.
Platform
Windows Server 2012 and later
Actions
Discovery, Installation, Verification, Rollback
Packages
windows-ca

Get started