Skip to content

← All integrations

Windows · Basics

Certificate Store import and discovery, IIS Central Certificate Store and PFX, PEM and JKS files on Windows servers.

The service agent on the server fetches the task from the appliance over outbound HTTPS on port 443 and installs the certificate locally on the server. The appliance never connects to the server.

What happens

  1. The service agent on the server fetches the task from the appliance over outbound HTTPS, port 443.
  2. The certificate is installed where the rule says: in the Windows certificate store, in the IIS Central Certificate Store or as a PFX, PEM or JKS file.
  3. Product integrations such as IIS, RDP and AD FS bind the certificate imported into the store.
  4. Verification: the package checks that the certificate is where it was installed and usable: in the store with its key, or in the file, which opens with its password.

Technical details

Connection
The package runs through the service agent on the server. The agent connects over outbound HTTPS to the appliance, port 443 by default. You open no port into the server.
You need
The service agent installed on the server.
Platform
Windows Server 2012 and later, Windows 10 and 11
Actions
Discovery, Installation, Verification, Removal
Packages
windows-cert-installwindows-oswindows-ccscustom-windows
Note
  • A certificate already in the store with a readable key is not imported again. Services that were given access to its key keep it.
  • The IIS Central Certificate Store must be set up in IIS. The PFX files are named after the certificate's host names.
  • Discovery finds services, certificates and TLS configuration on the server.

Get started