I renewed a https cert today in Windows and had problems with the new Cert sticking in Windows
It would add fine, without error, but would disappear when the IIS Server Certificates screen would refresh.
Open the Certificates in MMC (Local Machine) and inspecting the Web Hosting gave a clue, the new certificate was there, but with a key - the private key was missing.
Could be because the original certificate was created on a completely different machine and imported to this new server.
At any rate, a simple certutil command fixed it .
A tip I received from SSL disappears from the certificate list on Windows server - SSL Certificates - Namecheap.com
Key steps are:
- Double-click the certificate and go to Details tab.
- In certificate details locate the Serial Number field, click on it and copy its value.
- Open Command Prompt, pressing Win+R and typing cmd, then click OK
- In the command prompt type: certutil -repairstore my Serial_number from step 9
I actually typed
certutil -repairstore webhosting serialnumber
I had to replace my with webhosting, which leads to another tip, getting the command line names of the certificate stores.
This is achieved with the following...
PS C:\Users\Administrator> ls Cert:\LocalMachine
Name : TrustedPublisherName : ClientAuthIssuerName : Remote DesktopName : RootName : TrustedDevicesName : WebHostingName : CAName : Windows Live ID Token IssuerName : REQUESTName : AuthRootName : FlightRootName : TrustedPeopleName : addressbookName : MyName : SmartCardRootName : TrustName : DisallowedName : WindowsServerUpdateServices
Comments
Post a Comment