Automated certificates for Hyper-V Replica
Hyper-V Replica with certificate-based authentication fails quietly when the replication certificate expires. The package renews it and sets it on the host.
package windows-hyperv-replica-target 3.0.0
importsetReplicationCertificatecleanupwhen configured
At a glance
- Package
windows-hyperv-replica-target 3.0.0- Compatibility
Windows Server / Hyper-V >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyUpdate bindingRemove old certificate
- Deployment steps
- import → setReplicationCertificate → cleanup*
- Rollback
- None
- Key usage
- Server and client authentication
* conditional step
What it does
The agent imports the certificate and sets it as the certificate Hyper-V Replica uses for authentication on the configured port.
Replica needs a certificate valid for both server and client authentication. aethercert only offers this target with authorities that can issue that combination, such as AD CS with a suitable template - public ACME CAs issue server-authentication certificates only.
How it runs
- 01
import
Certificate and key are imported into the machine store.
- 02
setReplicationCertificate
The certificate is set for Hyper-V Replica authentication.
- 03
cleanup
The previous certificate is removed, if enabled.
What you configure
- Certificate authentication port (default 443)
- Certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on each Hyper-V host
- An internal CA template that issues server and client authentication
Limitations
- Not available with Let's Encrypt or other public ACME CAs, which do not issue client-authentication certificates.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Automate Hyper-V Replica
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.