aethercert
Microsoft and Windows Server

Automated certificates for Hyper-V Replica

Hyper-V Replica with certificate-based authentication fails quietly when the replication certificate expires. The package renews it and sets it on the host.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-hyperv-replica-target 3.0.0
Compatibility
Windows Server / Hyper-V >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyUpdate bindingRemove old certificate
Deployment steps
import → setReplicationCertificate → cleanup*
Rollback
None
Key usage
Server and client authentication

* conditional step

What it does

The agent imports the certificate and sets it as the certificate Hyper-V Replica uses for authentication on the configured port.

Replica needs a certificate valid for both server and client authentication. aethercert only offers this target with authorities that can issue that combination, such as AD CS with a suitable template - public ACME CAs issue server-authentication certificates only.

How it runs

  1. 01

    import

    Certificate and key are imported into the machine store.

  2. 02

    setReplicationCertificate

    The certificate is set for Hyper-V Replica authentication.

  3. 03

    cleanup

    The previous certificate is removed, if enabled.

What you configure

  • Certificate authentication port (default 443)
  • Certificate store, friendly name and clean-up

Prerequisites

  • A Windows agent on each Hyper-V host
  • An internal CA template that issues server and client authentication

Limitations

  • Not available with Let's Encrypt or other public ACME CAs, which do not issue client-authentication certificates.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Hyper-V Replica

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.