Automated certificates for Remote Desktop Services and RDP
Two packages cover the two places Remote Desktop uses a certificate: the roles of an RDS deployment - Gateway, Web Access, Connection Broker - and the RDP listener on an individual server.
package windows-rds-deployment-target 3.0.0
assignRdsCertificateverifyRdsCertificate
At a glance
- Package
windows-rds-deployment-target 3.0.0- Compatibility
Windows Server / Remote Desktop Services >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyVerify deployment
- Deployment steps
- assignRdsCertificate → verifyRdsCertificate
- Rollback
- None
- Key usage
- Server authentication
- Package
windows-rdp-target 3.0.0- Compatibility
Windows Server / Windows >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyUpdate bindingRemove old certificate
- Deployment steps
- import → assignRdpListener → cleanup*
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
The RDS deployment package assigns the renewed certificate to an RDS role through the Connection Broker - the step usually done with Set-RDCertificate - and verifies the assignment afterwards.
The RDP listener package imports the certificate into the machine store and binds it to the RDP-Tcp listener, so clients connecting directly to a server no longer see a self-signed certificate warning. Combined with a certificate policy, every server in a group gets its own.
How it runs
- 01
assignRdsCertificate
RDS deployment: the certificate is assigned to the configured role (for example RDGateway) through the Connection Broker.
- 02
verifyRdsCertificate
RDS deployment: the role is checked to use the new certificate.
- 03
import / assignRdpListener
RDP listener: the certificate is imported and bound to the listener.
- 04
cleanup
RDP listener: the previous certificate is removed, if enabled.
What you configure
- RDS role: RD Gateway, RD Web Access, RD Connection Broker (redirector or publishing)
- Connection Broker (default: localhost)
- For the RDP listener: certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on the Connection Broker for RDS roles
- A Windows agent on each server whose RDP listener should be covered
- For RD Gateway and Web Access: a certificate for the public name users connect to
Limitations
- Each RDS role is a separate deploy target.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Frequently asked questions
Remote Desktop Services and RDP
Do I still need Set-RDCertificate?
No. The RDS deployment package performs the assignment on the Connection Broker and verifies it.
Can every session host get its own RDP certificate?
Yes. Put the hosts in an agent group and use a certificate policy with the RDP listener package; each host gets a certificate for its own name.
Automate Remote Desktop Services and RDP
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.