aethercert
Microsoft and Windows Server

Automated certificates for Remote Desktop Services and RDP

Two packages cover the two places Remote Desktop uses a certificate: the roles of an RDS deployment - Gateway, Web Access, Connection Broker - and the RDP listener on an individual server.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-rds-deployment-target 3.0.0
Compatibility
Windows Server / Remote Desktop Services >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyVerify deployment
Deployment steps
assignRdsCertificate → verifyRdsCertificate
Rollback
None
Key usage
Server authentication
Package
windows-rdp-target 3.0.0
Compatibility
Windows Server / Windows >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyUpdate bindingRemove old certificate
Deployment steps
import → assignRdpListener → cleanup*
Rollback
None
Key usage
Server authentication

* conditional step

What it does

The RDS deployment package assigns the renewed certificate to an RDS role through the Connection Broker - the step usually done with Set-RDCertificate - and verifies the assignment afterwards.

The RDP listener package imports the certificate into the machine store and binds it to the RDP-Tcp listener, so clients connecting directly to a server no longer see a self-signed certificate warning. Combined with a certificate policy, every server in a group gets its own.

How it runs

  1. 01

    assignRdsCertificate

    RDS deployment: the certificate is assigned to the configured role (for example RDGateway) through the Connection Broker.

  2. 02

    verifyRdsCertificate

    RDS deployment: the role is checked to use the new certificate.

  3. 03

    import / assignRdpListener

    RDP listener: the certificate is imported and bound to the listener.

  4. 04

    cleanup

    RDP listener: the previous certificate is removed, if enabled.

What you configure

  • RDS role: RD Gateway, RD Web Access, RD Connection Broker (redirector or publishing)
  • Connection Broker (default: localhost)
  • For the RDP listener: certificate store, friendly name and clean-up

Prerequisites

  • A Windows agent on the Connection Broker for RDS roles
  • A Windows agent on each server whose RDP listener should be covered
  • For RD Gateway and Web Access: a certificate for the public name users connect to

Limitations

  • Each RDS role is a separate deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Remote Desktop Services and RDP

Do I still need Set-RDCertificate?

No. The RDS deployment package performs the assignment on the Connection Broker and verifies it.

Can every session host get its own RDP certificate?

Yes. Put the hosts in an agent group and use a certificate policy with the RDP listener package; each host gets a certificate for its own name.

Automate Remote Desktop Services and RDP

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.