aethercert
Microsoft and Windows Server

Automated certificates for Skype for Business Server

Skype for Business and Lync Server assign certificates per usage. The package imports the renewed certificate and assigns it with Set-CsCertificate for each usage you configure.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-skype-target 3.0.0
Compatibility
Skype for Business Server / Lync Server >=2013 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyUpdate binding
Deployment steps
importCertificate → assignCertificate
Rollback
None
Key usage
Server authentication

What it does

The agent on the server imports the certificate and runs the assignment for the configured usages - Default, WebServicesExternal, WebServicesInternal and others.

It is meant for environments that still run Skype for Business Server on premises and need its certificates kept current.

How it runs

  1. 01

    importCertificate

    The certificate is imported into the machine store.

  2. 02

    assignCertificate

    Set-CsCertificate assigns it for each configured usage.

What you configure

  • Certificate usages (Set-CsCertificate -Type values)

Prerequisites

  • A Windows agent on each Skype for Business or Lync server
  • The Skype for Business Management Shell available to the agent service

Limitations

  • Each server needs its own agent and deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Skype for Business Server

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.