aethercert
Microsoft and Windows Server

Automated certificates for the WinRM HTTPS listener

WinRM over HTTPS needs a valid certificate on every managed server - and a listener that points at it. The WinRM package replaces the listener with one bound to the renewed certificate.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-winrm-target 3.0.0
Compatibility
Windows Server >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyRemove bindingCreate bindingRemove old certificate
Deployment steps
import → removeHttpsListeners → createHttpsListener → cleanup*
Rollback
None
Key usage
Server authentication

* conditional step

What it does

The agent imports the certificate, removes the existing HTTPS listeners and creates a new one on the configured port (5986 by default) for the certificate's host name.

With a certificate policy on an agent group, every server gets a WinRM certificate for its own name, typically from AD CS.

How it runs

  1. 01

    import

    Certificate and key are imported into the machine store.

  2. 02

    removeHttpsListeners

    Existing WinRM HTTPS listeners are removed.

  3. 03

    createHttpsListener

    A new HTTPS listener is created with the new certificate.

  4. 04

    cleanup

    The previous certificate is removed, if enabled.

What you configure

  • Listener host name (defaults to the certificate's common name)
  • Listener port (default 5986)
  • Certificate store, friendly name and clean-up

Prerequisites

  • A Windows agent on each server
  • An authority that issues server certificates for internal names, such as AD CS

Limitations

  • Existing HTTPS listeners are replaced; HTTP listeners are not touched.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Windows Remote Management (WinRM)

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.