Automated certificates for the WinRM HTTPS listener
WinRM over HTTPS needs a valid certificate on every managed server - and a listener that points at it. The WinRM package replaces the listener with one bound to the renewed certificate.
package windows-winrm-target 3.0.0
importremoveHttpsListenerscreateHttpsListenercleanupwhen configured
At a glance
- Package
windows-winrm-target 3.0.0- Compatibility
Windows Server >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyRemove bindingCreate bindingRemove old certificate
- Deployment steps
- import → removeHttpsListeners → createHttpsListener → cleanup*
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
The agent imports the certificate, removes the existing HTTPS listeners and creates a new one on the configured port (5986 by default) for the certificate's host name.
With a certificate policy on an agent group, every server gets a WinRM certificate for its own name, typically from AD CS.
How it runs
- 01
import
Certificate and key are imported into the machine store.
- 02
removeHttpsListeners
Existing WinRM HTTPS listeners are removed.
- 03
createHttpsListener
A new HTTPS listener is created with the new certificate.
- 04
cleanup
The previous certificate is removed, if enabled.
What you configure
- Listener host name (defaults to the certificate's common name)
- Listener port (default 5986)
- Certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on each server
- An authority that issues server certificates for internal names, such as AD CS
Limitations
- Existing HTTPS listeners are replaced; HTTP listeners are not touched.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Automate Windows Remote Management (WinRM)
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.