I have been working with CTW in a small test environment to figure out how to use it and the management hub to deploy certificates to various servers. So far, I have figured out the DNS automation by moving one of my domains to Cloudflare who supports the DNS APIs, and have set up deployment to linux machines for NGINX and Apache, along with the needed post processes for those machines, as well as Exchange.
Where I have hit a wall this time is deploying to a remote desktop deployment. To properly deply the cert, it needs to be deployed to the following services, one at a time:
RD Connection Broker - Enable Single Sign on
RD Connection Broker - Publishing
RD Web Access
RD Gateway
I found a script here that looks like it should do the job, and I worked through a few errors (module not found so I installed that module, access denied, so I changed the way the credentials were stored), but I’ve hit a wall with a rather unhelpful error:
PowerShell Execution Mode: InProcess (selected Automatic, using in-process PowerShell for Windows credential impersonation compatibility).
PowerShell Host: Core 7.6.6
Certify.Models.CertificateRequestResult
Importing certificate from C:\ProgramData\certify\assets\my.domain\20270105_30d2747f.pfx
Error: Certificate import error at <ScriptBlock>, C:\Program Files\CertifyTheWeb\Scripts\AutoUpdate\RDCertInstall.ps1: line 21
That line is just ’ Throw “Certificate import error” ’
Does anyone have any ideas?