Automated deployment to Remote desktop deployment

I have been working with CTW in a small test environment to figure out how to use it and the management hub to deploy certificates to various servers. So far, I have figured out the DNS automation by moving one of my domains to Cloudflare who supports the DNS APIs, and have set up deployment to linux machines for NGINX and Apache, along with the needed post processes for those machines, as well as Exchange.

Where I have hit a wall this time is deploying to a remote desktop deployment. To properly deply the cert, it needs to be deployed to the following services, one at a time:
RD Connection Broker - Enable Single Sign on
RD Connection Broker - Publishing
RD Web Access
RD Gateway

I found a script here that looks like it should do the job, and I worked through a few errors (module not found so I installed that module, access denied, so I changed the way the credentials were stored), but I’ve hit a wall with a rather unhelpful error:

PowerShell Execution Mode: InProcess (selected Automatic, using in-process PowerShell for Windows credential impersonation compatibility).
PowerShell Host: Core 7.6.6
Certify.Models.CertificateRequestResult
Importing certificate from C:\ProgramData\certify\assets\my.domain\20270105_30d2747f.pfx
Error: Certificate import error at <ScriptBlock>, C:\Program Files\CertifyTheWeb\Scripts\AutoUpdate\RDCertInstall.ps1: line 21

That line is just ’ Throw “Certificate import error” ’

Does anyone have any ideas?

Are you running this on the machine that is hosting the Remote Desktop services or are you trying to deploy to a remote machine? Generally is easiest to run the app on the machine where the certs are required.

Does our built in deployment task not work for you?

What OS version is the machine with the RD services on?