How to renew the Web Server Certificate for Configuration manager?

Duchemin, Dominique 2,006 Reputation points
2023-01-23T22:42:28.6533333+00:00

Hello,

What is the process to renew the Web Certificate in SCCM?
I check it it is not set to auto-renewal yet.
I tried on one Distribution Point the following options:
mmc > Add or Remove Snap-ins > Certificates > Add > Computer Account > Local Computer > Certificates > Personal > Certificates
Rightc Click on the current SCCM Web Server Certificate > All Tasks > Advanced Operations > Request New Certificate with the Same Key

What are the next steps if any?

Thanks,
Dom

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,117 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. CherryZhang-MSFT 6,481 Reputation points
    2023-01-30T06:04:54.1833333+00:00

    Hi @Duchemin, Dominique

    Even though you have renewed the existing certificate rather than replaced it, it still has a new serial number and a new certificate thumbprint.  This means that you must still specify the renewed certificate on the DP Properties page. The screenshots for your reference:

    1

    2

    The related article for your reference:

    How to Renew the Site Server Signing Certificate (Microsoft Certificate Services) - Microsoft Community Hub

    Thanks for your time.

    Best regards,
    Cherry


     

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Duchemin, Dominique 2,006 Reputation points
    2023-01-27T17:14:48.13+00:00

    Hello,

    Any other step(s) to do for the renewal of the SCCM Web Server Certificate?

    Thanks,

    Dom

    0 comments No comments

  2. Duchemin, Dominique 2,006 Reputation points
    2023-01-30T18:54:19.55+00:00

    Hello,

    The certificate seen under Administration > Overview > Site Configuration >Servers and Site System Roles > Site System Roles > Distribution Point is expired for 3 weeks now but there is no issue ...!!!

    How is this possible? See attachment...

    Also I noticed we have two certificates

    1. Distribution Point Certificate (dpcert2021.pfx)
    2. Web Server Certificate What is the role of each of them? It is the Distribution Point Certificate which is expired since 11/2022 (3 months ago) and everything is working fine...

    Any idea?

    Thanks,

    Dom