Cloud Management Gateway server authentication certificate renewal

Stewart Pollock 11 Reputation points
2022-03-16T09:09:24.85+00:00

Hi

Can anyone confirm if it's possible to switch from a wildcard certificate to a named one without orphaning internet clients or needing to redeploy the CMG service?

The docs specify that the CN must be the same for the new cert but I wondered if the new cert matched the service name that was entered for a wildcard cert whether that would work as the name for the CMG would still be the same?

E.g. a CMG deployed using a cert with CN *. contoso.com and named CMG1.contoso.com. Could the certificate be renewed with one named CMG1.contoso.com?

Thanks

Microsoft Security Intune Configuration Manager Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Amandayou-MSFT 11,156 Reputation points
    2022-03-17T01:56:43.103+00:00

    Hi,

    As far as I know, these certificates are from the same trusted CA, the certificate could be renewed with one named CMG1.contoso.com.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.