Steps to Update/Renew Your CyberArk Infrastrucure Certificates

This post summarizes the steps to renew / update the certificate used by CyberArk PAM solutions.

Check your local computer's installed certificate:

certmgr.msc - current user

 

PVWA Certificate

An SSL certificate must be installed on the Web server in order to have a secure channel between the PVWA machine and the Internet browser. If the default website is not protected by a certificate, an error will appear in the browser indicating that the website is not trusted.

As a part of the Prerequisites script, a self-signed certificate is created. We recommend that you replace this certificate with a trusted certificate after installation.

Personel-Certificate

RDP Certificate

RDP connections to the PSM machine with SSL

Users can configure secure RDP connections to the PSM machine using an SSL connection.

RDP connections to target machines with SSL

Users can configure secure PSM-RDP connections to target machines by verifying the target machine before connecting to it and encrypting the session, using an SSL connection. To facilitate this type of connection, the target machine must have its own certificate. The PSM server machine must trust the CA that signed the certificate used by the target machine.

Before configuring secure RDP connections with SSL

Import the CA Certificate that signed the certificate used by the target machine into the Windows certificate store on the PSM server machine:
Certificates (Local Computer)/Trusted Root Certification Authorities
 

The PSM server must be able to access the CRL (Certificate Revocation List) from the CRL Distribution Points in the certificate.

By storing the certificate in this location, all users will be able to access the remote machine using an authenticated connection.
Remote Desktop - Certificate

Edit Remote Desktop Services Deployment:

This certificate is same as the one stored into PSM server's personel folder. 
This certificate can be used for all PSM servers and RDP services since the subject alternative name covers all PSM servers and local balancer. 

CA and Intermediate Cert

Both CA and Intermediate Certs will need to send to CyberArk to renew. 

 Trusted Root Certification Authorities - Certifiates

Intermediate Certificate

Videos

 

版权声明:
作者:zhangchen
链接:https://www.techfm.club/p/144464.html
来源:TechFM
文章版权归作者所有,未经允许请勿转载。

THE END
分享
二维码
< <上一篇
下一篇>>