[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Add a certificate to IIS global "Server Certificates" list using PowerShell?

Posted on 2012-03-19
8
Medium Priority
?
891 Views
Last Modified: 2012-04-17
Hi,

Been surfing the web for an example on how to add a certificate to the "global" IIS "Server Certificates" list using PowerShell but to no luck. I already have code in place on how to tie / associate a specific website with a specific cert but not how to add the new .cer file using the "Complete Certificate Request..." wizard using PowerShell.... I dont expect the final code to become published but if someone had an idea on how to integrate / get an entry point on where to interact between the "Server Certificate" list in IIS and POSH I would be super happy! :|
 
I am runnign IIS on a Windows 2008R2 x64 Standard Edition if that helps..... of course, I would settle for an CLI if there is no other way, but POSH is of course the way to go! :)
 
Thanks for the help in advance guys, take care!
0
Comment
Question by:Kandium
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 42

Expert Comment

by:Meir Rivkin
ID: 37738347
0
 
LVL 42

Expert Comment

by:Meir Rivkin
ID: 37738359
please check jgovednik post here:

http://forums.iis.net/t/1172382.aspx
0
 

Author Comment

by:Kandium
ID: 37742324
We are wanting to add a *.cer file and not a *.pfx file, but yes... the function below does work with a pfx file.

function Add-SSLCertificate{
param([string]$pfxPath,[string]$pfxPassword,[string]$hostHeader,[string]$siteName)

$certMgr = New-Object -ComObject IIS.CertObj -ErrorAction SilentlyContinue 
$certMgr.ImportToCertStore($pfxPath,$pfxPassword,$true,$true)

Import-Module WebAdministration;
New-WebBinding -Name $siteName -Port 443 -Protocol https -HostHeader $hostHeader 
}

Open in new window


Also - Yes, we have explored the IIS PowerShell Snap-in and could not find anything to work natively.

Thanks!
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 
LVL 42

Expert Comment

by:Meir Rivkin
ID: 37742553
what i'd is convert *.pfx to *.cer format either by certificate manager in Windows Management Console or using pvkimprt tool:
http://www.microsoft.com/download/en/details.aspx?displaylang=EN&id=6563
and then using the powershell script above.

also check the following link:
http://www.ehow.com/how_8586664_convert-cer-pfx.html
0
 
LVL 42

Expert Comment

by:Meir Rivkin
ID: 37793121
hi,

did u get any progress with your issue?
do u need any further help?

cheers
0
 

Author Comment

by:Kandium
ID: 37796034
Hey,

The tool specified "pvkimprt" does not exist in Windows Server 2008R2 and doing it graphically isn't a solution we are looking for, we need this to be done all through scripting.

We are now also talking to Microsoft for a solution for this one as well and the question has been escalated.

Thanks again!
0
 
LVL 42

Accepted Solution

by:
Meir Rivkin earned 1500 total points
ID: 37796146
well, i used this tool in server2008R2, you can download it from here http://www.microsoft.com/download/en/details.aspx?id=6563
also check this post which describes how to create Code Signing Certificate on Windows Server 2008 with OpenSSL and pvkimprt.
http://blog.webactivedirectory.com/create-a-code-signing-certificate-on-windows-server-2008-with-openssl-and-pvkimprt/

>>doing it graphically isn't a solution we are looking for
what do u mean?

you can have the powershell script run the pvkimprt and passing required parameters in command line, make the conversion and running the rest of the script. so basically you got it all in a single PS script.
0
 

Author Comment

by:Kandium
ID: 37855476
Thanks segwick, that solution will work and we will use it since we have not heard back from MS
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
A walk-through example of how to obtain and apply new DID phone numbers to your cloud PBX enabled users that are configured in Office 365. Whether you have 1, 10 or 100+ users in your tenant, it's quite easy to get them phone-enabled and making/rece…
Video by: ITPro.TV
In this episode Don builds upon the troubleshooting techniques by demonstrating how to properly monitor a vSphere deployment to detect problems before they occur. He begins the show using tools found within the vSphere suite as ends the show demonst…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question