By using this site, you agree to the Privacy Policy.
Accept
EnterinITEnterinITEnterinIT
  • HOME
  • IT PRO
  • TECH
  • MICROSOFT
    • Azure
    • ConfigMgr/SCCM
    • DPM
    • Orchestrator
    • Hyper-V
    • Microsoft Edge Insider
    • MSI
    • Office 365
    • Office Insider
    • Power BI
    • Skype
    • SQL Server
    • Teams
  • WINDOWS
    • Windows Admin Center
    • Windows Client
    • Windows Server
  • SCCM Query Collection List
Reading: How to Migrate Configuration Manager from HTTP to HTTPS
Font ResizerAa
EnterinITEnterinIT
Font ResizerAa
  • HOME
  • IT PRO
  • TECH
  • MICROSOFT
  • WINDOWS
  • SCCM Query Collection List
Search
  • HOME
  • IT PRO
  • TECH
  • MICROSOFT
    • Azure
    • ConfigMgr/SCCM
    • DPM
    • Orchestrator
    • Hyper-V
    • Microsoft Edge Insider
    • MSI
    • Office 365
    • Office Insider
    • Power BI
    • Skype
    • SQL Server
    • Teams
  • WINDOWS
    • Windows Admin Center
    • Windows Client
    • Windows Server
  • SCCM Query Collection List
Configuration Manager Query Collection List
ConfigMgr

How to Migrate Configuration Manager from HTTP to HTTPS

Published: February 11, 2024
3 Min Read
SHARE

How to Migrate Configuration Manager from HTTP to HTTPS – Step-by-Step Guide.

  1. Create the certificate Template (ConfigMgr Clients (if the workstation is not already in place), ConfigMgr IIS Servers, and ConfigMgr DP Servers);
  2. Request the certificates;
  3. On the IIS servers, change the bind to allow HTTPS port (default 443) and select the certificate;
  4. Export the Root CA (and any other CA) certificate and import it into SCCM. Note, do not force the SCCM to use PKI, instead, allow it to use HTTP or HTTPS;
  5. For each client, confirm that the Client Certificate is set to PKI (you can easily check the HKLM\Software\Microsoft\CCM\HttpsState and HKLM\Software\Microsoft\CCM\PKICertReady). or you can check the Report Clients incapable of HTTPS communication;
  6. Confirm that you can navigate to HTTPS://;
  7. From the server, confirm that you can navigate to the CRL for the certificate selected;
  8. From the client, confirm that you can navigate to the CRL for the certificate;
  9. On the console, add the column “Client Certificate” and confirm that it is set to PKI” for all clients (this may take a couple of days/week to be completed);
  10. Once all machines are ready to use HTTPS, migrate the MP and check the logs: MPSetup, MPMSI & MPControl;
  11. On the client side, check the ccmmessaging log.

Now it is time to start migrating and testing all other roles:

For DistributionPoint:

– Import the new DP Certificate and set it to use HTTPS;

For Application Catalog:

– Set the IIS Bindings to use an IIS Certificate;

– You can easily change the app catalog website from HTTP to HTTPS, however, you cannot do it for the app catalog webservice. in this case, you’ll need to uninstall and install it again.

For Software Update Point:

– Set the IIS Binding to use an IIS Certificate;

– run the WSUSUtil.exe configure SSL  (check ServerCertificateName and PortNumber under HKLM\Software\Microsoft\Update Services\Server\Setup);

– Change the SUP to use SSL and confirm it is working;

– force APIRemoting30, ClientWebService, DSSAuthWebService, ServerSyncWebService, and SimpleAuthWebService to use SSL only.

TAGGED:System CenterSystem Center Configuration ManagerTechnical Preview
Previous Article Configuration Manager Query Collection List SCCM Maintenance Windows for device collection
Next Article Configuration Manager Query Collection List Configuration Manager Application Relationships
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Translation

English中文(简体)DanskNederlandsFrançaisDeutschItaliano한국어PolskiPortuguêsRomânăEspañolУкраїнська
by Transposh - translation plugin for wordpress

Popular Posts

System Requirements for Windows Server 2016
Windows Server
Configuration Manager Query Collection List
Configuration Manager Query Collection List
ConfigMgr
Structured/Managed Navigation enabled on Modern Pages in Classic Team Sites
Tech
SCCM Failed to get DP locations as the expected version from MP
ConfigMgr

Recent Posts

Installing and Configuring Fail2ban for SSH Protection on Ubuntu 24.04
Linux
Enabling and Configuring FirewallD on AlmaLinux
Linux
User Creation and SSH Key Setup in AlmaLinux
Linux
How to reset password on AlmaLinux
Linux

© 2023 EnterinIT

Go to mobile version
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?