 ====== SSL Certificates for Remote Desktop Services ====== ====== SSL Certificates for Remote Desktop Services ======
 +Recently, all public certificate providers are stopping issuing certificates with ‘.LOCAL’ in them
 +<​cite>​[[https://​​askperf/​2014/​01/​24/​certificate-requirements-for-windows-2008-r2-and-windows-2012-remote-desktop-services/​|Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services | Ask the Performance Team Blog]] - also includes good info on wildcard / SAN certificate options</​cite>​
 ===== Install Certificate on Session Host ===== ===== Install Certificate on Session Host =====
 Set-WmiInstance -Path $path -argument @{SSLCertificateSHA1Hash="​$Thumbprint"​} Set-WmiInstance -Path $path -argument @{SSLCertificateSHA1Hash="​$Thumbprint"​}
 </​code>​ </​code>​
 +===== Installing certificate on the Gateway =====
 +Assuming you have a real (eg GoDaddy) certificate in PFX format (if it's already is mmc, right click in and export, along with private key),
 +There'​s several places where this needs to be imported into the RD Gateway
 +  - In RD Gateway Manager, Right click the server, properties, SSL Certificate tab
 +  - In the Deployment properties, select each role service, "​Select existing certificate",​ "​Choose a different certificate",​ browse to the PFX and enter the password. Do the same for each role service. Use the same certificate for all (suggest a wildcard eg *
