Windows Server: How to Use Trusted Certificates with Remote Desktop Services

Summary: This article shows how to configure Remote Desktop Services (RDS) to use a trusted certificate from a third-party certification authority (CA).

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

Several components of RDS can use certificates to provide secure communications. Self-signed certificates can be used, but they must be manually installed on clients in order to be trusted. Certificates issued by a trusted CA are automatically trusted by clients, but configuring RDS to use these certificates is not straightforward for two reasons:

  • There is no integrated mechanism within RDS for creating a certificate signing request (CSR).
  • A certificate received from a CA must be bound to its private key before RDS can use it.

This article shows how to generate a CSR, use the issued certificate to complete the CSR, and configure RDS to use the certificate.

Generate the CSR and submit it to the CA.

Note: In the steps below, Internet Information Services (IIS) Manager is used to generate and complete the CSR. Most RDS deployments have IIS components installed on at least one server, for use by Remote Desktop Web Access. IIS Manager provides a graphical interface for performing these steps, but there are other ways to perform them, such as the certreq command.
  1. Launch Internet Information Services (IIS) Manager from the Tools menu of Server Manager.
  2. Select the server in the left pane and double-click Server Certificates in the middle pane.
  3. In the Actions menu, select Create Certificate Request.
    Screenshot of Server Certificates in IIS Manager, with the "Create Certificate Request" link highlighted
    Figure 1: Click Create Certificate Request to begin the process of creating a CSR.
  4. Provide the requested information to the CSR wizard.
  5. Specify a filename and path for the CSR and click Finish.
    Dialog box prompting for a file name and path for the CSR 
    Figure 2: Specify a file name and path for the certificate request.
  6. Submit the CSR to the CA. The procedure for doing so cannot be documented here, as it depends on the CA.

 

Download the certificate, complete the CSR, and export it.

Note: The certificate issued by the CA will likely have a .cer or .crt extension, but RDS requires a .pfx file. To convert the issued certificate to a .pfx file, bind it to its private key with the following steps. IIS Manager is again used here to perform these steps, but there are other methods.
  1. Download the certificate issued by the CA in response to the CSR.
  2. Launch IIS Manager and return to the Server Certificates section.
  3. Click Complete Certificate Request.
    Screenshot of Server Certificates in IIS Manager, with the "Complete Certificate Request" link highlighted
    Figure 3: Click Complete Certificate Request to complete the CSR using the certificate issued by the CA.
  4. Provide the path and filename of the certificate, its friendly name, and the certificate store where it should be stored. The friendly name can be anything you want, and the Personal store is preferred. Click OK. This associates the certificate with the private key that was created alongside the CSR.
    Dialog box requesting the path to the CA-issued certificate, its friendly name, and the certificate store that will contain it 
    Figure 4: Specify the path to the certificate, its friendly name, and a certificate store.
  5. Double-click the certificate. Confirm the presence of a corresponding private key and click OK.
    Properties of the certificate, showing that a corresponding private key exists 
    Figure 5: The properties of the certificate, indicating the presence of its private key
  6. With the certificate selected, click Export.
    Screenshot of Server Certificates in IIS Manager, with the "Export" link highlighted
    Figure 6: Click Export to export the certificate and its private key. 
  7. Provide a filename and path for the exported certificate. Specify a password and confirm it, then click OK.
    Dialog box prompting for the filename, path, and password of the exported certificate 
    Figure 7: Provide the filename, path, and password of the exported certificate.

 

Configure RDS to use the certificate.

  1. In the Remote Desktop Services section of Server Manager, select Edit Deployment Properties.
    Screenshot of Remote Desktop Services in Server Manager, showing the "Edit Deployment Properties" link 
    Figure 8: Click Edit Deployment Properties to configure certificate usage in RDS.
  2. In the properties window, select Certificates.
  3. Perform the following steps for each role service:
    1. Select the role service and click Select existing certificate.
      Screenshot of the Certificates section of the RDS deployment properties window, with the "Select existing certificate" button highlighted
      Figure 9: Click Select existing certificate to specify a certificate for each role service.  
    2. With Choose a different certificate selected, provide the path to the exported certificate and its password.
      Select Allow the certificate to be added to the Trusted Root Certification Authorities certificate store on the destination computers.
      Dialog box prompting for the path and password of the certificate to be used 
      Figure 10: Specify the path and password of the certificate to the used, then check the Allow the certificate… box.
    3. Click OK.
    4. Click Apply.
  4. Confirm that the Level column shows a status of Trusted for each role service and click OK.
    Screenshot of the Certificates section of the RDS deployment properties window, showing that all certificates are trusted 
    Figure 11: The certificates used by all RDS role services are now trusted.

Additional Information

Refer to this video:

Configure Remote Desktop Services to Use Trusted Certificates

Duration: 00:07:51 (hh:mm:ss)
When available, closed caption (subtitles) language settings can be chosen using the CC icon on this video player.

You can also view this video on YouTube.

 

Affected Products

Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025
Article Properties
Article Number: 000273687
Article Type: How To
Last Modified: 28 May 2025
Version:  4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.