Administrator Guide
\MgmtSvc-TenantPublicAPI
\<Prefix>APT01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\MgmtSvc-TenantSite
\<Prefix>APT01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\MgmtSvc-Usage
\<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\MgmtSvc-UsageCollector
\<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\MgmtSvc-WebAppGallery
<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\MgmtSvc-WindowsAuthSite
<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\SMA
<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
\SPF
<Prefix>APA01
CF75D3CAE126353B0700F9820ECBA0F67F75001C.pfx
The Set-SslCerticate runbook that you run in the next section processes the folder tree in the following order:
• Searches for .pfx les at \\host\share\WebSiteName\VMName\*.pfx
• If it nds no .pfx les at the VM level, it searches \\host\share\WebSiteName\*.pfx
• If it nds no .pfx les at the website level, it searches \\host\share\*.pfx
• If it nds no .pfx les at all, it returns the following error message: Error, no .pfx le.
Step 5: Update to the new trusted certication authority certicate on
each component virtual machine
You must run a runbook to update to the new, signed certicates for the Windows Azure Pack website services, SMA and SPF.
1 Create a PowerShell Credential asset. The password for this asset must match the password that was used to protect the private key
of the new certicates.
NOTE
: If you want to restore a certicate, this password must match the password you used in Step
1.
a In the Windows Azure Pack management portal for administrators, click Automation in the navigation pane.
b On the Automation page, click Assets.
c Click Add Setting, and then in the Add Setting window, click Add Credential.
d In the Credential Type list, click PowerShell Credential.
e In the Name box, type a name for the asset (for example, CertImport), and then click the Next arrow.
f In the User Name box, enter a user name; for example, SMACred. This does not need to be an existing user in the domain, or
have any specic permissions.
132
Security