{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
        "slug": "dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/"
        },
        "title": "Track RDS role certificates separately from the session-host listener",
        "summary": "Which certificate assignments belong in an RDS deployment certificate review?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:36+00:00",
        "modified_at": "2026-09-08T18:29:33+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 207,
        "potentially_affected": "Administrators assigning certificates to Remote Desktop Services roles.",
        "dse_recommendation": "Prepare a role-to-name-to-certificate register with thumbprint, intended assignment, expiration, and renewal owner.",
        "primary_source": {
            "name": "Use certificates in Remote Desktop Services",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft describes TLS-protected connections for RD Web, Connection Broker, and Gateway role services. The documented deployment procedure requires a PFX export containing the certificate and its private key. The page separately directs administrators to listener-certificate guidance for certificates on an RD Session Host. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Inventory the actual RDS roles and client-facing names before selecting a certificate. Identify the role assignment being changed and whether session-host listener configuration also needs separate review. Check the current source requirements rather than assuming one imported certificate proves every RDP endpoint is configured.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare a role-to-name-to-certificate register with thumbprint, intended assignment, expiration, and renewal owner. Restrict access to the PFX and its private-key protection material through the approved certificate-handling process. Pilot the deployment assignment and preserve the previous bindings. Have the RDS owner identify which connection paths must be tested after the change.</p>\n<h2>Verification</h2>\n<p>Connect through each intended role using its approved name and inspect the presented certificate and trust result. Test a representative session-host connection separately when it is in scope. Compare the observed bindings with the register and investigate unexpected names or certificates before closing the change. Record renewal follow-up responsibility.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use certificates in Remote Desktop Services</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft describes TLS-protected connections for RD Web, Connection Broker, and Gateway role services. The documented deployment procedure requires a PFX export containing the certificate and its private key. The page separately directs administrators to listener-certificate guidance for certificates on an RD Session Host. Microsoft Learn.\nApplicability\nInventory the actual RDS roles and client-facing names before selecting a certificate. Identify the role assignment being changed and whether session-host listener configuration also needs separate review. Check the current source requirements rather than assuming one imported certificate proves every RDP endpoint is configured.\nDSE recommendation\nPrepare a role-to-name-to-certificate register with thumbprint, intended assignment, expiration, and renewal owner. Restrict access to the PFX and its private-key protection material through the approved certificate-handling process. Pilot the deployment assignment and preserve the previous bindings. Have the RDS owner identify which connection paths must be tested after the change.\nVerification\nConnect through each intended role using its approved name and inspect the presented certificate and trust result. Test a representative session-host connection separately when it is in scope. Compare the observed bindings with the register and investigate unexpected names or certificates before closing the change. Record renewal follow-up responsibility.\nOfficial references\nMicrosoft Learn: Use certificates in Remote Desktop Services. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft describes TLS-protected connections for RD Web, Connection Broker, and Gateway role services. The documented deployment procedure requires a PFX export containing the certificate and its private key. The page separately directs administrators to listener-certificate guidance for certificates on an RD Session Host. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates).\n\n## Applicability\n\nInventory the actual RDS roles and client-facing names before selecting a certificate. Identify the role assignment being changed and whether session-host listener configuration also needs separate review. Check the current source requirements rather than assuming one imported certificate proves every RDP endpoint is configured.\n\n## DSE recommendation\n\nPrepare a role-to-name-to-certificate register with thumbprint, intended assignment, expiration, and renewal owner. Restrict access to the PFX and its private-key protection material through the approved certificate-handling process. Pilot the deployment assignment and preserve the previous bindings. Have the RDS owner identify which connection paths must be tested after the change.\n\n## Verification\n\nConnect through each intended role using its approved name and inspect the presented certificate and trust result. Test a representative session-host connection separately when it is in scope. Compare the observed bindings with the register and investigate unexpected names or certificates before closing the change. Record renewal follow-up responsibility.\n\n## Official references\n\n[Microsoft Learn: Use certificates in Remote Desktop Services](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Track RDS role certificates separately from the session-host listener",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/",
                "headline": "Track RDS role certificates separately from the session-host listener",
                "description": "Which certificate assignments belong in an RDS deployment certificate review?",
                "abstract": "Which certificate assignments belong in an RDS deployment certificate review?",
                "articleBody": "Source facts\nMicrosoft describes TLS-protected connections for RD Web, Connection Broker, and Gateway role services. The documented deployment procedure requires a PFX export containing the certificate and its private key. The page separately directs administrators to listener-certificate guidance for certificates on an RD Session Host. Microsoft Learn.\nApplicability\nInventory the actual RDS roles and client-facing names before selecting a certificate. Identify the role assignment being changed and whether session-host listener configuration also needs separate review. Check the current source requirements rather than assuming one imported certificate proves every RDP endpoint is configured.\nDSE recommendation\nPrepare a role-to-name-to-certificate register with thumbprint, intended assignment, expiration, and renewal owner. Restrict access to the PFX and its private-key protection material through the approved certificate-handling process. Pilot the deployment assignment and preserve the previous bindings. Have the RDS owner identify which connection paths must be tested after the change.\nVerification\nConnect through each intended role using its approved name and inspect the presented certificate and trust result. Test a representative session-host connection separately when it is in scope. Compare the observed bindings with the register and investigate unexpected names or certificates before closing the change. Record renewal follow-up responsibility.\nOfficial references\nMicrosoft Learn: Use certificates in Remote Desktop Services. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:36+00:00",
                "dateModified": "2026-09-08T18:29:33+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-215-track-rds-role-certificates-separately-from-the-session-host-listener/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Track RDS role certificates separately from the session-host listener"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 207,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use certificates in Remote Desktop Services",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remote-desktop-services-certificates"
                }
            }
        ]
    }
}