{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
        "slug": "dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/"
        },
        "title": "Replace the Windows Admin Center HTTPS certificate deliberately",
        "summary": "What must be checked before a replacement certificate is selected for Windows Admin Center?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:11+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 223,
        "potentially_affected": "Administrators maintaining the HTTPS certificate used by a Windows Admin Center gateway.",
        "dse_recommendation": "Prepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement.",
        "primary_source": {
            "name": "Update the certificate used by Windows Admin Center",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Windows Admin Center requires an HTTPS certificate for its service. Microsoft requires a valid certificate with Server Authentication usage, a private key, and a name matching the gateway FQDN or IP address; its issuer must be trusted by the gateway and clients. The documented subject-name selection method requires a unique certificate subject name in the local-machine Personal certificate store. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the gateway address administrators actually use and the certificate-selection method for the installed version. Review the public certificate properties without exporting its private key. A successful certificate import is only one part of this replacement decision.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement. Where selection uses a subject name, inspect the relevant store for ambiguous matches before proceeding. Schedule the change with another management route available. Keep the previous certificate available under approved retention and key-handling rules until the replacement has passed the agreed connection checks.</p>\n<h2>Verification</h2>\n<p>Connect from an intended administrator browser using the normal gateway URL. Inspect the certificate actually presented, its name and trust chain, and then open a managed connection. If an error remains, review Windows Admin Center events alongside the browser error and record which certificate was selected.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Update the certificate used by Windows Admin Center</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nWindows Admin Center requires an HTTPS certificate for its service. Microsoft requires a valid certificate with Server Authentication usage, a private key, and a name matching the gateway FQDN or IP address; its issuer must be trusted by the gateway and clients. The documented subject-name selection method requires a unique certificate subject name in the local-machine Personal certificate store. Microsoft Learn.\nApplicability\nIdentify the gateway address administrators actually use and the certificate-selection method for the installed version. Review the public certificate properties without exporting its private key. A successful certificate import is only one part of this replacement decision.\nDSE recommendation\nPrepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement. Where selection uses a subject name, inspect the relevant store for ambiguous matches before proceeding. Schedule the change with another management route available. Keep the previous certificate available under approved retention and key-handling rules until the replacement has passed the agreed connection checks.\nVerification\nConnect from an intended administrator browser using the normal gateway URL. Inspect the certificate actually presented, its name and trust chain, and then open a managed connection. If an error remains, review Windows Admin Center events alongside the browser error and record which certificate was selected.\nOfficial references\nMicrosoft Learn: Update the certificate used by Windows Admin Center. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nWindows Admin Center requires an HTTPS certificate for its service. Microsoft requires a valid certificate with Server Authentication usage, a private key, and a name matching the gateway FQDN or IP address; its issuer must be trusted by the gateway and clients. The documented subject-name selection method requires a unique certificate subject name in the local-machine Personal certificate store. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate).\n\n## Applicability\n\nIdentify the gateway address administrators actually use and the certificate-selection method for the installed version. Review the public certificate properties without exporting its private key. A successful certificate import is only one part of this replacement decision.\n\n## DSE recommendation\n\nPrepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement. Where selection uses a subject name, inspect the relevant store for ambiguous matches before proceeding. Schedule the change with another management route available. Keep the previous certificate available under approved retention and key-handling rules until the replacement has passed the agreed connection checks.\n\n## Verification\n\nConnect from an intended administrator browser using the normal gateway URL. Inspect the certificate actually presented, its name and trust chain, and then open a managed connection. If an error remains, review Windows Admin Center events alongside the browser error and record which certificate was selected.\n\n## Official references\n\n[Microsoft Learn: Update the certificate used by Windows Admin Center](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Replace the Windows Admin Center HTTPS certificate deliberately",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/",
                "headline": "Replace the Windows Admin Center HTTPS certificate deliberately",
                "description": "What must be checked before a replacement certificate is selected for Windows Admin Center?",
                "abstract": "What must be checked before a replacement certificate is selected for Windows Admin Center?",
                "articleBody": "Source facts\nWindows Admin Center requires an HTTPS certificate for its service. Microsoft requires a valid certificate with Server Authentication usage, a private key, and a name matching the gateway FQDN or IP address; its issuer must be trusted by the gateway and clients. The documented subject-name selection method requires a unique certificate subject name in the local-machine Personal certificate store. Microsoft Learn.\nApplicability\nIdentify the gateway address administrators actually use and the certificate-selection method for the installed version. Review the public certificate properties without exporting its private key. A successful certificate import is only one part of this replacement decision.\nDSE recommendation\nPrepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement. Where selection uses a subject name, inspect the relevant store for ambiguous matches before proceeding. Schedule the change with another management route available. Keep the previous certificate available under approved retention and key-handling rules until the replacement has passed the agreed connection checks.\nVerification\nConnect from an intended administrator browser using the normal gateway URL. Inspect the certificate actually presented, its name and trust chain, and then open a managed connection. If an error remains, review Windows Admin Center events alongside the browser error and record which certificate was selected.\nOfficial references\nMicrosoft Learn: Update the certificate used by Windows Admin Center. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:11+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Replace the Windows Admin Center HTTPS certificate deliberately"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 223,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Update the certificate used by Windows Admin Center",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate"
                }
            }
        ]
    }
}