The certificate should be issued centrally via a certificate authority (CA) with Windows funds (
certlm.msc) for the server are issued and managed.In this way, the IT department can perform the renewal using Windows' built-in tools without having to make any changes to the server software.
The User accounts under which
pappserverandpappcacheare executed, must have access to the private key of the certificate used.Even for demo environments, you should try to set this up right from the start with valid CA certificates.
