1.4.5.5.4.1. Recommended: Manage certificates through a CA
  • The certificate should be issued centrally via a certificate authority (CA) with Windows funds ( certlm.msc ) for the server are issued and managed.

  • In this way, the IT department can perform the renewal using Windows' built-in tools without having to make any changes to the server software.

  • The User accounts under which pappserver and pappcache are executed, must have access to the private key of the certificate used.

  • Even for demo environments, you should try to set this up right from the start with valid CA certificates.