1.4.5.5.5.3. Step 3: Verify the service user and SSL certificate
  1. Ensure that the user under which the service is running is the desired service user.

    [Note]Note

    Install service installed the service as a local system. For operation of the cache service, this is sufficient, since it does not rely on any network shares, as long as the RFS2 cache directory locally. If the service is nevertheless to be provided under another user, set this directly in the Service Management ( services.msc ).

    The use of a different user also has implications for Windows authentication (Kerberos via Negotiate): The Service Principal Name (SPN) for the HTTP service is assigned by default to the computer account and therefore works automatically when the service runs as Local System. If the service runs under a dedicated user account, the SPN must be mapped to that account accordingly:

    setspn -S HTTP/<dnsname> <serviceuser>

    For more information, see the Microsoft documentation on Kerberos authentication via Negotiate.

  2. Positions Make sure that in the certificate store of the local computer ( certlm.msc ) a valid SSL certificate exists and that the service user has access to has the private key.

  3. If this is not the case, you can either:

    • Create a self-signed certificate (not recommended) – Click the " Create self-signed certificate…" button, or

    • Create a certificate request (CSR) to submit to your CA — click the " Generate certificate request (CSR)..." button — and then import the issued certificate using " Import issued certificate..." .