Configuring Server Certificate

When you configure Veeam Service Provider Console Server certificate, you can specify what TLS certificate must be used. Veeam Service Provider Console offers the following options:

Importing Certificate from Certificate Store

To establish a secure connection with Veeam Service Provider Console management agents, a Veeam Service Provider Console Server certificate must be a multi-domain or wildcard TLS certificate signed by a CA and located in the Microsoft Windows certificate store. The certificate must meet the following requirements:

Note:

It is recommended to use different TLS certificates for Veeam Cloud Connect and Veeam Service Provider Console server in distributed deployments. Using the same certificate on multiple machines may compromise the private key of the certificate.

To import a certificate from the Microsoft Windows certificate store, do the following on the machine where Veeam Service Provider Console Server component is installed:

  1. Log in to Veeam Service Provider Console. For details, see Accessing Veeam Service Provider Console.
  1. At the top right corner of the Veeam Service Provider Console window, click Configuration.
  2. In the configuration menu on the left, click Security.
  3. Navigate to the Security Certificates tab.
  4. At the top of the list, click Install > Server.
  5. At the Certificate Type step of the Manage Certificate window, select the Select certificate from the certificate store option.
  6. At the Pick Certificate step, select a certificate that you want to install and click Next.

Note:

Consider the following:

  • You can select only certificates that contain both a public key and a private key. Certificates without private keys are not displayed in the list.
  • The certificate must be installed in the Local Computer or Personal certificate store.
  • Make sure that an account used to install security certificates has access to private keys of the certificates.

Select Certificate from Certificate Store

  1. Review the certificate settings and click Finish.
  2. Log on as Administrator to the machine where Veeam Service Provider Console Server component is installed.
  3. Restart the Veeam Management Portal service.
  4. Refresh the Veeam Service Provider Console portal page.

Generating New Self-Signed Certificate

To generate self-signed TLS certificates, Veeam Service Provider Console uses RSA algorithm with a 2048-bit key length and SHA-2 hashing algorithm. The created TLS certificate is saved to the Shared certificate store. The following types of users can access the generated TLS certificate:

Note:

If you replace the default certificate with another self-signed certificate, you need to do the following:

  • Import the new certificate to the client machines (the machines from which you plan to access Veeam Service Provider Console). For details on importing certificates, see Microsoft Docs.
  • Manually configure a trusted connection between Veeam Service Provider Console and management agents. For details, see Deploying Management Agents Manually.

To generate a new self-signed TLS certificate, do the following:

  1. Log in to Veeam Service Provider Console.

For details, see Accessing Veeam Service Provider Console.

  1. At the top right corner of the Veeam Service Provider Console window, click Configuration.
  2. In the configuration menu on the left, click Security.
  3. Navigate to the Security Certificates tab.
  4. At the top of the list, click Install > Server.
  5. At the Certificate Type step of the Manage Certificate window, select the Generate new certificate option.
  6. At the Generate Certificate step, specify a friendly name for a certificate that you want to install and click Next.

Generate New Self-Signed Certificate

  1. Review the certificate settings and click Finish.
  2. Log on as Administrator to the machine where Veeam Service Provider Console Server component is installed.
  3. Restart Veeam Management Portal service.
  4. Refresh the Veeam Service Provider Console portal page.

Related Topics

Certificate Validation Errors

Page updated 6/2/2025

Page content applies to build 8.1.0.21999