• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
ControlUp Community

ControlUp Community

Connect, Learn, and Grow

  • Blog
  • Podcast
  • Meetups
  • Archives
  • Categories
    • ControlUp One Platform
    • ControlUp for Apps
    • ControlUp for Compliance
    • ControlUp for Desktops
    • ControlUp Scripts & Triggers
    • ControlUp Synthetic Monitoring
    • ControlUp for VDI
  • Topics
  • Events
    • Logos & Wallpaper
    • ControlUp.com
  • Join

How does ControlUp Agent Certificate Communication Work?

Posted on February 16, 2023

It was asked if a single certificate needs to be used across Real-Time Consoles, Monitors, and ControlUp Agents, with the Consoles and Monitors holding the private key while the public key is deployed to the Agents. Remediation can be automated for the agents with a GPO, and for the Console/Monitors with a supported PowerShell scripted provided by ControlUp. More information on agent certificate communication can be found at https://support.controlup.com/v1/docs/certificate-based-agent-authentication.


Read the entire ‘Automating Certificate Remediation with ControlUp Agents’ thread below:

Can anyone verify that I correctly understand the way that agent certificate communication works? https://support.controlup.com/v1/docs/certificate-based-agent-authentication

It looks like a single certificate needs to be used on Real-Time Consoles, Monitors and ControlUp Agents. With the Consoles and Monitors holding the private key and the public key being deployed to the Agents.

If I was enabling this in an Enterprise I would first expect to use ADCS or similar issued certificates that are auto-renewed. And then just tell ControlUp to trust certificates issued by that CA. This allows auto-renewing and reduces the remediation effort if a single private key is compromised.

That is not possible in ControlUp though, am I right?


You got this right @member. Not sure about ADCS, but in regards to automation, you can achieve it via the following method:


  1. for the agents, you can use a GPO (or any other method) to make sure the agents always have the latest public key certificate deployed and relevant registry keys configured
  2. for the Console / Monitors, it’s again just making sure that the relevant cert with the private key and the registry keys are up to date. we have a supported PowerShell script that automates this task, so you can use the PowerShell automation method each time you need to update the cert / keybut indeed, this is a single private key across the enterpriseThanks Yoni!

Continue reading and comment on the thread ‘How does ControlUp Agent Certificate Communication Work?’.  Not a member? Join Here!


Categories: All Archives, ControlUp for VDI, ControlUp Scripts & Triggers
Topics: Authentication, Automation, Automation & Alerting, Certificates, ControlUp Agent, PowerShell, Scripts

Ask Us Anything, Connect, Learn, and Grow with the ControlUp Community!

Login to the ControlUp Community to ask us anything, stay up-to-date on what’s new and coming soon and meet other like-minded techies like you.

Not already a member? Join Today!

Primary Sidebar

ControlUp Academy

Enroll in ControlUp Academy for expert-led technical training, equipping you with skills to effectively deploy, manage, and grow your ControlUp investment.

Learn here >

Rotating Images

Hidden Gem from our Community on Slack!

ControlUp Betas - What's Coming Next?
NEW ControlUp Features - Stay Up-to-Date!
ControlUp Scripts - Scripting, Zero to Hero
Latest KB Articles - Be the First to Learn
Did you Know - with Sivan Kroitoru
Practical Perspectives Technical Use Case Training

Video Tutorials Library

Visit our technical how-to videos, offering step-by-step tutorials on advanced features, troubleshooting, and best practices.

Watch here >

ControlUp Blog

Check out the ControlUp blog for expert advice and in-depth analysis.

Read here >

ControlUp Script Library

Visit the ControlUp technical script library, which offers a multitude of pre-built scripts and custom actions for your monitoring and troubleshooting requirements.

See here >

ControlUp Support

Visit the ControlUp support home and to delve deeper into ControlUp solutions.

Browse here >

Download ControlUp RealTime DX

Start with ControlUp for real-time end-user environment insights, swift troubleshooting, and unprecedented performance optimization. Download now.

Download here >

Footer

      

ControlUp Community
Of Techie, By Techie, For Techie!

Terms of Use | Privacy Policy | Security
Dive Deeper, Learn more at ControlUp.com

  • facebook
  • twitter
  • youtube
  • linkedin

© 2023–2025 ControlUp Technologies LTD, All Rights Reserved.

We use cookies to ensure that we give you the best experience on our website. by continuing to use this site you agree to our Cookie policy..