Prajwal Desai

SCCM | ConfigMgr | Intune | Windows 11 | Azure

  • Home
  • Cloud
    • Autopilot
    • Azure
    • Endpoint Analytics
    • Intune
    • PowerShell
    • Teams
    • Windows 365
  • Microsoft
    • Active Directory
    • Group Policy
    • SCCM
    • SCOM
    • Windows 10
    • Windows 11
    • Windows Server
    • WSUS
  • Software
  • Forums
  • Newsletter
  • Contact
Notification Show More
Latest News
Fix Windows Autopilot Reset Error 0x80070032
Fix Windows Autopilot Reset Error 0x80070032
Autopilot Intune
Windows activation error 0xc004c020
Fix: Windows Activation Error 0xC004C020 with 2 Easy Methods
Windows 11 Windows 10
Find the Package ID of SCCM Application
3 Best Ways to Find the Package ID of SCCM Application
SCCM
SCCM Updates Install Error 0x800b0109 0x8024b303
Fix: SCCM Updates Install Error 0x800b0109 | 0x8024b303
SCCM
Disable Windows Hello for Business using Intune ftimg
Disable Windows Hello for Business using Intune – Comprehensive Guide
Intune Autopilot
Aa

Prajwal Desai

SCCM | ConfigMgr | Intune | Windows 11 | Azure

Aa
Search
  • Home
  • Cloud
    • Autopilot
    • Azure
    • Endpoint Analytics
    • Intune
    • PowerShell
    • Teams
    • Windows 365
  • Microsoft
    • Active Directory
    • Group Policy
    • SCCM
    • SCOM
    • Windows 10
    • Windows 11
    • Windows Server
    • WSUS
  • Software
  • Forums
  • Newsletter
  • Contact
Follow US

Home » SCCM » 2 Easy Ways to Export Root CA Certificate for ConfigMgr

SCCM

2 Easy Ways to Export Root CA Certificate for ConfigMgr

By Prajwal Desai 1 View 2 comments July 1, 2022 5 Min Read

There are several ways to export Root CA certificate and I will show you 2 easy ways to export the Root Certification Authority certificate for ConfigMgr. The steps are applicable to anyone who wants to download Root CA certificate regardless of ConfigMgr being installed in setup or not.

Before you read further, I assume you have the Certification Authority installed and configured in your setup. You may use my guide to install Enterprise Root Certification Authority. There are two recommended methods to export root CA certificate. You can select any of the below methods to export root CA certificate.

  • Using the Command Prompt, export the Root CA certificate.
  • Request the Root Certification Authority Certificate from the Web Enrollment Site.

The first method seems to be easy and quick because with a single command, you can export Root CA Certificate. While the second method requires you to access the Root Certification Authority Web Enrollment Site and download the Root Certificate.

While working on ConfigMgr, there are instances when you require Root CA certificate. For example, when you are setting up a CMG, you specify the root certificate while adding the cloud management gateway role. Another example is when your CMG Fails with Error 0x80004005. Specifying the Root CA certificate and tweaking the Client Certificate Revocation solves the issue.

- Advertisement -
Ad image

When you deploy PKI certificates for ConfigMgr, you must specify Root CA certificate under the ConfigMgr Site Properties. Most of us ignore this step or we miss it. This is an important step and you shouldn’t skip this step.

ConfigMgr Trusted Root Certification Authorities
ConfigMgr Trusted Root Certification Authorities

Export Root CA Certificate Using Command Prompt

Using the command prompt you can request and export Root CA certificate for ConfigMgr.

  • Log into the Root Certification Authority server (Windows Server) with an Administrator Account.
  • Click Start and type CMD and run the command prompt as administrator.
  • To export the Root CA certificate, run the command certutil -ca.cert C:\RootCA_name.cer
  • Look for CertUtil: -ca.cert command completed successfully. That confirms the Root CA has been exported successfully.
  • Go to the root drive and you should find the Root Certificate.
Export Root CA Certificate
Export Root CA Certificate

Request the Root Certification Authority Certificate from the Web Enrollment Site

The second method involves requesting the certificate from web enrollment site and downloading the Root CA certificate. You can access the URL either from a member server or login to the certificate authority server and export the Root CA Certificate.

Open the browser (preferably Edge or Firefox) and access the Web enrollment site URL which is usually http://servername/certsrv. On the default page, you must select a task and this includes the following options.

  • Request a certificate
  • View the status of a pending certificate request
  • Download a CA certificate, certificate chain, or CRL

Click Download a CA Certificate.

Request the Root Certification Authority Certificate from the Web Enrollment Site
Request the Root Certification Authority Certificate from the Web Enrollment Site

In the next step, click Download CA certificate and save the Root CA certificate to desired location. We have successfully exported the root CA certificate.

Request the Root Certification Authority Certificate from the Web Enrollment Site
Request the Root Certification Authority Certificate from the Web Enrollment Site

Specify the Root CA Certificate under Trusted Root Certification Authorities

Once you have the Root CA certificate exported, you can set it under Trusted Root Certification Authorities.

  • Launch the Configuration Manager console.
  • Navigate to Administration\Overview\Site Configuration\Sites.
  • Select the ConfigMgr site and right click and click Properties.
  • On the Site Properties window, click Communication Security tab.
  • Look for Trusted Root Certification Authorities option and click the Set button.
  • Select the Root CA certificate and apply the certificate. When you do that you will see Root CA specified.
Specify the Root CA Certificate under Trusted Root Certification Authorities
Specify the Root CA Certificate under Trusted Root Certification Authorities

Video Tutorial to export Root Certificate for SCCM

Here is a video tutorial that explains how to export the Root CA Certificate for SCCM.

Sign Up For Weekly Newsletter

Get the most recent information on Configuration Manager, Intune, Windows 11, Windows 365, Autopilot, Azure, Software Reviews, and much more by subscribing to the newsletter.
By signing up, you agree and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Copy Link Print
Avatar photo
By Prajwal Desai
Follow:
Prajwal Desai is a Microsoft MVP in Enterprise Mobility. He writes articles on SCCM, Intune, Configuration Manager, Microsoft Intune, Azure, Windows Server, Windows 11, WordPress and other topics, with the goal of providing people with useful information.
Previous Article Integrate Microsoft Store for Business with Intune How To Integrate Microsoft Store for Business with Intune
Next Article Create Autopilot Profile for HoloLens 2 Devices ftimg Create Autopilot Profile for HoloLens 2 Devices
2 Comments 2 Comments
  • Avatar photo youranswercenter says:
    July 21, 2022 at 12:26 pm

    Super it worked…Thank you sir

    Reply
  • Avatar photo Rodney Garcia says:
    March 28, 2021 at 8:33 pm

    Loved this post!
    In the company, i nerd to implement bitlocker management. I have CM 1910 and need have pki certificares for my clients.

    Do you have steps to implement pki certificares?

    I Will appreciate you help! Thanks
    Rodney

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recast Sponsored AD
Ad image
Patch My PC Sponsored AD
Ad image

Latest Articles

Fix Windows Autopilot Reset Error 0x80070032
Fix Windows Autopilot Reset Error 0x80070032
Autopilot Intune
Windows activation error 0xc004c020
Fix: Windows Activation Error 0xC004C020 with 2 Easy Methods
Windows 11 Windows 10
Find the Package ID of SCCM Application
3 Best Ways to Find the Package ID of SCCM Application
SCCM
SCCM Updates Install Error 0x800b0109 0x8024b303
Fix: SCCM Updates Install Error 0x800b0109 | 0x8024b303
SCCM
Subscribe to Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

You Might Also Like

Find the Package ID of SCCM Application
SCCM

3 Best Ways to Find the Package ID of SCCM Application

By Prajwal Desai
SCCM Updates Install Error 0x800b0109 0x8024b303
SCCM

Fix: SCCM Updates Install Error 0x800b0109 | 0x8024b303

By Prajwal Desai
ConfigMgr Technical Preview 2302 New Features
SCCM

ConfigMgr Technical Preview 2302 New Features | Baseline Version

By Prajwal Desai

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?