We have a requirement to replace the self-signed certificate on tentacles. Is there a way to do this utilizing the Microsoft KeyStore and a GPO so that any new installed tentacle is automatically registered with our own certificate?
Thanks for getting in touch! I may need to get some more information from you to get a better idea of how you can achieve this best. But we do have some thoughts based on what you have provided.
It’s up to you how you get the certificate onto the Tentacle server, GPO could help you do that, though it sounded like you already have the Tentacles installed and just need to update the certificate. If this is the case, you could do this directly in Octopus.
If you were to use GPO to achieve this, you will need to copy the PFX over to the target server and have a script perform the certificate replacement against the Tentacle.
Using the Octopus manager for this would be the smoothest approach if you already have Tentacle installed.