Инструкция по настройке рабочего места zakupki.gov.ru

Инструкция описывает настройку рабочего места на сайте zakupki.gov.ru — Единой информационной системы в сфере закупок.
Автоматизированная настройка zakupki.gov.ru
На сайте zakupki.gov.ru появилась возможность автоматизированной настройки рабочего места.
Переходим по ссылке скачиваем Автоматизированная настройка рабочего места (Windows).exe и запускаем.
После автоматизированной настройке должны установиться браузер Яндекс и плагины.
Ручная настройка zakupki.gov.ru
Браузер для работы в zakupki.gov.ru
Чтобы попасть в личный кабинет сайта zakupki.gov.ru, необходимо использовать Яндекс браузер и Криптопро браузер плагин. Другие браузеры не рекомендуется использовать с сайтом Единой информационной системы в сфере закупок.
Update 2022. Ниже не используем.
Корневой сертификат zakupki.gov.ru
Скачать корневой сертификат zakupki.gov.ru можно по этой ссылке. Необходимо скачать, распоковать архив.
Нажимаем правой кнопкой мыши на файле сертификата -> Установить сертификат.
Откроется «Мастер импорта сертификатов» -> Далее.
В окне «Хранилище сертификатов», выбираем «Поместить все сертификаты в следующее хранилище» -> Обзор -> Доверенные корневые центры сертификации.

Настройка браузера Internet Explorer для zakupki.gov.ru
Чтобы добавить сайт https://zakupki.gov.ru/ в список доверенных узлов необходимо:
Открыть Internet Explorer (в Windows 10 не Edge) -> нажать клавишу Alt -> В меню «Сервис» выбрать «Свойства браузера», выбрать вкладку «Безопасность» -> Надежные сайты -> Сайты.

Добавить сайт https://zakupki.gov.ru

Во вкладке Надежные сайты, нажимаем на кнопку Другой
В открывшемся окне изменяем следующие значения:
- Блокировать всплывающие окна — Отключить
- Доступ к источникам данных за пределами домена — Включить

Также в этом же окне в блоке Сценарии:
- Активные сценарии — Включить
- Включить фильтр XSS — Отключить
- Выполнять сценарии приложений Java — Включить

Во вкладке Дополнительно, убрать галочку использовать Использовать SSL 3.0:

Установка компонента для формирования подписи Ланит sign.cab
Скачать компонент для формирования подписи Ланит sign можно по этой ссылке.

Настройка рабочего места zakupki.gov.ru завершена.
Ошибки при работе с zakupki.gov.ru:
При попытке зайти в «Личный кабинет» zakupki.gov.ru не появляется окно выбора сертификата
- Установлен ли корневой сертификат УЦ
- Правильно ли установлен личный сертификат
- Проверить работу КриптоПро
Не отображает страницу zakupki.gov.ru или Не удается отобразить эту страницу
Временно отключите антивирусное ПО.
Ошибка при установлении защищённого соединения
Необходимо использовать Internet Explorer.
16 Комментариев Инструкция по настройке рабочего места zakupki.gov.ru ” —>
Николай says:
Если вы делали все по инструкции и у Вас ошибка «Не удается установить соединение» и при этом установлен антивирус Касперский, то в настройках необходимо отключить «Проверять защищенные соединения». Тогда все заработает.
RaYKeX says:
Спасибо, Николай, у меня тоже именно из-за Каспера не работало, всё перепробовал, стал рыться уже в яндексе — чего делать — и попал сюда. Всё работает)
Роберт says:
Всем привет, долго мучался со всей этой хрень и помогло только выполнить диагностику на контуре и исправить все автоматически сразу получилось зарегестрироваться. может кому будет полезно https://help3.kontur.ru/uc
Алексей says:
Спасибо, добрый человек! Аналогичная ситуация, помогло!
Константин says:
Спасибо большое Роберт, ты спас мои нервы!!
Василий says:
«Скачать компонент для формирования подписи Ланит sign можно по этой ссылке.» — ссылка не работает.
Александр says:
Если я ничего не путаю, то для сайта закупок можно использовать браузер Спутник (только установить с поддержкой отечественной криптографии).
анна says:
А мы вообще не можем разместить сведения о заключенном контракте пятый день. Ошибка сервера после обновления, срок пройдёт будем штраф платить. В техподдержку невозможно дозвониться, на обращения не отвечают. Задолбала эта ЕИС
Константин says:
звоните ночью
рапро says:
такое ощущение что государство с помощью этой настройки безопасности хочет геноцид устроить, все время что то да глючит позор им
Александр says:
Не могу понять — в госуслугах я подтвердил что я ИП, но при регистрации везде галочка Участник закупок (Физическое лицо РФ, являющееся индивидуальным предпринимателем) недоступна. Но ниже есть запись: Поставщик является субъектом малого предпринимательства. Не могу понять — галочку мне все же надо как-то поставить или это все так и задумано ?
Александр says:
Да, глюки у них постоянно; то плагин версии 3.0.0.0 с Континентом не дружит и из-за этого не зайти, пока не снесешь все, что принадлежит на ключевом носителе Континенту, то сегодня (10.07.2018 г.) невозможно войти в личный кабинет, хотя недели две назад проблем не было и я в системе ничего не менял. Вход на портал госуслуг получается без проблем, также и Торги и ГМУ работают нормально. Сегодня, если у них регламентные работы, то почему в службе поддержки об этом не знают — звонил час назад (около 18.00 мск)
Виктор says:
Почему все ПО, которое касается гособеспечения, сделано через одно место?
Виктор says:
Ребята разработчики, это вы так хорошо занимаетесь импортозамещением? Всецело используя браузер IE от пресловутого Microsoft, а как же ваш хваленый спутник? Почему нет возможности использовать другие браузеры?
“Unable to find manifest signing certificate in the certificate store” — even when add new key
I cannot build projects with a strong name key signing — the message in the title always comes up. Yes the project was initially copied over from another machine. However even if I add a new key via the Signing tab in Project Properties, this error is still shown. I have tried running Visual Studio as an Administrator and have tried manually adding the keys to Windows Certificate Store. Help! Edit: I don’t get this error with a new project, but I’d quite like to get this existing project working. It won’t work even if I create a new certificate!
- visual-studio-2010
- visual-studio
- code-signing
- strongname
asked Aug 14, 2012 at 17:03
9,069 10 10 gold badges 45 45 silver badges 65 65 bronze badges
What type of VS project? Have you unchecked the «Sign the ClickOnce manifests» on the Project Properties Signing Tab as well?
Aug 20, 2012 at 17:21
@Simon Mourier, if I uncheck that option then the file won’t be signed. I want it to be signed! It’s a C# project. Works fine on my main development machine, just not on the laptop.
Aug 23, 2012 at 21:53
Is the error message displayed in your build log, or in some other way? It may help if you copy and paste the log.
Aug 25, 2012 at 14:35
An error in the build log: “Unable to find manifest signing certificate in the certificate store”
Aug 25, 2012 at 14:52
I didn’t see the lines of code in the accepted answer. But this worked for me: I created a new key in VS2015. I unclicked Sign the Assembly and saved. Then I clicked the Select from File button,chose the file I’d just created, clicked again on Sign the assembly, and saved. Rebuilt.
Aug 22, 2017 at 19:03
12 Answers 12
I’ve finally found the solution.
- Edit the .csproj file for the project in question.
- Delete the following lines of code:
. xxxxxxxx.pfx true false
1,760 1 1 gold badge 9 9 silver badges 31 31 bronze badges
answered Aug 26, 2012 at 12:27
9,069 10 10 gold badges 45 45 silver badges 65 65 bronze badges
Worked for me too. Any caveats of such action?
Jan 16, 2019 at 17:36
Yup, deleted anything with «Manifest» and it worked 🙂
Jun 18, 2019 at 20:40
I wouldn’t do this without knowing the repercussions. does it anyway
Jun 27, 2019 at 12:42
In my case, Deleting ManifestCertificateThumbprint and ManifestKeyFile solve the problem.
Dec 19, 2019 at 11:12
@Parrotmaster were there any long term repercussions in the long term for your project?
Nov 6, 2020 at 19:40
Go to your project’s «Properties» within visual studio. Then go to signing tab.
Then make sure Sign the Click Once manifests is turned off.
Updated Instructions:
Within your Solution Explorer:
- right click on your project
- click on properties
- usually on the left-hand side, select the «Signing» tab
- check off the Sign the ClickOnce manifests
- Make sure you save!

answered Mar 2, 2015 at 13:17
2,747 1 1 gold badge 17 17 silver badges 23 23 bronze badges
What you said is fine and should work but didn’t. In the end I had to delete the lines of code as mentioned in the answer below
Oct 29, 2015 at 10:14
What does this do/what does this action mean?
Feb 26, 2016 at 22:33
@TrailMix It will modify you config file appropriately.
Oct 4, 2016 at 22:30
this gave me a solution for vs2010 🙂 up !
Nov 22, 2016 at 5:45
Nice answer! I am using VS2012 and it really works! +1
Jan 26, 2018 at 0:59
I resolved this problem by following this steps:

- Open project properties
- Click on Signing Tab
- And uncheck «Sign the assembly»
2,462 1 1 gold badge 21 21 silver badges 36 36 bronze badges
answered Apr 29, 2018 at 3:37
Amit Kadam Amit Kadam
589 6 6 silver badges 8 8 bronze badges
This may prevent publishing (if we care) but now it runs.
Mar 16, 2022 at 19:17
Right click on your project → Go to properties → Click signing which is left side of the screen → Uncheck the Sign the click once manifests → Save & Build
39.8k 58 58 gold badges 177 177 silver badges 291 291 bronze badges
answered Nov 28, 2016 at 8:53
1,256 1 1 gold badge 14 14 silver badges 19 19 bronze badges
In additional, SignManifest value can be set to false in the .csproj file of the relevant project
Nov 8, 2022 at 13:07
- Open the .csproj file in Notepad.
- Delete the following information related to signing certificate in the certificate store
xxxxx xxxxxx xxxxxxxx.pfx true false
14.7k 22 22 gold badges 140 140 silver badges 175 175 bronze badges
answered Aug 13, 2014 at 12:51
Rajamohan Rajendran Rajamohan Rajendran
369 1 1 gold badge 3 3 silver badges 13 13 bronze badges
Go to your projects «Properties» within visual studio. Then go to signing tab.
Then make sure Sign the Click Once manifests is turned off.
1.Open the .csproj file in Notepad.
2.Delete the following information related to signing certificate in the certificate store xxxxx xxxxxx xxxxxxxx.pfx true false `
answered May 5, 2016 at 15:50
81 1 1 silver badge 3 3 bronze badges

Assuming this is a personal certificate created by windows on the system you copied your project from, you can use the certificate manager on the system where the project is now and import the certificate. Start the certificate manager (certmgr) and select the personal certificates then right click below the list of existing certificates and select import from the tasks. Use the browse to find the .pfx in the project (the .pfx from the previous system that you copied over with the project). It should be in the sub-directory with the same name as the project directory. I am familiar with C# and VS, so if that is not your environment maybe the .pfx will be elsewhere or maybe this suggestion does not apply. After the import you should get a status message. If you succeeded, the compile certificate error should be gone.
answered Oct 27, 2014 at 17:52
327 1 1 silver badge 7 7 bronze badges
Clear and concise!
Apr 15, 2019 at 15:50
It is not enough to manually add keys to the Windows certificate store. The certificate only contains the signed public key. You must also import the private key that is associated with the public key in the certificate. A .pfx file contains both public and private keys in a single file. That is what you need to import.
answered Aug 23, 2012 at 21:10
Owen Wengerd Owen Wengerd
1,628 1 1 gold badge 11 11 silver badges 11 11 bronze badges
Thanks but already tried that. Visual Studio should automatically add the certificate when you create a new one anyway. However I have tried adding the .pfx file manually too. Left windows to install it in the correct certificate store and also added it to my personal store.
Aug 23, 2012 at 21:52
The private key is not stored in the certificate store. Please read this, maybe it will help you understand the distinction: technet.microsoft.com/en-us/library/cc962112.aspx
Aug 24, 2012 at 3:07
I should add that you can verify that the associated private key is available by opening the certificate property window in certificate manager. If the private key is available, the following text is displayed at the bottom of the General page: «You have a private key that corresponds to this certificate». If you do not see that text, the private key is not installed.
Aug 24, 2012 at 3:14
Yes it does say «You have a private key that corresponds to this certificate».
Aug 24, 2012 at 14:23
I think that rules out the key or the certificate as the problem.
Aug 24, 2012 at 15:30
You said you copied files from another computer. After you copied them, did you ‘Unblock’ them? Specifically the .snk file should be checked to make sure it is not marked as unsafe.
answered Aug 24, 2012 at 15:39
Owen Wengerd Owen Wengerd
1,628 1 1 gold badge 11 11 silver badges 11 11 bronze badges
It’s not blocked, it came over from Windows Live Mesh syncing software. However it’s irrelevant since even creating a new key inside Visual Studio on the laptop won’t work.
Aug 25, 2012 at 12:56
To sign an assembly with a strong name using attributes
Open AssemblyInfo.cs (in $(SolutionDir)\Properties )
the AssemblyKeyFileAttribute or the AssemblyKeyNameAttribute , specifying the name of the file or container that contains the key pair to use when signing the assembly with a strong name.
add the following code:
[assembly:AssemblyKeyFileAttribute("keyfile.snk")]
14.7k 22 22 gold badges 140 140 silver badges 175 175 bronze badges
answered Aug 19, 2012 at 17:23
304 2 2 silver badges 9 9 bronze badges
Adding this line doesn’t make a difference, I still get the same error.
Aug 24, 2012 at 14:41
If you need just build the project or solution locally then removing the signing might be a dead simple solution as others suggest.
But if you have this error on your automation build server like TeamCity where you build your actual release pieces for deployment or distribution you might want to consider how you can get this cert properly installed to the cert store on the build machine, so that you get a signed packages at the end of the build.
Generally it is not recommenced to check-in/commit any PFX certificates into source control, so how you get this files on your build server during the build process is a bit another question, but sometimes people do have this file stored along with the solution code, so you can find it in the project folder.
All you need to do is just install this certificate under proper account on your build server.
- Download PsExec from Windows Sysinternals.
- Open a command prompt, and enter the following. It will spawn a new command prompt, running as Local System (assuming that your TeamCity is running under the default Local System account): > psexec.exe -i -s cmd.exe
- In this new command prompt, change to the directory containing the certificate and enter the filename to install (change the name of the file to yours): > mykey.pfx
- The Import Certificate wizard will start up. Click through and select all the suggested defaults.
- Run the build.
All credits goes to Stuart Noble (and then further to Laurent Kempé I believe ☺).
Citrix Workspace Linux 22.9.0.21 SSL Error


Miguel Francis | Enthusiast | 2 | Members | 2 posts
I am getting the dreaded SSL error when trying to use the current version of Citrix Workspace on Ubuntu 22.04.1 LTS. When I try to launch one our applications from our Citrix portal, I get this error:
«Contact your help desk with the following information: You have not chosen to trust ‘AAA Certificate Services’, the issuer of the server’s security certificate (SSL error 61)»
I checked Mozilla’s directory and the most current cert was there so I tried the method mentioned on other posts:
- sudo ln -s /usr/share/ca-certificates/mozilla/* /opt/Citrix/ICAClient/keystore/cacerts
- /opt/Citrix/ICAClient/util/ctx_rehash
Doesn’t fix the issue and still get the same error message.
Saved searches
Use saved searches to filter your results more quickly
Cancel Create saved search
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Error encountered while opening certificate store 1.9.7 #597
SteffenAL opened this issue Oct 12, 2017 · 20 comments
Error encountered while opening certificate store 1.9.7 #597
SteffenAL opened this issue Oct 12, 2017 · 20 comments
Comments
SteffenAL commented Oct 12, 2017 •
Running 1.9.7 beta 2
Having Apache server.
The certificate were created with 1.9.6.
With 1.9.6 all was fine.
N: Create new certificate L: List scheduled renewals R: Renew scheduled S: Renew specific A: Renew *all* C: Cancel scheduled renewal X: Cancel *all* scheduled renewals Q: Quit Please choose from the menu: s 1: apachelounge.com - renew after 2017-12-1 9:34:26 C: Cancel Which renewal would you like to run?: 1 [INFO] Renewing certificate for apachelounge.com [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [EROR] Error encountered while opening certificate store System.Security.Cryptography.CryptographicException: The system cannot find the file specified. at System.Security.Cryptography.X509Certificates.X509Store.Open(OpenFlags flags) at LetsEncrypt.ACME.Simple.Services.CertificateStoreService.GetCertificate(Func`2 filter, X509Store store) [EROR] Renewal for apachelounge.com failed, will retry on next run
Same result with: >letsencrypt —forcerenewal
The text was updated successfully, but these errors were encountered:
WouterTinus added this to the v1.9.7 milestone Oct 14, 2017
WouterTinus added the confirmed bug label Oct 14, 2017
leenen commented Oct 14, 2017
I already changed the storename to Personal, but haven’t tried to rerun LetsEncrypt as the certificate generated is valid and gives no further issues.
SteffenAL commented Oct 14, 2017
Changed in letsencrypt.exe.config to Personal, same issue as above.
Personal
Indeed in MMC/Certificates (Local Computer)/Personal/Certificates I see the certificate apachelounge.com (On Windows 2012 R2)
Btw.
Running Apache, there is no need to use the CertificateStore.
WouterTinus added a commit that referenced this issue Oct 14, 2017
WouterTinus commented Oct 14, 2017
If you don’t want the certificate to be installed to any store, the alternative is to use the —centralsslstore switch, which outputs .pfx files to the specified folder instead of installing to a Windows Certificate Store. AFIAK those .pfx files are not useful for Apache either, but at least it will leave the Certificate Store clean.
leenen commented Oct 14, 2017 •
Seems OK now, except there’s still no scheduled task generated for renewal and no registration in registry at all.
Is there a difference between renewal and a rerun with all parameters specified again?
WouterTinus added the testing label Oct 15, 2017
SteffenAL commented Oct 15, 2017 •
Trying with Beta 3:
First attempt: Certificates are renewed:
[EROR] Error encountered while opening certificate store System.Security.Cryptography.CryptographicException: The system cannot find the file specified. at System.Security.Cryptography.X509Certificates.X509Store.Open(OpenFlags flags) at LetsEncrypt.ACME.Simple.Services.CertificateStoreService.GetCertificate(Func`2 filter, X509Store store) [INFO] Requesting certificate apachelounge.com 2017-10-15 12:19:18 [INFO] Saving certificate to C:\ProgramData\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\apachelounge.com-crt.der [INFO] Installing certificate in the certificate store [INFO] Installing SSL certificate in server software [WARN] Unable to run script. [INFO] Renewal for apachelounge.com succeeded, next one scheduled for 2017-12-14 10:19:20
[INFO] Saving certificate to C:\ProgramData\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\apachelounge.com-crt.der
Should be:
[INFO] Saving certificate to C:\ProgramData\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\
Second attempt, no error any more and certificate is stored in Wouterstore
>letsencrypt --forcerenewal [INFO] Let's Encrypt Windows Simple (LEWS) [INFO] Version 1.9.7.20942 (RELEASE) [INFO] ACME Server https://acme-v01.api.letsencrypt.org/ [INFO] Please report issues at https://github.com/Lone-Coder/letsencrypt-win-simple [INFO] Renewing certificate for apachelounge.com [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Cached authorization result: valid [INFO] Requesting certificate apachelounge.com 2017-10-15 12:28:57 [INFO] Saving certificate to C:\ProgramData\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\apachelounge.com-crt.der [INFO] Installing certificate in the certificate store [INFO] Installing SSL certificate in server software [WARN] Unable to run script. [INFO] Uninstalling certificate from the certificate store [INFO] Removing certificate apachelounge.com 2017-10-15 12:19:18 [INFO] Renewal for apachelounge.com succeeded, next one scheduled for 2017-12-14 10:29:00
So all fine. Maybe you can add an option that IIS is not installed/used, so we do not have a Warning.
Btw.
With 1.9.7 I see : [INFO] Cached authorization result: valid
What does this mean ?
I see that there are no new acme-challenge’s and see no traffic from letsencrypt.org in my server ?
WouterTinus commented Oct 15, 2017 •
The first error happens when LEWS is looking for the previously issued certificate, but is not fatal.
When the new certificate is saved it creates the store (if it doesn’t exist yet). And of course it should be the WebHosting store, not the Wouterstore, I fixed that little oopsie with the beta4 build.
Btw.
With 1.9.7 I see : [INFO] Cached authorization result: validWhat does this mean ?
I see that there are no new acme-challenge’s and see no traffic from letsencrypt.org in my server ?
It means that your previous authorization for the domain is still valid, so it’s not necessary to go through the process again, and we can skip straight to requesting the certificate. It’s a little optimization that saves a little time and prevents you from running into rate limits.
SteffenAL commented Oct 15, 2017
Darklurker commented Oct 15, 2017
Coming in from #598 , is there a way to tell LEWS that we have a valid Cert, we just need it to put it in the proper store and setup the scheduled renewal task? Kinda like the optimization you were talking about above for the authorization stage, but starting after the certificate has been received. (Maybe this is too much of an edge case to address, since normally this shouldn’t happen)
If not, I’ll test this again on Win2008/IIS on Friday when I’m out of the penalty box.
WouterTinus commented Oct 16, 2017
Unfortunately not, though re-requesting a previously issued certificate (i.e. for the same hosts) shouldn’t be hit with a rate limiting exception., as it would count as a renewal.
ThomasCr commented Oct 16, 2017 •
Hi, i have the same problem. Cert is not getting imported with letsencrypt-win-simple.v1.9.7.0-beta5.
In my letsencrypt.exe.config I have set CertificateStore to Personal (I came from letsencrypt-win-simple.V1.9.3 and from there I had set is to personal right before).
I see the error also only once, the second time the error is gone, but cert is not imported.
C:\Users\Administrator>"C:\Program Files (x86)\letsencrypt-win-simple\letsencrypt.exe" --forcerenewal --baseuri "https://acme-v01.api.letsencrypt.org/" [INFO] Let's Encrypt Windows Simple (LEWS) [INFO] Version 1.9.7.40771 (RELEASE) [INFO] ACME Server https://acme-v01.api.letsencrypt.org/ [INFO] Please report issues at https://github.com/Lone-Coder/letsencrypt-win-simple [INFO] Renewing certificate for wsus.comp.com [INFO] Authorizing wsus.comp.com using http-01 validation (FileSystem) [INFO] Answer should now be browsable at http://wsus.comp.com/.well-known/acme-challenge/6oFLH42REJY1dS6sfc9rS1yYPgLT_qnncHVr2bgQHIc [INFO] Authorization result: valid [EROR] Error encountered while opening certificate store System.Security.Cryptography.CryptographicException: Das System kann die angegebene Datei nicht finden. bei System.Security.Cryptography.X509Certificates.X509Store.Open(OpenFlags flags) bei LetsEncrypt.ACME.Simple.Services.CertificateStoreService.GetCertificate(Func`2 filter, X509Store store) [INFO] Requesting certificate wsus.comp.com 2017.10.16 5:46:13 [INFO] Saving certificate to C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org [INFO] Installing certificate in the certificate store [INFO] Installing SSL certificate in server software [WARN] Unable to run script. [INFO] Renewal for wsus.comp.com succeeded, next one scheduled for 2017.12.15 3:46:23 C:\Users\Administrator>"C:\Program Files (x86)\letsencrypt-win-simple\letsencrypt.exe" --forcerenewal --baseuri "https://acme-v01.api.letsencrypt.org/" [INFO] Let's Encrypt Windows Simple (LEWS) [INFO] Version 1.9.7.40771 (RELEASE) [INFO] ACME Server https://acme-v01.api.letsencrypt.org/ [INFO] Please report issues at https://github.com/Lone-Coder/letsencrypt-win-simple [INFO] Renewing certificate for wsus.comp.com [INFO] Cached authorization result: valid [INFO] Requesting certificate wsus.comp.com 2017.10.16 5:50:20 [INFO] Saving certificate to C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org [INFO] Installing certificate in the certificate store [INFO] Installing SSL certificate in server software [WARN] Unable to run script. [INFO] Uninstalling certificate from the certificate store [INFO] Removing certificate wsus.comp.com 2017.10.16 5:46:13 [INFO] Renewal for wsus.comp.com succeeded, next one scheduled for 2017.12.15 3:50:27
The current cert files are in %appdata%\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\
But I think, letsencrypt-win-simple should maybe check, if the import in the windows stores are well done, and if not should retry to import.
WouterTinus commented Oct 16, 2017
What makes you say the certificate is not imported? This line in the log
[INFO] Installing certificate in the certificate store
Which is not followed by any exception, point to the fact that it is (both first and second times). It could be imported to the wrong Certificate Store perhaps, but it definitely looks like its being imported somewhere. Can just run with —verbose to maybe see where it’s going?
ThomasCr commented Oct 16, 2017 •
no, it was not — not in webhosting section and not in personal section — and I was for sure in certlm.msc and refreshed the view. And there was also no cert binding in IIS set (cleared).
I runned it again, but also no import done:
C:\Users\Administrator>"C:\Program Files (x86)\letsencrypt-win-simple\letsencrypt.exe" --forcerenewal --verbose --baseuri "https://acme-v01.api.letsencrypt.org/" [DBUG] Config folder: C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org [VERB] Using registry key HKEY_CURRENT_USER\Software\letsencrypt-win-simple\https://acme-v01.api.letsencrypt.org/ [VERB] Settings Settings <> [DBUG] Loading signer from C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\Signer [DBUG] Getting AcmeServerDirectory [DBUG] Send GET request to https://acme-v01.api.letsencrypt.org/directory [DBUG] Loading registration from C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org\Registration [DBUG] Certificate folder: C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org [DBUG] Certificate store: Personal [DBUG] Renewal period: 60 [INFO] Let's Encrypt Windows Simple (LEWS) [INFO] Version 1.9.7.40771 (RELEASE) [INFO] ACME Server https://acme-v01.api.letsencrypt.org/ [INFO] Please report issues at https://github.com/Lone-Coder/letsencrypt-win-simple [VERB] Verbose mode logging enabled [VERB] Checking renewals [INFO] Renewing certificate for wsus.comp.com [DBUG] Send POST request to https://acme-v01.api.letsencrypt.org/acme/new-authz [INFO] Cached authorization result: valid [DBUG] RSAKeyBits: 4096 [INFO] Requesting certificate wsus.comp.com 2017.10.16 7:19:18 [DBUG] Send POST request to https://acme-v01.api.letsencrypt.org/acme/new-cert [INFO] Saving certificate to C:\Users\Administrator\AppData\Roaming\letsencrypt-win-simple\httpsacme-v01.api.letsencrypt.org [DBUG] Set private key exportable [INFO] Installing certificate in the certificate store [DBUG] Opened certificate store Personal [DBUG] Adding certificate wsus.comp.com 2017.10.16 7:19:18 to store [DBUG] Closing certificate store [INFO] Installing SSL certificate in server software [WARN] Unable to run script. [INFO] Uninstalling certificate from the certificate store [DBUG] Opened certificate store Personal [INFO] Removing certificate wsus.comp.com 2017.10.16 5:50:20 [DBUG] Closing certificate store [INFO] Renewal for wsus.comp.com succeeded, next one scheduled for 2017.12.15 5:19:33