Forge Home


Module to manage SSL Certificates on Windows Server 2008 and upwards


25,377 latest version

5.0 quality score

We run a couple of automated
scans to help you access a
module's quality. Each module is
given a score based on how well
the author has formatted their
code and documentation and
modules are also checked for
malware using VirusTotal.

Please note, the information below
is for guidance only and neither of
these methods should be considered
an endorsement by Puppet.

Version information

  • 4.1.0 (latest)
  • 4.0.0
  • 3.4.0
  • 3.3.0
  • 3.2.0
  • 3.1.0
  • 3.0.0
  • 2.2.0
  • 2.1.1
released Jan 14th 2020
This version is compatible with:
  • Puppet Enterprise 2019.8.x, 2019.7.x, 2019.5.x, 2019.4.x, 2019.3.x, 2019.2.x, 2019.1.x, 2019.0.x, 2018.1.x
  • Puppet >= 5.5.8 < 7.0.0
This module has been deprecated by its author since Jun 26th 2023.

Start using this module


puppet/sslcertificate — version 4.1.0 Jan 14th 2020

SSL Certificate module for Puppet

Build Status Puppet Forge Puppet Forge - downloads Puppet Forge - endorsement Puppet Forge - scores

Table of Contents

  1. Overview
  2. Module Description - What the module does and why it is useful
  3. Setup - The basics of getting started with sslcertificate
  4. Usage - Configuration options and additional functionality
  5. Reference - An under-the-hood peek at what the module is doing and how
  6. Limitations - OS compatibility, etc.
  7. Development - Guide for contributing to the module


Small defined type that will allow you to manage Windows certificates.

Module Description

A module that will allow you to install and remove your certificates on Windows machines. It will manage pfx, cer, der, p7b, sst certificates.


What sslcertificate affects

  • Installs certificates into your Windows key stores

Beginning with sslcertificate

To install a certificate in the My directory of the LocalMachine root store:

    sslcertificate { "Install-PFX-Certificate" :
      name       => 'mycert.pfx',
      password   => 'password123',
      location   => 'C:\',
      thumbprint => '07E5C1AF7F5223CB975CC29B5455642F5570798B'

To install a certificate in an alternative directory:

    sslcertificate { "Install-Intermediate-Certificate" :
      name       => 'go_daddy_intermediate.p7b',
      location   => 'C:\',
      store_dir  => 'CA',
      root_store => 'LocalMachine',
      thumbprint => '07E5C1AF7F5223CB975CC29B5455642F5570798B'

To install a certificate in the My directory of the LocalMachine root store and set the key as not exportable:

    sslcertificate { "Install-PFX-Certificate" :
      name           => 'mycert.pfx',
      password       => 'password123',
      location       => 'C:',
      thumbprint     => '07E5C1AF7F5223CB975CC29B5455642F5570798B',
      exportable  => false

For more details on the different options available with certificate management directories, see Windows Dev Center.


Classes and Defined Types

Defined Type: sslcertificate

The primary definition of the sslcertificate module. This definition will install the certificates into your keystore(s).

Parameters within sslcertificate:


The password for the given certificate


The location where the file certificate is. Do not end the string with any forward or backslash. Note that in puppet manifests, double-backslashes must be re-doubled, even in single-quoted strings, e.g.

    sslcertificate { "Install-PFX-Certificate from UNC path" :
      name       => 'mycert.pfx',
      password   => 'password123',
      location   => '\\\\StorageServer\Fileshare',
      thumbprint => '07E5C1AF7F5223CB975CC29B5455642F5570798B'

The thumbprint used to verify the certificate


The certifcate store where the certificate will be installed to


The store location for the given certification store. Either LocalMachine or CurrentUser


This parameter has been deprecated and isn't used anymore. The scripts aren't saved to disk anymore.


Flag to set the key as exportable. true == exportable; false == not exportable. By default is set to true.


Flag to set the MachineKeySet flag in import, used for importing wildcard certificates. Defaults to false


If this is set to true, any intermediate certificates included will be imported in the same store_dir, not the intermediate store. Defaults to false



Public Definition


This module is tested on the following platforms:

  • Windows 2008 R2

It is tested with the OSS version of Puppet only.



Please read for full details on contributing to this project.