{"id":313294,"date":"2025-07-06T23:55:15","date_gmt":"2025-07-06T21:55:15","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=313294"},"modified":"2025-07-07T02:21:19","modified_gmt":"2025-07-07T00:21:19","slug":"connectwise-screenconnect-zertifikate-werden-zurueckgezogen","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2025\/07\/06\/connectwise-screenconnect-zertifikate-werden-zurueckgezogen\/","title":{"rendered":"ConnectWise Screenconnect: Zertifikate werden zur\u00fcckgezogen (7.7.2025)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Stop - Pixabay\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Stop01.jpg\" alt=\"Stop - Pixabay\" align=\"left\" \/>Jemand aus der Leserschaft der ConnectWise Screenconnect als Fernwartungssoftware einsetzt? Der Anbieter zieht bei der Fernwartungsl\u00f6sung Screenconnect gerade die die Code-Signing-Zertifikate f\u00fcr die Agenten auf den Clients zur\u00fcck. Was bleibt, wenn man Screenconnect einsetzen will? Man kann entweder eigene kostspielige Code-Signing-Zertifikate erwerben oder zur Cloud-L\u00f6sung des Anbieters wechseln. Ansonsten ist ab dem heutigen Montag (7.7.2025) Schluss mit Fernwartung.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/2b761054de07407ab7194b9aac0a2a8a\" alt=\"\" width=\"1\" height=\"1\" \/>Das Ganze ist ziemlich an mir vorbei gegangen. Aber Leser Heinz hat mir zum 4. Juni 2025 per Mail kurz informiert (er hatte mich seinerzeit auch \u00fcber die im Beitrag\u00a0<a href=\"https:\/\/borncity.com\/blog\/2025\/06\/09\/connectwise-screenconnect-dringend-vor-dem-10-juni-2025-updaten\/\">ConnectWise aktualisiert Server-Zertifikate, Software vor dem 13. Juni 2025 aktualisieren<\/a> beschriebene Aktualisierung der Server-Zertifikate informiert.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i.postimg.cc\/zXF39VRR\/image.png\" alt=\"ConnectWise Screenconnect certificates\" width=\"640\" height=\"455\" \/><\/p>\n<p>Auf reddit.com bin ich auf obigen Thread\u00a0<a href=\"https:\/\/www.reddit.com\/r\/ConnectWise\/comments\/1lordhl\/screenconnect_cert_expiring_again\/\" target=\"_blank\" rel=\"noopener\">ScreenConnect cert expiring again?<\/a> gesto\u00dfen. Wer Lizenzen hat, sollte zum 1. Juli 2025 ggf. per E-Mail informiert worden sein. Auf reddit.com hat jemand in <a href=\"https:\/\/www.reddit.com\/r\/ScreenConnect\/comments\/1loraav\/update_certificate_changes_for_screenconnect\/\" target=\"_blank\" rel=\"noopener\">diesem Thread<\/a> die Mail ver\u00f6ffentlicht &#8211; ich habe die Informationen hier am Artikelende angeh\u00e4ngt. Passt nat\u00fcrlich super, da am 4. Juli 2025 in den USA Feiertag war. ConnectWise hat zum 5. Juni 2025 <a href=\"https:\/\/docs.connectwise.com\/ConnectWise_Unified_Product\/Information_and_Supportability_Statements\/ScreenConnect_Digital_Certifications\" target=\"_blank\" rel=\"noopener\">diesen Supportbeitrag<\/a> mit weiteren Details ver\u00f6ffentlicht.<\/p>\n<p>Heinz merkte dazu an: \"Da Cloud bei Fernwartung f\u00fcr uns ein absolutes NoGo ist wechseln wir dieses Wochenende im \u201eHauruck\" Verfahren zu <a href=\"https:\/\/docs.tacticalrmm.com\/\" target=\"_blank\" rel=\"noopener\">Tactical Remote Management<\/a>. Die haben bei Connectwise den Vertrag gek\u00fcndigt. Laut Leser kocht diese gesamte Geschichte im reddit- und im screenconnect-Forum von Connectwise hoch. Die Ma\u00dfnahme ist m\u00f6glicherweise das Ergebnis eines Cyberangriffs (siehe <a href=\"https:\/\/borncity.com\/blog\/2024\/02\/23\/connectwise-screenconnect-server-durch-lockbit-angegriffen\/\" rel=\"bookmark\">ConnectWise ScreenConnect-Server durch LockBit angegriffen<\/a>).<\/p>\n<p><strong>\u00c4hnliche Artikel:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2024\/02\/21\/kritische-schwachstelle-in-connectwise-remote-software-screenconnect-feb-2024\/\" rel=\"bookmark\">Kritische Schwachstelle in ConnectWise-Remote-Software ScreenConnect (Feb. 2024)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2024\/02\/23\/connectwise-screenconnect-server-durch-lockbit-angegriffen\/\" rel=\"bookmark\">ConnectWise ScreenConnect-Server durch LockBit angegriffen<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2025\/04\/25\/important-security-update-fuer-connect-wise-screenconnect\/\" rel=\"bookmark\">Important Security Update f\u00fcr Connect Wise ScreenConnect bis v25.2.3<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/blog\/2025\/06\/09\/connectwise-screenconnect-dringend-vor-dem-10-juni-2025-updaten\/\" rel=\"bookmark\">ConnectWise aktualisiert Server-Zertifikate, Software vor dem 13. Juni 2025 aktualisieren<\/a><\/p>\n<hr \/>\n<div class=\"flex\">\n<div class=\"flex flex-col grow max-w-full\">\n<h2 id=\"post-title-t3_1loraav\" class=\"text-neutral-content-strong m-0 font-semibold text-18 xs:text-24 mb-xs px-md xs:px-0 xs:mb-md overflow-hidden\" aria-label=\"Beitragstitel: Update: &quot;Certificate Changes for ScreenConnect On-Prem.&quot;\" aria-describedby=\"feed-post-credit-bar-t3_1loraav\">Update: \"Certificate Changes for ScreenConnect On-Prem.\"<\/h2>\n<div class=\"w-fit m-0 border-0 bg-transparent cursor-pointer relative\"><span style=\"font-size: 16px;\">[<a href=\"https:\/\/www.reddit.com\/r\/ScreenConnect\/comments\/1loraav\/update_certificate_changes_for_screenconnect\/\" target=\"_blank\" rel=\"noopener\">Email received July 1, 2025 UTC 03:00.<\/a>]<\/span><\/div>\n<\/div>\n<\/div>\n<div class=\"text-neutral-content\">\n<div class=\"mb-sm mb-xs px-md xs:px-0 overflow-hidden\" data-post-click-location=\"text-body\">\n<div id=\"t3_1loraav-post-rtjson-content\" class=\"md text-14-scalable\">\n<p>Dear Partner,<\/p>\n<p>As part of our commitment to platform trust and product integrity, we're making important changes to how digital certificates are handled for ScreenConnect on-premises deployments.<\/p>\n<p><strong>What's Changing and Why<\/strong><br \/>\nTo facilitate the personalization of the install package, we have historically allowed partners to make changes to certain parameters of the ScreenConnect install. These same capabilities were flagged by a researcher as a potential for misuse, and the current certificate will stop working on\u00a0<strong>Monday, July 7, 2025, at 12:00 p.m. ET (16:00 UTC)<\/strong>.<\/p>\n<p>To prevent further possibilities of misuse by threat actors, we have taken two steps:<\/p>\n<ol>\n<li>We have removed any personalization capability from the install packages. This prevents threat actors from using these features for malicious purposes.<\/li>\n<li>To further protect the validity of the installer, we are no longer signing the installer for the on-premises versions of ScreenConnect with the common certificate from ConnectWise. We are asking each on-premises partner who wishes to stay with their own hosted instance of ScreenConnect to sign the installer with their own certificate. Not only does this provide a higher level of security and assurance for each partner, but it also ensures that install packages are not reused outside your organization.<\/li>\n<\/ol>\n<p><strong>What You Need to Do<\/strong><br \/>\nBeginning with the next ScreenConnect build (available July 1), all on-premises partners will be required to provide a\u00a0<strong>publicly trusted certificate<\/strong>\u00a0to sign guest clients. The product will no longer ship with pre-signed clients. The release also includes one-click installation improvements to streamline the guest experience when joining a Support session.<\/p>\n<p>You may obtain a certificate from a public certificate authority (CA) of your choice. Guidance on how to apply your certificate and complete the signing process will be provided with the release.<\/p>\n<p>Please note that clients that are not properly signed with a trusted certificate may be flagged by endpoint protection software and could cause installation issues.<\/p>\n<p><strong>Optional: Move to Cloud<\/strong><br \/>\nIf managing certificates on-premises is not ideal for your environment, you may migrate to ScreenConnect Cloud, where ConnectWise signs client binaries on your behalf. A promotional offer to support this transition will be available shortly.<\/p>\n<p><strong>Support<\/strong><br \/>\nLive Support Chat is available for technical assistance for active maintenance subscribers. If you have questions or concerns, please contact our support team via\u00a0<a class=\"relative pointer-events-auto a cursor-pointer underline \" href=\"https:\/\/m.connectwise.com\/NDE3LUhXWS04MjYAAAGbYuZeoji9TKIcxCfiz2HEBqqgLLiykbdyf1eNT7JZImIrF57lg4cfGfuPMhsv0W09KtZfKGw=\" target=\"_blank\" rel=\"noopener nofollow ugc\">live support chat<\/a>. You can also join our Partner Town Hall on Wednesday, July 2, at 12:00 p.m. ET (16:00 UTC) to review these changes and ask questions.\u00a0<a class=\"relative pointer-events-auto a cursor-pointer underline \" href=\"https:\/\/m.connectwise.com\/NDE3LUhXWS04MjYAAAGbYuZeohjVbn4JpFtStqNdLI__5NkmDvznt-fnGbRRJAKwBApjtrOrjKt_Hea7c2nA3W-JEOk=\" target=\"_blank\" rel=\"noopener nofollow ugc\">Register here<\/a>.<\/p>\n<p>The landscape for remote access software has changed. As threat actors adopt more sophisticated techniques, maintaining trust requires stronger, more transparent security standards. These changes reflect our commitment to helping partners stay protected and ahead of evolving risks.<\/p>\n<p>As always, we appreciate your continued partnership.<\/p>\n<p>Sincerely,<br \/>\nConnectWise<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jemand aus der Leserschaft der ConnectWise Screenconnect als Fernwartungssoftware einsetzt? Der Anbieter zieht bei der Fernwartungsl\u00f6sung Screenconnect gerade die die Code-Signing-Zertifikate f\u00fcr die Agenten auf den Clients zur\u00fcck. Was bleibt, wenn man Screenconnect einsetzen will? Man kann entweder eigene kostspielige &hellip; <a href=\"https:\/\/borncity.com\/blog\/2025\/07\/06\/connectwise-screenconnect-zertifikate-werden-zurueckgezogen\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,7459],"tags":[4328,3836],"class_list":["post-313294","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-software","tag-sicherheit","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/313294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=313294"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/313294\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=313294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=313294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=313294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}