{"id":28,"date":"2026-03-22T11:10:00","date_gmt":"2026-03-22T11:10:00","guid":{"rendered":"https:\/\/overlaps.co.uk\/docs\/?page_id=28"},"modified":"2026-03-31T13:28:36","modified_gmt":"2026-03-31T12:28:36","slug":"first-configuration","status":"publish","type":"page","link":"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/installation-and-configuration\/first-configuration\/","title":{"rendered":"First Configuration"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This page will guide you through the very first steps you must take with a fresh install of OVERLAPS.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"adding-the-first-administrators\">Adding the First Administrators<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before you can login the first time, you must first add yourself as an Administrator user.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"adding-an-administrator-from-the-configuration-utility\">Adding an Administrator from the Configuration Utility<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"707\" height=\"539\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_users_and_groups.png\" alt=\"Adding an Administrator from the Configuration Utility\" class=\"wp-image-128\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_users_and_groups.png 707w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_users_and_groups-300x229.png 300w\" sizes=\"auto, (max-width: 707px) 100vw, 707px\" \/><figcaption class=\"wp-element-caption\">Adding an Administrator from the Configuration Utility<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To add an Administrator from the Configuration Utility, navigate to the Users and Groups tab, then:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Click <strong>New<\/strong><\/li>\n\n\n\n<li>Enter the <strong>domain and username<\/strong> of the user<\/li>\n\n\n\n<li>Check the <strong>Administrator<\/strong> box<\/li>\n\n\n\n<li>Click <strong>Save Changes<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The user should now appear in the list on the left of the window with a check under the &#8220;Admin&#8221; column.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"adding-an-administrator-from-olconfigexe\">Adding an Administrator from OLconfig.exe<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"303\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add.png\" alt=\"olconfig.exe user \/help\" class=\"wp-image-139\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add-300x151.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">olconfig.exe user \/help<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To add an administrator from the command line you can use the olconfig.exe tool as shown below. (substituting \u201c&lt;myusername&gt;\u201d for the user&#8217;s Active Directory login name).<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe user &lt;myusername> \/add \/admin\n<\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"87\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add_success.png\" alt=\"User added from olconfig.exe\" class=\"wp-image-140\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add_success.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/config_cli_users_add_success-300x43.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">User added from olconfig.exe<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"configuring-https-connection-encryption\">Configuring HTTPS Connection Encryption<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To further increase security to OVERLAPS, it is recommended that you install an SSL\/TLS certificate so that traffic between the server and a client is encrypted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This is particularly critical if you are intending to use the Login Form<\/strong> (as opposed to Windows Integrated Authentication), because anything entered in the form (username and password) is sent unencrypted to the server without an SSL\/TLS certificate, making it vulnerable to network sniffing attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certificates can be obtained from third-party Trusted Authorities (such as Thawte, Comodo SSL, or Let\u2019s Encrypt). They can also be created from your own root certificate or created as standalone self-signed certificates (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/additional-tools\/self-signed-certificate-generator\/\">Self-Signed Certificate Generator<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Throughout this documentation we will refer to <strong>Certificate Binding<\/strong>. This is the process and status of having an SSL\/TLS certificate mapped to a particular address on the server, for example its IP address, or a DNS identity such as &#8220;<em>overlaps.contoso.com<\/em>&#8220;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For information on how to create a properly-formed self-signed certificate, see our <a href=\"https:\/\/int64software.com\/blog\/2020\/04\/20\/creating-a-self-signed-ssl-certificate-for-your-intranet-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">guide here<\/a>, or use the included <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/additional-tools\/self-signed-certificate-generator\/\">Self-Signed Certificate Generator<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you have your certificate files (a private key for the server (.pfx or .p12), and a public key for distribution to client devices), you can install and configure encryption using either of the configuration tools, or manually using the Windows \u201cnetsh\u201d command. Each of these approaches are detailed below, but we recommend using the Configuration Utility.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-https-using-the-configuration-utility\">Configuring HTTPS using the Configuration Utility<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"714\" height=\"546\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https.png\" alt=\"Configuring HTTPS using the Configuration Utility\" class=\"wp-image-130\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https.png 714w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https-300x229.png 300w\" sizes=\"auto, (max-width: 714px) 100vw, 714px\" \/><figcaption class=\"wp-element-caption\">Configuring HTTPS using the Configuration Utility<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The list of HTTPS Certificate Bindings will be automatically populated with any discovered on the server (only those related to OVERLAPS will be shown).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some older versions of OVERLAPS used an alternative GUID to label their certificate bindings. If you cannot see your bindings in this list, try checking the \u201cShow Legacy Bindings\u201d option.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"adding-a-new-binding\">Adding a New Binding<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To start adding a new binding, click the \u201c<strong>Add a New Binding<\/strong>\u201d button.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"338\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_add_binding.png\" alt=\"Adding a New Certificate Binding\" class=\"wp-image-141\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_add_binding.png 569w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_add_binding-300x178.png 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><figcaption class=\"wp-element-caption\">Adding a New Certificate Binding<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you have already loaded a certificate this session, it is cached and will appear in the dropdown list so that you don\u2019t have to load it again for each binding. Otherwise, click the \u201c<strong>Browse<\/strong>\u201d button to locate and load your private key file (*.pfx).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the certificate is secured with a password (which private keys normally are), you will be asked to enter it. Then you will be asked to identify the type of certificate.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"455\" height=\"228\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_certificate_type.png\" alt=\"Identifying the Certificate Type\" class=\"wp-image-142\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_certificate_type.png 455w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_certificate_type-300x150.png 300w\" sizes=\"auto, (max-width: 455px) 100vw, 455px\" \/><figcaption class=\"wp-element-caption\">Identifying the Certificate Type<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The Configuration Utility will attempt to automatically determine this, but please check that the selected value is correct.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Full Chain Certificate<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select this option if the certificate was generated by a Trusted Root Authority. This can be a third-party authority (e.g. Thawte, Comodo SSL, or Lets Encrypt), or your own company root certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Self-Signed Certificate<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Choose this option if the certificate was generated without the involvement of a trusted root authority, such as if it was generated in IIS, OpenSSL, or our own Self-Signed Certificate Generator.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"339\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_select_binding.png\" alt=\"Certificate Loaded, Configure the Binding\" class=\"wp-image-143\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_select_binding.png 571w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_select_binding-300x178.png 300w\" sizes=\"auto, (max-width: 571px) 100vw, 571px\" \/><figcaption class=\"wp-element-caption\">Certificate Loaded, Configure the Binding<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Once the certificate has been loaded or selected, select the target to bind it to (IP Address or DNS Hostname\/alias) and either select the desired value from the dropdown list or enter your own.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The port will be automatically set to the HTTPS port configured in OVERLAPS and should not be changed here. If you need to use a different port, consider configuring that in the Host tab first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once done, click \u201c<strong>Create Binding<\/strong>\u201d to finish the process. If everything is correct, the binding will now appear in the bindings list.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"86\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bindings.png\" alt=\"Certificate Binding List\" class=\"wp-image-144\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bindings.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bindings-300x43.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">Certificate Binding List<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If your certificate is self-signed you will need to distribute the public key part (typically a .cer or .der file) to the Trusted Root Certification Authorities store on any client computer which will be logging into OVERLAPS. This can be done using Group Policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Never distribute your private key (.pfx or .p12 file).<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"deleting-an-existing-binding\">Deleting an Existing Binding<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To delete an existing binding, select it in the list and click the \u201c<strong>Delete Selected Binding<\/strong>\u201d button.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"enabling-or-disabling-https-in-overlaps\">Enabling or Disabling HTTPS in OVERLAPS<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Once a certificate binding has been setup you can tell OVERLAPS to start processing secure requests by clicking the \u201c<strong>Enable OVERLAPS HTTPS<\/strong>\u201d button. If this reads \u201c<strong>Disable OVERLAPS HTTPS<\/strong>\u201d instead, then OVERLAPS is already configured to listen for HTTPS requests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-https-using-the-configuration-utility-legacy-https-mode\">Configuring HTTPS using the Configuration Utility Legacy HTTPS Mode<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The OVERLAPS HTTPS configuration section was overhauled to provide greater control and clarity when setting it up. However, if you would prefer to go back to the legacy certificate binding tab, click the \u201c<strong>Show Legacy HTTPS Configuration Tab<\/strong>\u201d button on the Introduction tab.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"459\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_legacy.png\" alt=\"Configuring HTTPS using the Configuration Utility Legacy tab\" class=\"wp-image-145\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_legacy.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_legacy-300x229.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">Configuring HTTPS using the Configuration Utility Legacy tab<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To install the certificate, click browse and locate the .pfx or .p12 certificate file (your private key), and enter the password if required. Then select the correct Certificate Type for the certificate file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Certificate Type<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the type of certificate (third-party or self-signed), select the Certificate Type from the dropdown. This will effect which Certificate Store it is saved into.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you find that the process succeeded, but your HTTPS connection keeps failing after hours or days, try unbinding it, changing this value and then re-binding it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have a certificate created from your own internal root certificate then select the option appropriate to that root certificate instead.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click <strong>Load Certificate<\/strong>. The Configuration Utility will attempt to load the certificate file and display its information for you to confirm.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once loaded, you can then specify the hostname(s), IP address and HTTPS port of your server that you want to bind the certificate to, then click <strong>Bind Certificate to OVERLAPS<\/strong> to import and bind the certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If everything works as expected, you can then click the <strong>Enable OVERLAPS HTTPS<\/strong> button to set OVERLAPS to host encrypted content.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"wildcard-certificates-eg-contosocom\">Wildcard Certificates (e.g. *.contoso.com)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Wildcard certificates are supported by OVERLAPS, but when specifying the hostname to bind, enter the actual URL of overlaps (e.g. overlaps.contoso.com) and the wildcard, separating the two with a semicolon. For example:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"38\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bind_to_hostname.png\" alt=\"Binding a wildcard certificate\" class=\"wp-image-146\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bind_to_hostname.png 602w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_https_bind_to_hostname-300x19.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><figcaption class=\"wp-element-caption\">Binding a wildcard certificate<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-https-using-olconfigexe\">Configuring HTTPS using olconfig.exe<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can install and configure HTTPS encryption using the olconfig.exe tool in one of two ways:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"installing-from-the-certificate-file\">Installing from the certificate file<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If you have the certificate file available, you would use the \u201chttps \/certfile\u201d command, specifying the certificate filename and password (if needed):<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe https \/certfile &lt;filename.pfx> [\/password &lt;password>] \/ipaddress &lt;ip address> \/port 443\nor\nolconfig.exe https \/certfile &lt;filename.pfx> [\/password &lt;password>] \/hostname &lt;address> \/port 443\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe https \/certfile mycertificate.pfx \/password SuperSecurePass1 \/ipaddress 0.0.0.0 \/port 443\nolconfig.exe https \/certfile mycertificate.pfx \/password SuperSecurePass1 \/hostname overlaps.contoso.com \/port 443\n<\/pre>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"installing-from-a-certificate-already-in-your-servers-certificate-store\">Installing from a certificate already in your server\u2019s Certificate Store<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If you have already installed the certificate into your server\u2019s certificate store, you can instead use olconfig.exe using the certificate\u2019s thumbprint to identify it:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe https \/thumbprint &lt;certificate thumbprint> \/hostname &lt;address> \/port 443\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe https \/thumbprint {BECDF484-E0C1-4B5D-A326-01C0A93B62AB} \/hostname overlaps.contoso.com \/port 443\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">When importing your certificate manually it is important that it is installed in the correct Certificate Store:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Third-Party certificates should be installed in the <strong>Current Computer \u2013 Trusted Root Certification Authorities<\/strong> store.<\/li>\n\n\n\n<li>Self-Signed certificates should be installed into the <strong>Current Computer &#8211; Personal<\/strong> certificate store.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"error-1312\">Error 1312<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">An Error 1312 message is not uncommon here and can happen due to a number of reasons in the underlying Windows HTTP API code. Typically it means that when the certificate was imported, it wasn\u2019t marked to be persisted in the server\u2019s certificate cache. If this problem persists, try removing the certificate and re-installing it, or configuring manually using the \u201cnetsh\u201d command (see below).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-https-manually\">Configuring HTTPS manually<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To configure HTTPS manually, first install your certificate file to the appropriate certificate store (see online for instruction on doing this). This will be the <strong>Current Computer \u2013 Trusted Root Certification Authorities<\/strong> store for third-party certificates (e.g. Thawte, Comodo SSL or Let&#8217;s Encrypt), or the <strong>Current Computer \u2013 Personal<\/strong> store for self-signed certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the certificate is installed, you can bind it to the OVERLAPS service by using the netsh command line utility as shown below:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"bind-to-an-ip-address-and-port\">Bind to an IP Address and Port<\/h4>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">netsh http add sslcert ipport=&lt;ip address>:443 certhash=&lt;thumbprint of your certificate> appid={4e893f69-206d-49e3-af7e-5813a2cf0281}\n<\/pre>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"bind-to-a-hostname-and-port\">Bind to a Hostname and Port<\/h4>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">netsh http add sslcert hostnameport=&lt;servername>:443 certhash=&lt;thumbprint of your certificate> appid={4e893f69-206d-49e3-af7e-5813a2cf0281} certstorename=&lt;store>\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Where \u201c<strong>&lt;store&gt;<\/strong>\u201d will be either \u201c<strong>MY<\/strong>\u201d for the Personal store, or \u201c<strong>Root<\/strong>\u201d for the Trusted Root Certification Authorities store.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You should receive the message \u201c<strong>SSL Certificate successfully added<\/strong>\u201d. If, however, you receive the message \u201c<strong>A specified logon session does not exist<\/strong>\u201d, then the certificate could be installed in the wrong store, check that it is in the correct one before trying again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"enabling-https-in-overlaps\">Enabling HTTPS in OVERLAPS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you are not using the Configuration Utility, then once HTTPS is configured you will need to enable HTTPS in OVERLAPS from the Configuration page (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/host-settings\/#communication-security\">Communication Security<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"unencrypted-http-once-https-is-enabled\">Unencrypted HTTP once HTTPS is enabled<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In previous versions it was recommended to then disable the unencrypted HTTP port. However, any attempt to access the HTTP port when HTTPS is enabled will be automatically redirected to the encrypted port, so it is safe to leave HTTP connections enabled.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"troubleshooting-https\">Troubleshooting HTTPS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There have been reports of HTTPS working initially when bound using the instructions above, but then failing again after a few hours and producing errors on client browsers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This typically comes down to one of the following problems:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"certificates-getting-removed-from-their-store\">Certificates getting removed from their store<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft\u2019s CryptoAPI v2 is responsible for automatically removing certificates from the certificate store, and sometimes it has been known to remove your own trusted certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can check if this is happening by looking for event code 4108 in your Windows Event Log.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If installing the certificate using the Configuration Utility, make sure you are selecting the correct Certificate Type setting as this will attempt to put it into the correct store. If installing manually, make sure that self-signed certificates are installed into the computer\u2019s Personal store, and third-party certificates are installed into the Third-Party Root Certification Authorities store.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"wildcard-certificates\">Wildcard Certificates<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Wildcard certificates (e.g. *.contoso.com) need to be bound using their wildcard as well. For more information, see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/installation-and-configuration\/first-configuration\/#wildcard-certificates-eg-contosocom\">Wildcard Certificates (e.g. *.contoso.com)<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"mismatching-issued-to-or-subject-alternative-name-san\">Mismatching &#8220;Issued To&#8221; or Subject Alternative Name (SAN)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The client browser will examine the site\u2019s certificate to make sure that the URL you are visiting matches the address the certificate was created for. It does this by checking the URL against the certificate&#8217;s Common Name (CN) and Subject Alternative Name (SAN) properties, and if it doesn&#8217;t find the URL in either of these then it may reject the certificate. Note that, as per RFC 6125, the validation process will check the SAN first and, if it exists, it will ignore the CN property.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"configuring-kerberos\">Configuring Kerberos<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By default, the OVERLAPS http server will use NTLM when a user selects the option to login with Windows Integrated Authentication (or if this is enforced). While this is fine for most cases, NTLM has been shown to be vulnerable to certain Man-In-The-Middle attacks, so Kerberos is preferred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note that even when configured, Kerberos will only be used when the client computer is also a member of your Active Directory domain, or when a DNS name is configured for the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To configure Kerberos, you must define a Service Principal Name (SPN) for the server. You can do this in one of two ways: automatically using the either of the configuration tools included with OVERLAPS, or manually using the \u201csetspn.exe\u201d tool provided by Microsoft with Windows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-kerberos-using-the-configuration-utility\">Configuring Kerberos using the Configuration Utility<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"711\" height=\"544\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_kerberos.png\" alt=\"Configuring Kerberos in the Configuration Utility\" class=\"wp-image-131\" srcset=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_kerberos.png 711w, https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/configuration_utility_kerberos-300x230.png 300w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><figcaption class=\"wp-element-caption\">Configuring Kerberos in the Configuration Utility<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can create an SPN to enable Kerberos using the Configuration Utility by checking the Host Name and Service Account fields are correct:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"host-nameaddress\">Host Name\/Address<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The server name or address used to access OVERLAPS (e.g. overlaps.mydomain.com).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"service-account\">Service Account<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The account that the OVERLAPS service is running as. This is the server\u2019s Local System account (NT AUTHORITY\\SYSTEM) by default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click the <strong>Refresh<\/strong> button to check the Kerberos configuration for these values.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If Kerberos shows as disabled for either HTTP or HTTPS, you may then click the <strong>Enable Kerberos<\/strong> button under HTTP or HTTPS sections to enable Kerberos over the respective connection. Note that the HTTPS section will not be enabled if connection encryption has not yet been setup.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-kerberos-using-olconfigexe\">Configuring Kerberos using olconfig.exe<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enabling Kerberos support using the olconfig.exe tool can be achieved very simply with one of the following commands depending on whether you are using HTTP, HTTPS or both HTTP and HTTPS (recommended).<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe security \/enablekrb http\nolconfig.exe security \/enablekrb https\nolconfig.exe security \/enablekrb both\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to this, you can specify these optional parameters:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Parameter<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>\/url &lt;hostname\/address&gt;<\/td><td>The address of the server (defaults to the hostname)<\/td><\/tr><tr><td>\/account &lt;account&gt;<\/td><td>The service account OVERLAPS runs as (defaults to SYSTEM)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To check the current Kerberos status, you can use the command line:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">olconfig.exe security \/krbstatus\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Please be aware that this works by calling SetSPN.exe with the correct parameters already filled out for you. If you encounter any problems, please consult the SetSPN documentation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"configuring-kerberos-manually\">Configuring Kerberos manually<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Alternatively, to register an SPN manually, use the command line:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">SetSPN \u2013a HTTP(S)\/&lt;servername> &lt;machineaccount>$\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">So, for example if our server was called \u201coverlaps\u201d, and we wanted to configure both HTTP and HTTPS to support Kerberos we would use the command lines:<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">SetSPN \u2013a HTTP\/OVERLAPS OVERLAPS$\nSetSPN \u2013a HTTPS\/OVERLAPS OVERLAPS$\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For more information on configuring Service Principal Names manually, please refer to Microsoft documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This page will guide you through the very first steps you must take with a fresh install of OVERLAPS. Adding the First Administrators Before you can login the first time, you must first add yourself as an Administrator user. Adding an Administrator from the Configuration Utility To add an Administrator from the Configuration Utility, navigate [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":20,"menu_order":300,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-28","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/comments?post=28"}],"version-history":[{"count":2,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/28\/revisions"}],"predecessor-version":[{"id":147,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/28\/revisions\/147"}],"up":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/20"}],"wp:attachment":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/media?parent=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}