IdenTrust Inc. Logo
Home | Login | Contact Us  

  
OVERVIEW DIGITAL CERTIFICATE INSTRUCTIONS FAQ LIBRARY HOW-TO DOWNLOADS
Microsoft Internet Information Server (IIS) 5

Support > Generation Instructions


Creating a Certificate Signing Request (CSR) and Key

Follow the step-by-step instructions to generate a certificate signing request (CSR) and key:

  1. Select the Internet Information Services console within the Administrative Tools menu.
  2. Select the computer and web site (host) that you wish to secure. Right mouse-click to select Properties.
  3. Select the Directory Security tab.
  4. Select Server Certificate under Secure Communications
  5. Click Next in the Welcome to the Web Server Certificate Wizard window.
  6. Select Create a new certificate, Click Next.
  7. Select Prepare the request now, but send it later.
  8. At the Name and Security Settings screen, fill in the [friendly] name field for the new certificate. Select bit length. We recommend using 1024-bit length. Click Next.
  9. When creating a CSR you must follow these conventions.
    Enter the Distinguished Name Field information.
    Note: The following characters can not be accepted:
    < > ~ ! @ # $ % ^ * / \ ( ) ?

    Distinguished
    Name Field
    Explanation Example
    Common Name The fully qualified domain name for your web server. This must be an exact match. If you intend to secure the URL https://www.identrust.com/, then your CSR's common name must be www.identrust.com
    Organization Name The exact legal name of your organization. Do not abbreviate your organization name. IdenTrust Inc.
    Organization Unit Section of the organization Marketing
    City or Locality The city where your organization is legally located. Salt Lake City
    State or Province Name The state or province where your organization is legally located. Can not be abbreviated. Utah
    Country Name The two-letter ISO abbreviation for your country US = United States
  10. Enter your Administrator contact information.
  11. Enter a path and file name for the CSR.
  12. Verify your request and then click Next.
  13. At the Completing the Web Server screen, select Finish.
    DO NOT REMOVE the pending request or the .crt file will not match and your certificate will not install.
  14. Send the entire certificate request to IdenTrust, including ----BEGIN CERTIFICATE REQUEST---- and ----END CERTIFICATE REQUEST----

    Note: Remember to back up your key pair file.

Backing up your key pair file

Creating your Snap-in Management Console

Certificate Snap-in consoles (MMC) are not preconfigured. You will need to preconfigure your Snap-in consoles in order to perform any Export/Import functionality. To preconfigure your Snap-in consoles, follow the steps below: The system administrator will have to create the console.

  1. Go to Start. Select Run. Type mmc and click OK. This will bring up a empty console with no management functionality.
  2. Click Add/Remove Snap-in on the Console menu.
  3. The Snap-ins added to box will list only the Console Root. Click Add.
  4. Click Certificates Snap-in and then click Add.
  5. Select Computer Account.
  6. Click on Finish.
  7. Click Close.
  8. Click on OK.

Managing your certificates

  1. Go to the Microsoft Management Console (MMC) for Snap-in Certificates.
  2. Select the folders Console Root\Certificates(Local Computer)\Personal\Certificates.
  3. Right click on the certificate to export.
  4. Go to the Action menu.
  5. Select All Tasks and Export.
  6. The Welcome to the Certificate Manager Import Wizard window opens. Click Next.
  7. Select Yes, export the private key. Click Next.
  8. Make sure the Personal Information Exchange- PKCS # 12(.PFX) box is selected.
    Warning: Make sure that the "Delete the private key if the export is successful" is NOT checked.
  9. Check the box Enable strong protection (requires IE5.0, NT4.0 SP4 or above. Select Next.
  10. Type and confirm your export password.
    Warning: If you lose the password, you must purchase another certificate.
  11. Save the file to a disk or other form of media. You should choose a from of media that you will be able to recover if your system has to be rebuilt. Save this file in a secure location as a pfx extension.
  12. Select Finish.

Back to Listing



RELATED CONTENT
Certificate Management Center
FAQ: Before You Buy
HOW-TO: Backup a Certificate
HOW-TO: Replace a Certificate
FAQ: General
FAQ: ACES
FAQ: ECA
FAQ: State of Washington
PKI Basics
Certificate Security and Protection
Change Control Schedules
Support Main
Contact Support
 

FEDERAL AGENCY PROGRAMS
Department of State
D-Trade
Department of Labor
Department of Labor
Department of Treasury IRS
Secure Data Transfer
MeF Electronic Filing Certificate
General Services Administration
eOffer

STATE AGENCY PROGRAMS
Florida
JCalendar for State Court Systems
West Virginia
Department of Environmental Protection
Virginia
Department of Transportation (VDOT)
Department of Mines Minerals and Energy (DMME)
 © 2008 IdenTrust Inc. All Rights Reserved    Home | Contact Us | Legal Policies IdenTrust