How to Generate a CSR in IIS 7 and 8

CSR in IIS 7 and 8\n

This guide covers generating a CSR (Certificate Signing Request) and a private key on Windows IIS 7 or IIS 8 servers. We recommend writing down your password and backing up your key, since it cannot be restored if lost and we cannot help recover it. Keep your backup files somewhere safe.

Step 1: Generate a CSR on IIS 7/8

  1. Click Start;
  2. Select Administrative Tools;
  3. Launch Internet Services Manager;
  4. Click your server name;
  5. In the center pane, double-click Server Certificates under Security.

Step 2: Create the Certificate Request Form

  1. In the Actions pane on the right, click Create Certificate Request.

Step 3: Fill In the Certificate Request Form

  1. The Distinguished Name Properties window will open. Enter the following information:
    • Common Name: Enter the fully qualified domain name (FQDN) you intend to use the SSL certificate for. For a Wildcard SSL certificate, the Common Name must contain at least one asterisk (*). For example: *.domain.tld, *.sub.domain.tld
    • Organization: Enter your company name.
    • Organization Unit: Enter the relevant unit name (e.g., IT, Security).
    • Company location: Enter country, city and region.
  2. Click Next.

Step 4: Cryptographic Settings

  1. In the Cryptographic Service Provider Properties window, leave the settings at their defaults (Microsoft RSA SChannel and 2048 bit).
  2. Click Next.

Step 5: Save the CSR File

  1. Enter a file name and location to save the CSR file. You'll need this file when installing your IIS SSL certificate.
  2. Click Finish.
  3. The newly generated CSR will be found in Desktopcert_req.txt.

Step 6: Save the Private Key (Optional)

  1. In the MMC snap-in, go to the Certificates section;
  2. Select Requests;
  3. Hover over All Tasks;
  4. Click Export.

Tips:

  • When generating a CSR, make sure to include the -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST----- lines. Certificate generation cannot complete without them.

Can't find the answer you need?

Contact Us