CSR in IIS 7 and 8\n
This guide covers generating a CSR (Certificate Signing Request) and a private key on Windows IIS 7 or IIS 8 servers. We recommend writing down your password and backing up your key, since it cannot be restored if lost and we cannot help recover it. Keep your backup files somewhere safe.
Step 1: Generate a CSR on IIS 7/8
- Click Start;
- Select Administrative Tools;
- Launch Internet Services Manager;
- Click your server name;
- In the center pane, double-click Server Certificates under Security.
Step 2: Create the Certificate Request Form
- In the Actions pane on the right, click Create Certificate Request.
Step 3: Fill In the Certificate Request Form
- The Distinguished Name Properties window will open. Enter the following information:
- Common Name: Enter the fully qualified domain name (FQDN) you intend to use the SSL certificate for. For a Wildcard SSL certificate, the Common Name must contain at least one asterisk (*). For example:
*.domain.tld,*.sub.domain.tld - Organization: Enter your company name.
- Organization Unit: Enter the relevant unit name (e.g., IT, Security).
- Company location: Enter country, city and region.
- Common Name: Enter the fully qualified domain name (FQDN) you intend to use the SSL certificate for. For a Wildcard SSL certificate, the Common Name must contain at least one asterisk (*). For example:
- Click Next.
Step 4: Cryptographic Settings
- In the Cryptographic Service Provider Properties window, leave the settings at their defaults (Microsoft RSA SChannel and 2048 bit).
- Click Next.
Step 5: Save the CSR File
- Enter a file name and location to save the CSR file. You'll need this file when installing your IIS SSL certificate.
- Click Finish.
- The newly generated CSR will be found in Desktopcert_req.txt.
Step 6: Save the Private Key (Optional)
- In the MMC snap-in, go to the Certificates section;
- Select Requests;
- Hover over All Tasks;
- Click Export.
Tips:
- When generating a CSR, make sure to include the -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST----- lines. Certificate generation cannot complete without them.
Can't find the answer you need?
Contact Us