Entrust Certificate Services Support Knowledge BaseLast Modified: 2016-09-07 15:42:26.0
How to generate a CSR using Microsoft IIS 8/8.5
Article Number: 44829
How do I generate a CSR using Microsoft IIS 8/8.5?
1. Launch the Server Manager
- From within the Server Manager at the top left corner Select: Tools | Internet Information Services (IIS) Manager
2. From the right hand side under "Connections" select the workstations name
- Once the name is selected, look to the center of the screen and locate "Server Certificates" once selected double click
3. Once in the "Server Certificates" to the upper right hand side under "Actions" select: Create Certificate Request...
- Please Note: If you are renewing the Certificate you always select "Create Certificate Request..." If you choose the renew option, you will produce a CSR that is not supported by Public CA's
- Choosing the option to create a new CSR when renewing the certificate will not effect the current certificate in any way.
4. After selecting "Create Certificate Request..." you will now be prompted with the "Certificate Request" wizard
- Fill in the information as prompted by the wizard
- Common name: Enter the Fully Qualified Domain Name that you wish to secure in the SSL certificate
- Please Note: If you are issuing a CSR for a Multi-Domain certificate and are wondering how to add SAN's, you will not be prompted in the wizard and will manually need to enter them on Entrust.net when placing your request for the certificate.
- Organization Name: Enter the full legal name for your Organization name
- Organization Unit: This is a non mandatory field. OU must be approved by Entrust. Traditionally used to specify a department.
- City/Location: Provide the location of where the Server is located that you will be installing the certificate on
- State/Province: Provide the State/Province of where the Server is located that you will be installing the certificate on
- Country: Provide the Country of where the Server is located that you will be installing the certificate on
- Once you have provided the above information continue to the next page of the Wizard by Selecting Next
5. Leave the default selection for "Cryptographic service provider:" as "Microsoft RSA SChannel Cryptographic Provider"
- For "Bit length" you must select a minimum of 2048
- Please Note: 1024 bit CSR's are no longer supported by Public CA's
- Once done Select: Next
6. Provide a save location for the CSR file
- Make sure to take note of where you are saving the file. You will need to open the file in Note Pad to submit your Certificate Request to Entrust.net
- The name of the file does not matter, make sure that you can distinguish from other files and documents.
7. Locate the CSR text file and view it in Note Pad
- Select All including: -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST-----
- Paste the content online at Entrust.net
If you have any questions or issues please feel free to contact Entrust Support: https://www.entrust.net/customer_support/contact.cfm
- Entrust Certificate Services SSL Mgmt Service Account - Non-Pooling Version Not Applicable ALL Platform Not Applicable