Microsoft Internet Information Server 6.0 for Windows 2003 Support
It is highly recommended that you back up the Private Key for your Web Server and store the file in a secure location.
Backing up the Private Key will ensure the ability to restore the security for your Web Site in the event of a disaster.
The Certificates snap-in utility must be installed.
Snap-In Configuration
Use the following steps to create a new Microsoft Managment Console (MMC) and add the Certificates snap-in:
- Click Start, and then click Run.
- Type in "MMC" (without the quotation marks) and click OK.
- Click Console in the new MMC you created, and then click Add/Remove Snap-in.
- In the new window that appears, click Add.
- Highlight Certificates, and then click Add.
- Choose the Computer account option and click Next.
- Select Local Computer on the next screen, and then click Finish.
- Click Close, and then click OK.
Exporting your keypair (private and public keys):
From the MMC Console opened in the above steps:
- Expand the 'Certificates' tree in the left preview panel
- Expand the 'Personal' tree in the left preview panel and highlight 'Certificates'
- Select and Right-click your Entrust SSL Certificate from the right preview panel
- Select All Tasks/ Export - The Certificate Export Wizard appears
- Select Next to continue.
- Select Yes, to export the private key
- Select Next to continue.
- Ensure 'Enable Strong Protection' is checked, click Next
- Supply and confirm a password for your keypair back up.
N.B. It is very important that you remember this password. If you forget it you will not be able to gain access to your Private Key.
- Supply a file name and location for your keypair back up. This will create a PFX file.
N.B. Store your PFX keypair backup onto some form of removable media to ensure it is not lost.
- Select Next to continue.
- Select Finish.
- Select OK to complete the Export.
You have successfully backed up your keypair (private and public keys).
Importing your Private Key:
The Certificates snap-in utility must be installed. See Snap-In Configuration.
From the MMC console opened in the above steps:
- Expand the 'Certificates' tree in the left preview panel
- Right-click 'Personal'
- Select All Tasks/Import - The Certificate Import Wizard appears.
- Select Next to continue.
- Browse to, and Select your PFX keypair file.
- Select Next to continue.
- Supply the password which was provided during the creation of the PFX keypair file.
N.B. Be sure the 'Mark the key as exportable' option is selected if you want to be able to export the key pair again from this computer. As an added security measure, you may want to leave this option unchecked to ensure that no one can make a backup of your private key.
- Select Next to continue.
- Select Next to continue.
- Select Finish.
- Select OK to complete the Import.
You have successfully imported your PFX keypair into the Windows certificate store.
To enable IIS 6.0 to use this certificate please follow the steps proceeding:
- Go into the properties of the site and choose the Directory Security tab
- Click on Server Certificate button under Secure Communication area.
- Choose the option "Assign an existing certificate"
- A pop up will appear with your Entrust SSL Certificate. Choose the Entrust SSL Certificate and finish the wizard.
- Make sure that SSL Port 443 is open on the firewall and within IIS 6 (default tab)
- Stop and Start the website.
![[Certification Authorities - Webtrust - Deloitte]](/images/cert_services/deloitte_seal_sm.jpg)