Creating a CSR and installing your SSL certificate on your Windows server 2016
Use the instructions on this page to use IIS 10 to create your certificate signing request (CSR) and then to install your SSL certificate on your Windows server 2016.
If you are looking for a simple way to create CSRs, and install and manage your SSL Certificates, we recommend using the DigiCert® Certificate Utility for Windows. You can use the DigiCert Utility to generate your CSR and install your SSL certificate. See Windows Server 2016 : Create CSR & Install SSL Certificate with DigiCert Utility .
1. IIS 10: How to Create Your CSR on Windows Server 2016
Using IIS 10 to Create Your CSR
- In the Windows begin menu, type Internet Information Services (IIS) Manager and open it.
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( leave pane ), locate and click the server mention .
- On the waiter diagnose Home page ( plaza pane ), in the IIS section, double-click Server Certificates .
-
On the Server Certificates page ( center field paneling ), in the Actions menu ( right acid ), click the Create Certificate Request… connection .
-
In the Request Certificate sorcerer, on the Distinguished Name Properties page, provide the information specified below and then chink Next :
Common name: Type the fully-qualified domain name (FQDN) (e.g., www.example.com). Organization: Type your company’s legally registered name (e.g., YourCompany, Inc.). Organizational unit: The name of your department within the organization. Frequently this entry will be listed as “IT”, “Web Security,” or is simply left blank. City/locality: Type the city where your company is legally located. State/province: Type the state/province where your company is legally located. Country: In the drop-down list, select the country where your company is legally located. -
On the Cryptographic Service Provider Properties page, provide the data below and then click Next .
Cryptographic In the drop-down list, select Microsoft RSA SChannel Cryptographic Provider, service provider: unless you have a specific cryptographic provider. Bit length: In the drop-down list select 2048, unless you have a specific reason for opting for larger bit length. -
On the File Name page, under Specify a file name for the certificate request, click the … corner to browse to a location where you want to save your CSR .
Note: Remember the filename that you choose and the placement to which you save your csr.txt file. If you just enter a filename without browsing to a location, your CSR will end up in C : \Windows\System32 .
- When you are done, snap Finish .
-
Use a text editor ( such as Notepad ) to open the file. then, copy the textbook, including the —–BEGIN NEW CERTIFICATE REQUEST—– and —–END NEW CERTIFICATE REQUEST—– tags, and paste it into the DigiCert order form .
fix to orderliness your SSL certificate
Buy Now
Learn More - After you receive your SSL certificate from DigiCert, you can install it .
2. IIS 10: How to Install and Configure Your SSL Certificate on Windows Server 2016
If you have not so far created a CSR and ordered your certificate, see iraqi intelligence service 10 : How to Create Your CSR Windows Server 2016 .
After we validate and issue your SSL certificate, you need to install it on the Windows 2016 waiter where the CSR was generated. then, you need to configure the server to use it .
- (Single Certificate) How to install and configure your SSL certificate
- (Multiple Certificates) How to install and configure your SSL certificates using SNI
(Single Certificate) How to install your SSL certificate and configure the server to use it
Install SSL Certificate
- On the waiter where you created the CSR, save the SSL security .cer file ( for example, your_domain_com.cer ) that DigiCert sent to you .
- In the Windows startle menu, type Internet Information Services (IIS) Manager and open it .
-
In Internet Information Services (IIS) Manager, in the Connections menu corner ( leftover acid ), settle and click the server name .
- On the server appoint Home page ( kernel paneling ), in the IIS section, double-click Server Certificates .
-
On the Server Certificates page ( center paneling ), in the Actions menu ( right paneling ), click the Complete Certificate Request… connection .
-
In the Complete Certificate Request sorcerer, on the Specify Certificate Authority Response page, do the pursuit and then click OK :
File name containing the Click the … box and browse to and select the .cer file certificate authority’s response: (e.g., your_domain_com.cer) that DigiCert sent to you. Friendly name: Type a friendly name for the certificate. The friendly name is not part of the certificate; instead, it is used to identify the certificate. We recommend that you add DigiCert and the expiration date to the end of your friendly name, for example: yoursite-digicert-(expiration date). This information helps identify the issuer and expiration date for each certificate. It also helps distinguish multiple certificates with the same domain name. Select a certificate store In the drop-down list, select Web Hosting. for the new certificate: - nowadays that you ‘ve successfully installed your SSL certificate, you need to assign the certificate to the allow site .
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( impart acid ), expand the name of the server on which the security was installed. then expand Sites and click the web site you want to use the SSL certificate to secure .
- On the web site Home page, in the Actions menu ( good acid ), under Edit Site, click the Bindings… connection .
-
In the Site Bindings window, chink Add .
-
In the Add Site Bindings window, do the following and then click OK :
Type: In the drop-down list, select https. IP address: In the drop-down list, select the IP address of the site or select All Unassigned. Port: Type port 443. The port over which traffic is secure by SSL is port 443. SSL certificate: In the drop-down list, select your new SSL certificate (e.g., yourdomain.com). -
Your SSL certificate is now installed, and the web site configured to accept procure connections.
Read more: How to register as a VIP in GTA Online
Assign SSL Certificate
(Multiple Certificates) How to install your SSL certificates and configure the server to use them using SNI
This instructions explains how to install multiple SSL certificates and assign them using SNI. The process is split into two parts as follows :
- Installing and Configuring Your first SSL Certificate
- Installing and Configuring All Additional Certificates
Install First SSL Certificate
Do this first base set of instructions only once, for the first SSL certificate .
- On the server where you created the CSR, save the SSL certificate .cer file ( for example, your_domain_com.cer ) that DigiCert sent to you .
- In the Windows startle menu, type Internet Information Services (IIS) Manager and open it .
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( leave acid ), locate and click the waiter name .
- On the waiter identify Home page ( center acid ), in the IIS segment, double-click Server Certificates .
-
On the Server Certificates page ( center pane ), in the Actions menu ( right pane ), click the Complete Certificate Request… liaison .
-
In the Complete Certificate Request sorcerer, on the Specify Certificate Authority Response page, do the following and then chink OK :
File name containing the Click the … box and browse to and select the .cer file certificate authority’s response: (e.g., your_domain_com.cer) that DigiCert sent to you. Friendly name: Type a friendly name for the certificate. The friendly name is not part of the certificate; instead, it is used to identify the certificate. We recommend that you add DigiCert and the expiration date to the end of your friendly name, for example: yoursite-digicert-(expiration date). This information helps identify the issuer and expiration date for each certificate. It also helps distinguish multiple certificates with the same domain name. Select a certificate store In the drop-down list, select Web Hosting. for the new certificate: - now that you ‘ve successfully installed your SSL certificate, you need to assign the certificate to the allow web site .
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( leave pane ), expand the name of the server on which the security was installed. then expand Sites and click the web site you want to use the SSL certificate to secure .
- On the web site Home page, in the Actions menu ( right pane ), under Edit Site, click the Bindings… connection .
-
In the Site Bindings windowpane, snap Add .
-
In the Add Site Bindings window, do the following and then chink OK :
Type: In the drop-down list, select https. IP address: In the drop-down list, select the IP address of the site or select All Unassigned. Port: Type port 443. The port over which traffic is secure by SSL is port 443. SSL certificate: In the drop-down list, select your new SSL certificate (e.g., yourdomain.com). - Your first SSL security is now installed, and the web site configured to accept impregnable connections .
Install Additional SSL Certificates
To install and assign each extra SSL certificate, repeat the steps below, as needed .
- On the server where you created the CSR, save the SSL certificate .cer file ( for example, your_domain_com.cer ) that DigiCert sent to you .
- In the Windows startle menu, type Internet Information Services (IIS) Manager and open it .
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( leave acid ), situate and click the server name .
- On the server name Home page ( center pane ), in the IIS incision, double-click Server Certificates .
-
On the Server Certificates page ( center pane ), in the Actions menu ( correct paneling ), click the Complete Certificate Request… link .
-
In the Complete Certificate Request sorcerer, on the Specify Certificate Authority Response page, do the comply and then pawl OK :
File name containing the Click the … box and browse to and select the .cer file certificate authority’s response: (e.g., your_domain_com.cer) that DigiCert sent to you. Friendly name: Type a friendly name for the certificate. The friendly name is not part of the certificate; instead, it is used to identify the certificate. We recommend that you add DigiCert and the expiration date to the end of your friendly name, for example: yoursite-digicert-(expiration date). This information helps identify the issuer and expiration date for each certificate. It also helps distinguish multiple certificates with the same domain name. Select a certificate store In the drop-down list, select Web Hosting. for the new certificate: - immediately that you ‘ve successfully installed your SSL certificate, you need to assign the certificate to the appropriate web site .
-
In Internet Information Services (IIS) Manager, in the Connections menu tree ( bequeath pane ), expand the appoint of the waiter on which the certificate was installed. then expand Sites and click the site you want to use the SSL certificate to secure .
- On the web site Home foliate, in the Actions menu ( right field pane ), under Edit Site, click the Bindings… link .
-
In the Site Bindings window, chatter Add .
-
In the Add Site Bindings window, do the watch and then pawl OK :
Type: In the drop-down list, select https. IP address: In the drop-down list, select the IP address of the site or select All Unassigned. Port: Type port 443. The port over which traffic is secure by SSL is port 443. Host name: Type the host name that you want to secure. Require Server After you enter the host name, check this box. Name Indication: This is required for all additional certificates/sites, after you’ve installed the first certificate and secured the primary site. SSL certificate: In the drop-down list, select an additional SSL certificate (e.g., yourdomain2.com). - You have successfully installed another SSL certificate and configured the web site to accept secure connections .
Test Installation
If your web site is publicly accessible, our DigiCert® SSL Installation Diagnostic Tool can help you diagnose common problems .