CSR Support

 

Microsoft Internet Information Server 5.0/6.0

Note: If you are renewing your certificate or your site is currently running a web server certificate please refer to renewal section of this document

Creating a Certificate Signing Request

  1. Select the Internet Information Services console within the Administrative Tools menu.
  1. Select the computer and web site (host) that you wish to secure.

Right mouse-click to select Properties.

  1. Select the Directory Security tab.
  1. Select Server Certificate under Secure Communications
  1. Click Next in the Welcome to the Web Server Certificate Wizard window.
  1. Select Create a new certificate, Click Next.
  1. Select Prepare the request now, but send it later.
  1. At the Name and Security Settings screen, fill in the [friendly] name field for the new certificate. Select bit length. We recommend using 1024-bit length. Click Next.
  1. When creating a CSR you must follow these conventions.

Enter your Distinguished Name Field information.

The following characters can not be accepted: < > ~ ! @ # $ % ^ * / \ ( ) ?&.

This includes commas.  

 

Distinguished Name Field

Explanation

Example

Common Name (Server Host Name)

The fully qualified domain name for your web server. You will get a certificate name check warning if this is not an exact match.

If you intend to secure the URL https://secure.yourURL.com, then your CSR's Server Hostname must be secure.yourURL.com

 

 

 

Organization Name

The exact legal name of your organization. Do not abbreviate

IPS S.L.

Organizational Unit

Optional for additional organization information

Marketing

City or Locality

The city where your organization is located.

Atlanta

State or Province Name

The state or province where your organization is located. Can not be abbreviated.

Georgia

Country Name

The two-letter ISO abbreviation for your country

US = United States

 
  1. Enter your Administrator contact information.
  1. Enter a path and file name for the CSR.
  1. Verify your request and then click Next.
  1. At the Completing the Web Server screen, select Finish.

DO NOT REMOVE the pending request or the .crt file will not match and your certificate will not install.

  1. Select Finish.

Submit your CSR to IPSCA.

Renewals or Sites currently running ssl

The renewal request option within IIS 5.0 does not create a request in a PKCS10 format. This should be corrected with SP2. IIS 5.0 does not allow your site that is currently running ssl to generate a certificate signing request (CSR) without removing the existing certificate. For most sites this is not an option since your site will not be able to run a ssl session while your certificate is being processed. To obtain a certificate for your existing web site you will have to do the following. Please read and print these instructions before submitting your new certificate request.

  1. Leave your existing site that currently has the certificate installed alone.
  2. Create another virtual site within IIS (this does not have to be a functional site).
  3. Create a certificate request within the newly created virtual site.
  4. Submit the new request through the following URL http://certificados.ipsca.com/SrvC/Default.htm.
  5. Wait for the .crt response file to be emailed to you from servidores@ipsca.com.
  6. After you receive the response file (.crt) you will need go to the new virtual site and process the pending request by selecting the .crt file we sent you.
  7. After combining your .crt file to the pending request you may then go to the original web site and remove the current certificate.
  8. You can then assign an existing certificate, which will be the new certificate. 

 



 CSR installation

 

Microsoft Internet Information Server 5.0/6.0

Microsoft IIS customers trying to obtain Server Certificates, may run in to problems from a number of different sources when trying to install a certificate. First, you may encounter certain problems if your e-mail program corrupts the certificate that you receive from IPSCA. Second, you may have problems if you do not use a supported server configuration. Finally, your customers may have problems establishing SSL sessions if they are using older browsers, Please make sure that you follow the steps below, and you should encounter no problems in providing the special services enabled by these products to your customers.

Installing a Server Certificate on MicroSoft IIS 5.0/6.0.

Stage 1: Installing the Intermediate CA Certificate.

The intermediate CA certificate uses the import facility within IE5.

Step 1

The Intermediate CA certificate can be downloaded from here


Step 2

Copy the Intermediate CA Certificate and save it as a text file, with Notepad. Remember to include the lines ----BEGIN CERTIFICATE--- and ---END CERTIFICATE--- Do not use Word or other word processors. These add various formatting characters that may prevent correct operation.

Step 3

Check to see if a copy of IE5, or above, is installed in the server. If not, please install a copy of this browser now together with the service packs 1 & 2.

Step 4

Select Internet Options from the IE Tools menu.



Select Content tag.

Step 5



Select Certificates button.

Step 6



Select Import button.

Step 7

The Certificate Import Wizard starts.



Step 8

Select the Next button.

Step 9

Browse to the Intermediate CA Certificate text file.



Select the Next button.

Step 10



Select "Place all certificates in the following store" radio button.

Step 11

Select the Browse button.

Step 12



Tick the "Show physical stores" box.

Step 13



Select and expand the "Intermediate Certificate Authorities" folder and select "Local computer".

Step 14

Select the OK button.

Step 15



Select the Next button.

Step 16



Select the Finish button.
You will be able to view the imported Intermediate CA Certificate in IE along with all the regular certificates.

Step 17

Select OK in the next dialog box.

Step 18


Select the Close button.

Step 19



Select the OK button.

Step 20

Stop and restart the Web server. Users should now be able to connect the Web server via https at 128 bit.

Stage 2: Installing the Server Certificate.

Step 1

Wait until the server certificate has been emailed to you.

Step 2

Save the Server Subscriber Certificate as a text file.

Step 3

Restart the Web Server Certificate Wizard. ( See Generating a CSR and Certificate Request steps 1 to 8 in Stage 1).

Step 4

Select "Next ".

Step 5



Select "Next ".

Step 6

Select "Next".

Step 7

Browse to Server Certificate text file, and select the certificate.

Step 8

Select "Next".

Step 9



Certificates details are now displayed.

Step 10

Select "Next".

Step 11

Select "Finish".

return to the top

© 1996 - 2007 ipsCA, IPS Certification Authority, S.L. all Rights reserved.
Our CPS summarized or complete, CRLs, Root Certificates and legal documents
  can be found in our repository
Read our  Privacy Policy and Terms of Use