Note:
If you are renewing your certificate or your site is currently running a web
server certificate, please refer to renewal section of this document.
Creating a Certificate
Signing Request
Select
the Internet Information Services console within the
Administrative Tools menu.
Select
the computer and web site (host) that you wish to secure.
Right
mouse-click to select Properties.
Select
the Directory Security tab.
Select
Server Certificate under Secure Communications
Click
Next in the Welcome to the Web Server Certificate Wizard window.
Select
Create a new certificate, Click Next.
Select
Prepare the request now, but send it later.
At
the Name and Security Settings screen, fill in the [friendly]
name field for the new certificate. Select bit length. We recommend
using 1024-bit length. Click Next.
When
creating a CSR you must follow these conventions.
Enter
your Distinguished Name Field information.
The
following characters are not accepted: < > ~ ! @ # $ % ^ * / \ ( )
?&.
Wildcard certificates must start with *. characters
This
includes commas.
Contact ipsCA
For further Information: Email: Phone: +34 91 6402052
Distinguished
Name Field
Explanation
Example
Common
Name (Server Host Name)
The
fully qualified domain name for your web server. You will get a
certificate name check warning if this is not an exact match.
If
you intend to secure the URL https://secure.yourURL.com, then your
CSR's Server Hostname must be secure.yourURL.com
Organization
Name
The
exact legal name of your organization. Do not abbreviate
IPS
S.L.
Organizational
Unit
Optional
for additional organization information
Marketing
City
or Locality
The
city where your organization is located.
Atlanta
State
or Province Name
The
state or province where your organization is located. It cannot be
abbreviated.
Georgia
Country
Name
The
two-letter ISO abbreviation for your country
US
= United States
Enter
your Administrator contact information.
Enter
a path and file name for the CSR.
Verify
your request and then click Next.
At
the Completing the Web Server screen, select Finish.
DO
NOT REMOVE the pending request or the .crt file will not match and your
certificate will not be installed.
Select
Finish.
Submit
your CSR to IPSCA.
Renewals
on Sites currently running ssl
The
renewal request option within IIS 5.0 does not create a request in a PKCS10
format. This should be corrected with SP2. IIS 5.0 does not allow your site
that is currently running ssl to generate a certificate signing request
(CSR) without removing the existing certificate. For most sites this is not
an option since your site will not be able to run a ssl session while your
certificate is being processed. To obtain a certificate for your existing
web site you will have to do the following. Please read and print these
instructions before submitting your new certificate request.
Leave
your existing site that currently has the certificate installed alone.
Create
another virtual site within IIS (this does not have to be a functional
site).
Create
a certificate request within the newly created virtual site.
Wait
for the .crt response file to be emailed to you from servidores@ipsca.com.
After
receiving the response file (.crt) you will need to go to the new virtual
site and process the pending request by selecting the .crt file we sent
you.
After
combining your .crt file to the pending request you may then go to the
original web site and remove the current certificate.
You
can then assign an existing certificate, which will be the new
certificate.
CSR Installation
Microsoft Internet Information Server 5.0/6.0
Microsoft IIS customers trying to obtain Server Certificates, may run into
problems from a number of different sources when trying to install a
certificate. Firstly, you may encounter certain problems if your e-mail program
corrupts the certificate that you receive from IPSCA. Secondly, you may have
problems if you do not use a supported server configuration. Finally, your
customers may have problems establishing SSL sessions if they are using older
browsers. Please make sure that you follow the steps below, and you should not encounter
any problems in providing the special services enabled by these
products to your customers.
Installing a Server Certificate on MicroSoft IIS 5.0/6.0.
Stage 1: Installing the Intermediate CA Certificate.
The intermediate CA certificate uses the import facility within IE5.
Step 1
The Intermediate CA certificate
can be downloaded from here
Step 2
Copy the Intermediate CA Certificate and save it as a text file, with Notepad. Remember to include the lines ----BEGIN CERTIFICATE--- and ---END CERTIFICATE--- Do not use Word or other word processors. These add various formatting characters that may prevent correct operation.
Step 3
Check to see if a copy of IE5, or above, is installed in the server. If not, please install a copy of this browser now together with the service packs 1 & 2.
Step 4
Select Internet Options from the IE Tools menu.
Select Content tag.
Step 5
Select Certificates button.
Step 6
Select Import button.
Step 7
The Certificate Import Wizard starts.
Step 8
Select the Next button.
Step 9
Browse to the Intermediate CA Certificate text file.
Select the Next button.
Step 10
Select "Place all certificates in the following store" radio button.
Step 11
Select the Browse button.
Step 12
Tick the "Show physical stores" box.
Step 13
Select and expand the "Intermediate Certificate Authorities" folder and select "Local computer".
Step 14
Select the OK button.
Step 15
Select the Next button.
Step 16
Select the Finish button.
You will be able to view the imported Intermediate CA Certificate in IE along with all the regular certificates.
Step 17
Select OK in the next dialog box.
Step 18
Select the Close button.
Step 19
Select the OK button.
Step 20
Stop and restart the Web server. Users should now be able to connect the Web server
via https at 128 bit.
Stage 2: Installing the Server Certificate.
Step 1
Wait until the server certificate has been emailed to you.
Step 2
Save the Server Subscriber Certificate as a text file.
Step 3
Restart the Web Server Certificate Wizard. ( See Generating a CSR and Certificate Request steps 1 to 8 in Stage 1).
Step 4
Select "Next ".
Step 5
Select "Next ".
Step 6
Select "Next".
Step 7
Browse to Server Certificate text file, and select the certificate.