 |
 |
SSL Certificates Support
|
CSR Generation Instructions- Microsoft IIS 4.0
To generate a CSR,
you will need to create a key pair for your server. These two items
are a digital certificate key pair and cannot be separated. If you lose
your public/private key file or your password and generate a new one,
your SSL Certificate will no longer match. You will have to request
a new SSL Certificate and may be charged.
VeriSign recommends
that you contact the IIS 4.0 vendor for additional information.
Generate a Key
Pair and Certificate Signing Request
- Open the Microsoft Management Console (MMC) for IIS. This is normally
reached by selecting Start -> Programs -> Windows NT 4.0 Option
Pack -> Microsoft Internet Information Server -> Internet Service
Manager.
- Expand the Internet Information Server folder by selecting the "+"
sign and then select the "+" sign next to the computer name.
- Locate the website that is going to be using the SSL Certificate.
This is usually the "Default Web Site". Right click on the
website and choose "Properties".
- In the "Properties" window, choose the "Directory Security"
tab.
- You should see "Secure Communications" and next to it is
the "Edit button". Click on it and then click the "Key
Manager" button.
- In "Key Manager" right click the WWW icon and select "Create
New Key..."
- Choose "Put the request in a file that you will send to an authority."
Select an appropriate filename (or accept the default).
- Fill out the next dialogue. Key lengths available will depend on the
version and Service Packs installed. Please remember the password you
enter. Without it, you will not be able to install or backup the certificate.
NOTE: For every website using SSL that has a distinct DNS name, there
must be a certificate installed. Each website for SSL MUST also have
a distinct IP address as well. SSL DOES NOT SUPPORT THE USE OF HOST
HEADERS.
- You must also specify a bit length for the CSR, choose 1024.
- Fill out the appropriate contact information and Finish. This information
can be whatever you like since it will not actually be placed in the
certificate.
- Key Manager will display a key icon under the WWW icon with a red
slash through it indicating it is not complete.
- Choose the "Computers" menu and select "Exit".
Choose YES when asked to commit changes.
- You have just created a key pair and a CSR. To copy and paste
the information into the enrolment form, open the file in a text editor
that does not add extra characters (Notepad or Vi are recommended).
- Go to Enrolment.
Terms Defined
Common Name
The Common Name
is the Host + Domain Name. It looks like "www.company.co.uk"
or "company.co.uk".
VeriSign certificates
can only be used on Web servers using the Common Name specified during
enrolment. For example, a certificate for the domain "domain.co.uk"
will receive a warning if accessing a site named "www.domain.co.uk"
or "secure.domain.co.uk", because "www.domain.co.uk"
and "secure.domain.co.uk" are different from "domain.co.uk".
Organisation Information
- If your company or department has an &, @, or any other symbol
using the shift key in its name, you must spell out the symbol or omit
it to enrol.
- The “Org Unit” field is the name of the department or organisation
unit making the request.
- The Locality field is the city or town name, for example: Guildford.
- Do not abbreviate the county name, for example: Surrey.
- Use the two-letter code without punctuation for country, for example:
GB.
Contact Information
During the verification
process, VeriSign may need to contact your organisation. Be sure to
provide an email address, phone number, and fax number that will be
checked and responded to quickly. These fields are not part of the certificate.
|
 |