Server Certificates

Applies To: Windows Server 2012 R2, Windows Server 2012

Apply the Server Certificates feature page to view the names of certificates, the fully qualified domain names (FQDNs) of hosts to which certificates have been issued, and the FQDNs of the servers that issued the certificates.

Related scenarios

  • Build a Static Website on IIS

  • Build a Classic ASP Website on IIS

  • Build an ASP.Net Website on IIS

  • Build a PHP Website on IIS

  • Build a Web Farm with IIS Servers

In this document

  • UI Elements for Server Certificates

  • Import Certificate Dialog Box

  • Asking Document Sorcerer

  • Complete Certificate Request Dialog Box

  • Create Certificate Wizard

  • Create Self-Signed Certificate Dialog Box

  • Export Certificate Dialog Box

  • Renew an Existing Certificate Wizard

UI Elements for Server Certificates

The following tables describe the UI elements that are available on the feature page and in the Actions pane.

Feature Page Elements

Chemical element Name

Description

Name

Displays the names of certificates that have been issued to clients that are running on either Internet or intranet hosts.

Note

Certificates are not required to have names. Yous might take to view other columns to obtain information about certificates.

Issued To

Displays the FQDNs of either the Internet or intranet hosts to which certificates have been issued.

Issued Past

Displays the FQDNs of servers that take issued certificates to clients that are running on either Internet or intranet hosts.

Expiration Date

Displays the date that the certificate expires.

Certificate Hash

Displays binary data produced by using a hashing algorithm. Although this information uniquely identifies a certificate, the hash data cannot be used to trace a certificate because hashing is a 1-way procedure.

Certificate Shop

Displays the name of the provider that stores the certificate.

Actions Pane Elements

Element Name

Description

Import

Opens the Import Document dialog box to restore a lost or damaged document that you previously backed upwardly, or to install a document sent to you by another user or certification authorization (CA).

Create Certificate Request

Opens the Request Certificate magician to provide information near your arrangement to an external certification authority.

Complete Certificate Asking

Opens the Consummate Certificate Asking dialog box to install the certificates that you receive from your certification authority.

Create Domain Certificate

Opens the Create Certificate wizard to provide data about your organization to an internal certification authority.

Create Self-Signed Document

Opens the Create Self-Signed Certificate dialog box to create certificates to use in server testing environments and for troubleshooting tertiary-party certificates.

View

Opens the Certificate dialog box so that you can view details about a certificate. Select a certificate to see this pick.

Export

Opens the Export Document dialog box to export certificates from a source server when you want to use the same certificate to a target server, or when you want to back up a certificate and its associated private key. Select a document to see this option.

Remove

Removes the item that is selected from the list on the feature page. Select a certificate to see this option.

Import Document Dialog Box

Use the Import Certificate dialog box to restore a lost or damaged document that you previously backed up, or to install a certificate sent to yous past another user or certification authority (CA).

Element Name

Description

Certificate file (.pfx)

Type a file proper name in the Document file (.pfx) box or click Browse to navigate to the name of a file where the exported certificate is stored.

Password

Type the password in the Countersign field, if the certificate was exported with a password.

Select Certificate Store

Displays the name of the provider that stores the document.

Permit this certificate to exist exported

Select Let this certificate to be exported if you lot want to exist able to export the certificate, or clear Allow this document to exist exported if you do non want to allow boosted exports of this certificate.

Request Document Wizard

Use the Asking Certificate wizard to request a certificate from a certification potency (CA).

Distinguished Proper noun Backdrop Magician Page

Utilise the Distinguished Name Properties dialog box to provide information well-nigh your organization to an internal or external certification authority.

Element Name

Description

Common name

Type a name for the certificate.

Organization

Type the proper name of the organization for which the certificate is used.

Organizational unit of measurement

Type the name of the department or partition in the system in which the certificate is used.

City/locality

Type the unabbreviated name of the metropolis or locality where your organisation or organizational unit is located.

State/province

Type the unabbreviated name of the state or province where your organization or organizational unit is located.

State/region

Type the proper name of the country or region where your organization or organizational unit of measurement is located.

Cryptographic Service Provider Properties Magician Page

Use the Cryptographic Service Provider Wizard folio to select either Microsoft RSA SChannel Cryptographic Provider or Microsoft DH SChannel Cryptographic Provider to provide certificates that can encrypt transmissions betwixt your server and clients. Additionally, you can adjust the level of security for your transmission by irresolute the bit length associated with the cryptographic service provider.

Element Proper name

Description

Cryptographic service provider

Select either Microsoft RSA SChannel Cryptographic Provider or Microsoft DH SChannel Cryptographic Provider. The default cryptographic service provider is Microsoft RSA SChannel Cryptographic Provider.

Annotation

Select Microsoft DH SChannel Cryptographic Provider when you must commutation a secret fundamental over a network that is not secure and you have had no prior communication with the other party.

Bit length

Select a bit length that the provider you selected uses. By default, the RSA SChannel provider uses a flake length of 1024, and the DH SChannel provider uses a flake length of 512.

Note

A longer fleck length increases the level of encryption. However, it tin decrease operation because it requires the transmission of additional bits.

File Name Sorcerer Folio

Employ the File Name dialog box to name and then save your certificates to the appropriate storage location.

Chemical element Name

Description

Specify a file proper noun for certificate request

Type a file name in the Specify a file name for the certificate asking field.

Navigate to a file proper name under which to store the certificate.

Complete Certificate Request Dialog Box

Utilise the Consummate Certificate Asking dialog box to install the certificates that you lot receive from your certification say-so (CA). Additionally, provide a Friendly name for the certificate that you desire to install to complete the certificate installation procedure.

Element Proper name

Clarification

File name containing certification authority's response

Type the path of the file that contains the response from the certification authority in the File name containing certification dominance's response box, or click Scan to navigate to the location in which the file from the certification authority is stored.

Important

Complete this process to install a certificate on your server.

Friendly proper name

Blazon a name in the Friendly proper noun box to consummate the certificate installation process.

Select a certificate shop for the new certificate

Select from a list of available certificate providers.

Create Certificate Wizard

Use the Create Certificate wizard to create a domain certificate. A domain document is an internal certificate that is not issued by an external certification authority (CA).

Distinguished Name Properties Wizard Folio

Utilise the Distinguished Name Properties dialog box to provide information about your arrangement to an internal or external certification potency.

Chemical element Name

Description

Common proper name

Blazon a name for the certificate.

Organization

Type the proper name of the organization for which the certificate is used.

Organizational unit of measurement

Blazon the name of the department or division in the organization in which the certificate is used.

City/locality

Type the unabbreviated proper noun of the city or locality where your organisation or organizational unit is located.

State/province

Type the unabbreviated name of the country or province where your arrangement or organizational unit is located.

Land/region

Blazon the name of the country or region where your organization or organizational unit is located.

Online Certification Authority Wizard Page

Use the Online Certification Authorisation Wizard page to identify an online certification authority (CA) server in your Windows domain. Additionally, supply the CA server that you desire to use with a Friendly name to consummate the Create Domain Document Wizard.

Element Name

Description

Specify Online Certification Authority

Type the path of a CA server that is in your Windows domain, or click Select to search for a CA server that is in your domain and display the Select Certification Authority dialog box.

Annotation

Domain certificates are non appropriate for utilize with external clients that are non members of your internal Windows domain.

Friendly name

Type a name for the CA server that you want to use in the Friendly name box. Blazon a name in the Friendly name box to complete the Create Domain Certificate Wizard.

Select Certification Authority Dialog Box

Use the Select Certification Authority dialog box to select the internal certification authority (CA) that you want to apply.

Element Name

Description

Select a certification authorisation you want to use

Lists the friendly names of CA and the fully qualified domain name (FQDN) of the computer that hosts the CA. Select the CA that yous want to use.

Create Self-Signed Certificate Dialog Box

Use the Create Self-Signed Document dialog box to create certificates to use in server testing environments and for troubleshooting 3rd-party certificates.

You can view the properties of your self-signed document on the Server Certificates Page.

Element Proper noun

Description

Specify a friendly name for the certificate

Type a friendly name in the Name box to create a cocky-signed document.

Note

The certificates you create with this feature are not from a trusted certification dominance (CA) source. Therefore, use self-signed certificates only to assist secure information transmissions betwixt your server and clients inside a test surroundings.

Export Certificate Dialog Box

Utilize the Export Certificate dialog box to export certificates from a source server when you want to utilise the aforementioned certificate to a target server, or when you want to back up a certificate and its associated private key.

Annotation

If you acquaintance a password with the certificate, whoever imports the certificate must know the countersign earlier the certificate can be applied to the target server.

Element Name

Description

Consign to

Type a file name in the Export to box or click Browse to navigate to the proper noun of a file in which to shop the certificate for exporting.

Password

Type a countersign in the Countersign box if you lot want to associate a password with the exported certificate.

Confirm password

Retype the countersign in the Confirm password box and then click OK.

Renew an Existing Document Wizard

Use the Renew an Existing Certificate wizard to renew a certificate that is about to elapse.

Important

You cannot renew a certificate that has already expired. If yous try to renew a certificate that has expired, the certification authority (CA) rejects the request, and you volition see an error message similar to "Error Verifying Asking Signature or Signing Certificate. A required certificate is non within its validity period when verifying confronting the current organisation clock or the timestamp in the signed file." This message is also displayed in the Failed Requests node of the issuing CA. If your certificate has already expired, request a new certificate instead of renewing the existing certificate.

Element Name

Description

Renew an existing certificate

Select this choice to renew an existing certificate from an internal certification authority (CA) on your domain.

Create a renewal certificate asking

Select this option to package your renewal information for later submission to a CA.

Complete document renewal request

Select this option to complete the document renewal asking with the document you received from a CA.