<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4458964827866241824</id><updated>2025-02-05T05:00:39.236-08:00</updated><category term="Tomcat"/><category term="Apache"/><category term="CSR"/><category term="SSL"/><category term="IIS"/><category term="MMC"/><category term="PKCS12"/><category term="jboss"/><category term="openssl"/><category term="orapki"/><category term="pfx"/><category term="ECC"/><category term="ECDSA"/><category term="EXCHANGE"/><category term="INTERMEDIATE"/><category term="JKS"/><category term="ROOT"/><category term="TLS"/><category term="keytool"/><category term="sapgenpse"/><category term="wildfly"/><title type='text'>PKI404</title><subtitle type='html'>All about public key infrastructure</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.pki404.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default'/><link rel='alternate' type='text/html' href='http://www.pki404.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-1077019301809305392</id><published>2024-06-10T00:36:00.000-07:00</published><updated>2024-06-10T00:36:08.604-07:00</updated><title type='text'>How to fix &quot;One or More of the Object&#39;s Properties Are Missing or Invalid&quot;</title><content type='html'>&lt;div&gt;Are you encountering the &quot;Code Sign CSR Error: One or More of the Object&#39;s Properties Are Missing or Invalid&quot; error in Microsoft Management Console (MMC)? This video will guide you through the steps to troubleshoot and resolve this common issue when generating a Certificate Signing Request (CSR).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Let&#39;s See how to fix below Error.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;One or More of the Object&#39;s Properties Are Missing or Invalid&lt;/h2&gt;&lt;div&gt;Please go through the below Video to resolve the issue, and subscribe to the channel as well to post such contents.&lt;/div&gt;

&lt;div class=&quot;ytiframe&quot;&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;300&quot; src=&quot;https://www.youtube-nocookie.com/embed/HZY7tjvLSh0?rel=0&quot; title=&quot;YouTube video player&quot; width=&quot;100%&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;

&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;

</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/1077019301809305392/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2024/06/how-to-fix-one-or-more-of-objects.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1077019301809305392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1077019301809305392'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2024/06/how-to-fix-one-or-more-of-objects.html' title='How to fix &quot;One or More of the Object&#39;s Properties Are Missing or Invalid&quot;'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-190816212702398717</id><published>2024-05-27T03:08:00.000-07:00</published><updated>2024-05-27T03:08:09.344-07:00</updated><title type='text'>How to import CRL into MMC</title><content type='html'>&lt;p&gt;Please Open the MMC (Start &amp;gt; Run &amp;gt; MMC).&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Go to File &amp;gt; Add / Remove Snap In&lt;/li&gt;&lt;li&gt;Double Click Certificates&lt;/li&gt;&lt;li&gt;Select Computer Account.&lt;/li&gt;&lt;li&gt;Select Local Computer &amp;gt; Finish&lt;/li&gt;&lt;li&gt;Click OK to exit the Snap-In window.&lt;/li&gt;&lt;li&gt;Click [+] next to Certificates &amp;gt; Trusted root certification authorities&lt;/li&gt;&lt;li&gt;Right click on folder and select All Tasks &amp;gt; Import&lt;/li&gt;&lt;li&gt;Click Next&lt;/li&gt;&lt;li&gt;Click Browse&lt;/li&gt;&lt;li&gt;Select the .crl you would like to import. Click Open.&lt;/li&gt;&lt;li&gt;Click Next&lt;/li&gt;&lt;li&gt;Select Automatically select the certificate store based on the type of certificate.&lt;/li&gt;&lt;li&gt;Click Finish &amp;amp; OK&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Kindly perform same once for Intermediate certification authorities folder instead of trusted root certification authorities.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;If you have closed the MMC, then please follow the above steps from 1-5 then continue the below steps.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Now Click [+] next to Certificates &amp;gt; Intermediate certification authorities&lt;/li&gt;&lt;li&gt;Right click on folder and select All Tasks &amp;gt; Import&lt;/li&gt;&lt;li&gt;Click Next&lt;/li&gt;&lt;li&gt;Click Browse&lt;/li&gt;&lt;li&gt;Select the .crl you would like to import. Click Open.&lt;/li&gt;&lt;li&gt;Click Next&lt;/li&gt;&lt;li&gt;Select Automatically select the certificate store based on the type of certificate.&lt;/li&gt;&lt;li&gt;Click Finish &amp;amp; OK&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/190816212702398717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2024/05/how-to-import-crl-into-mmc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/190816212702398717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/190816212702398717'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2024/05/how-to-import-crl-into-mmc.html' title='How to import CRL into MMC'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-8616724509387777112</id><published>2021-12-11T08:09:00.000-08:00</published><updated>2021-12-11T08:09:17.455-08:00</updated><title type='text'>OPENSSL MOST USEFUL COMMANDS IN PKI</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone!! Welcome to another exciting article by&amp;nbsp;&lt;b&gt;&lt;a href=&quot;https://www.pki404.com&quot; target=&quot;_blank&quot;&gt;PKI404&lt;/a&gt;&lt;/b&gt;, In this article we will see most common command used in openssl for pfx and key files on apache and other web servers So lets start without any further due.&lt;/p&gt;&lt;h1 style=&quot;text-align: center;&quot;&gt;OPENSSL MOST USEFUL COMMANDS&lt;/h1&gt;&lt;h3&gt;1. To Generate CSR and Private key&lt;/h3&gt;&lt;div&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;1. openssl req -new -newkey rsa:2048 -sha256 -nodes -out domainname.csr -keyout privatekey.key&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;2. openssl req -new -newkey rsa:2048 -nodes -out domainname.csr -keyout privatekey.key&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Generate CSR and Private key from one command&lt;br /&gt;&lt;br /&gt;&lt;b style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl req -new -newkey rsa:2048 -nodes -out domainname.csr -keyout privatekey.key -subj &quot;/C=IN/ST=Delhi/L=New Delhi/O=PKI404/OU=PKI/CN=www.pki404.com&quot;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;2. To Generate CSR and Encrypted Private key&lt;/h3&gt;&lt;div&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl req -new -newkey rsa:2048 -sha256 -out domainname.csr -keyout privatekey.key&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;h3&gt;3.Convert PEM to DER&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl x509 -outform der -in certificate.pem -out certificate.der&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;4.Convert DER to PEM&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl x509 -inform der -in certificate.der -out certificate.pem&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;5.Convert PEM/CRT to P7B&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b -certfile CACert.crt&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;6.Convert P7B to PEM/CRT&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;7.Convert PEM/CRT &amp;amp; Private Key to PFX/P12&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;8.Convert P7B to PFX: (first convert p7b to pem/crt from above commands then use below)&lt;/h3&gt;&lt;h3&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx -certfile CACert.cer&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;/h3&gt;&lt;h3&gt;9.Convert PFX to PEM/CRT and Private Key&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl pkcs12 -in certificate.pfx -out certificate.pem -nodes&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;10.OpenSSL command to remove private key password&lt;/h3&gt;&lt;h3&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;b style=&quot;color: red;&quot;&gt;openssl rsa -in file.key -out newfile.key&lt;/b&gt;&lt;/p&gt;11.convert simple private to&amp;nbsp; RSA&amp;nbsp; private key&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl rsa -in normal.key -out newrsa.key&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;12.Create RSA Private Key from PFX (private key without any password)&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl pkcs12 -in certificate.pfx -nocerts -nodes | openssl rsa -out newrsaprivatekey.key&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;13.View CSR contents&lt;br /&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl req -in mycsr.csr -noout -text&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;/h3&gt;&lt;h3&gt;14.View Certificate X509 contents (.cer/,crt/.pem files)&lt;br /&gt;&lt;br /&gt;&lt;b style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -in certificate.crt -text -noout&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;15.To Match private key, CSR and certificate (output of all three commands should be the same)&lt;/h3&gt;&lt;h3&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkey -in privateKey.key -pubout -outform pem | sha256sum&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -in domaincertificate.cer -pubkey -noout -outform pem | sha256sum&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl req -in CSR.csr -pubkey -noout -outform pem | sha256sum&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;/h3&gt;&lt;h3&gt;16.openssl command print out md5 checksums of the certificate and key&lt;/h3&gt;&lt;h3&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -noout -modulus -in server.cer| openssl md5&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl rsa -noout -modulus -in server.key| openssl md5&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;17.Check which certificate is installed on 443 or 8443 port on server&lt;br /&gt;&lt;br /&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl s_client -connect localhost:443&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;For&amp;nbsp; TLS 1.1, 1.2,1.3 check (tls1_1, tls1_2, tls1_3)&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl s_client -connect localhost or www.pki404.com:443 -tls1_2&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;18. Check installed SSL certificate on server with validity&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl s_client -connect localhost:443 -showcerts | openssl x509 -noout -dates&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;19.Check SSL status without any CA issuer error&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;b style=&quot;color: red; font-size: medium;&quot;&gt;openssl s_client -connect localhost:443 -CApath /etc/ssl/certs/&lt;/b&gt;&lt;/h3&gt;&lt;h3&gt;20.Generate a Self-Signed Certificate from an Existing Private Key and CSR&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509&amp;nbsp; -signkey private.key&amp;nbsp; -in csrfilename.csr&amp;nbsp; -req -days 365 -out certificate.crt&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;21.Generate a Self-Signed Certificate for 365 days&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl req -newkey rsa:2048 -nodes -keyout newprivate.key-x509 -days 365 -out selfsigncertificate.crt&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;22.Generate a CSR for an Existing Certificate and Private Key&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -x509toreq -in certificatename.crt -out csrfilename.csr -signkey privatekeyname.key&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;23.Encrypt an Unencrypted Private Key&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl rsa -des3&amp;nbsp; -in unencryptedfilename.key&amp;nbsp; -out encryptedfilename.key&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;24.Decrypt an Encrypted Private Key&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl rsa&amp;nbsp; -in encryptedfilename.key -out decryptedfilename.key&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;25.Generate ECC/ECDSA CSR&lt;br /&gt;&lt;br /&gt;First Generate private key&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl ecparam -out server.key -name prime256v1 -genkey&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;Next command to generate CSR using the private key&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl req -new -key server.key -out server.csr -sha256&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;26.View PKCS12/pfx/p12 information&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl pkcs12 -info -in filename.pfx&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;27.Check Private key status&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl rsa -in privatekeyname.key -check&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;28.Check certificate public key fingerprint (Public key SHA256 in Base64 format)for pinning for RSA certificate&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -in pki404rsa.crt -pubkey -noout | openssl rsa -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;For ECC/ECDSA&lt;/h3&gt;&lt;h3&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -in pki404ecc.crt -pubkey | openssl ec -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64&lt;/span&gt;&lt;/h3&gt;&lt;h3&gt;29.Check certificate hash&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -noout -hash -in server.crt&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;30.Check certificate issuer hash&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: 18.72px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -noout -issuer -issuer_hash -in server.crt&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;31.Check openssl version&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl version -a&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;32.Openssl encryption and decryption test with plain.txt cipher.txt&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;span style=&quot;color: red;&quot;&gt;echo &#39;my message&#39; &amp;gt; plain.txt&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Encrypt plain text to cipher text&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl enc -k yourpassword -aes256 -base64 -e -in plain.txt -out cipher.txt&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;cat cipher.txt&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Decrypt cipher text to plain text&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl enc -k yourpassword -aes256 -base64 -d -in cipher.txt -out plain.txt&lt;br /&gt;&lt;br /&gt;cat plain.txt&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;That&#39;s all for this blog see you in next one, do leave your comments if any more command needs to be added. :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/8616724509387777112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/12/openssl-most-useful-commands-in-pki.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/8616724509387777112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/8616724509387777112'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/12/openssl-most-useful-commands-in-pki.html' title='OPENSSL MOST USEFUL COMMANDS IN PKI'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-3690569698294906816</id><published>2021-08-18T14:59:00.043-07:00</published><updated>2021-08-19T10:32:11.787-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSR"/><category scheme="http://www.blogger.com/atom/ns#" term="IIS"/><category scheme="http://www.blogger.com/atom/ns#" term="SSL"/><category scheme="http://www.blogger.com/atom/ns#" term="TLS"/><title type='text'>CREATE CSR AND COMPLETE SSL TLS CERTIFICATE REQUEST RESPONSE IN IIS</title><content type='html'>&lt;p&gt;&amp;nbsp;Hi Everyone, Welcome to another exciting article by&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/&quot; target=&quot;_blank&quot;&gt;PKI404&lt;/a&gt;. Please follow the below steps thoroughly to Create CSR in IIS and complete the request response from CA.&lt;/p&gt;&lt;h1 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;CREATE CSR AND COMPLETE SSL TLS CERTIFICATE REQUEST RESPONSE IN IIS&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;&lt;b&gt;1.&lt;/b&gt; &lt;b&gt;Open Internet Information Services (IIS) Manager&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Click Start, Control Panel, System and Security, Administrative Tools, and then select Internet Information Services (IIS) Manager.&lt;/p&gt;&lt;p&gt;OR&lt;/p&gt;&lt;p&gt;Open Run - type - inetmgr&lt;/p&gt;&lt;p&gt;&lt;b&gt;2. Select the server where you want to generate the certificate&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the left Connections menu, select the server name (host) where you want to generate the request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1zyzgyu-Vo2hBdkuy0hr6W4tHJ5OWBTCG/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;604&quot; data-original-width=&quot;879&quot; height=&quot;220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHPO6yUPagp_MwSUpH_b5FxdXrD5PaSJYc9OYjdoPpsKkgcB_pySnsvtjeW5-yFUfY2OG9Khi6kLzYmiYsKh46R_PbjWHqHv32E5TVZ-gPqxvf75OzrI1Rf6LqoWfBoQK4EU0-izWB-6v/w320-h220/IIS-1.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;3. Navigate to Server Certificates&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the center menu, click the Server Certificates icon under the Security section near the bottom.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Z0penHVtxobh8orscwveqebbJuTXooX0/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;758&quot; data-original-width=&quot;1101&quot; height=&quot;220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLiYjNttdZKYfP_ltdLBm-LnTGsUgsTVs90zvn-R-lpc9tEbPA2zd78xnPPgn7jyUFVuMvJgczCItIit3VaF4lh_IL_tapGbYeTETP9Ymfy73t3sU_DHZZslAhyphenhyphenvAAvwohR0iIUvsbcQKj/w320-h220/IIS-2.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;4. Select Create a New Certificate&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the right Actions menu, click Create Certificate Request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1EhacSA-icWnagpezN5mJaeGAZOH_lY1g/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;757&quot; data-original-width=&quot;1098&quot; height=&quot;221&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAoJzWR4SbfuCOzJdn1o7CXJpmdwyBwZq1OyZSTxpF0gRMWNlnrXg3N9ZaOd431mUFO2jsoMVPFse3QjgWk703fNLMEBSkk3px0Xmczs-jzsYyajKwslAdDUeKrsb3R4_nAjFFqapNIdaa/w320-h221/IIS-3.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;5. Enter your CSR details&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the Distinguished Name Properties window, enter in the required CSR details and then click Next.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1gTpzvSG1Pk0qf_cHpBCY_KI_AVZ0gYY-/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;657&quot; data-original-width=&quot;862&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdsssN5ahdZrr0L2Agw1uSMW5Yw_Op8j1bbAdpJqG7c1VcbV-m_sPpPSy3NXr2ln1LkVsDq3thFQ338039vUcLgM2c4j4X18QJ8mo_Rtns_mEkJB1-l9GO6dl8ad-SYppkMB34O3bT5Grk/w320-h244/IIS-4.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Note: To avoid common mistakes when filling out your CSR details, for wildcard use *.domain.com&lt;/p&gt;&lt;p&gt;&lt;b&gt;6. Select a cryptographic service provider and bit length&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the Cryptographic Service Provider Properties window, select Microsoft RSA SChannel Cryptographic Provider and Bit Length of 2048, then click Next.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1fIzE_vBAGQiD7VFdP0X3ZC9_uRVK_JWy/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;656&quot; data-original-width=&quot;861&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPn75i7_TXbXtMiSFB404Mymg6x36McgQsWta5AmGqmflonDo-wZTLdudsfaRxwXOEpKTpmLTphA2j_3v9m9n3NHk9mXdVseGEZGZBHjFjSBfguKKRvnwiFjBkYpgHvl0BQxuAxBB6tCYX/w320-h244/IIS-5.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Note: Bit Length: 2048 is the current industry standard. You may choose a larger key size, but only if you have a requirement to do so, as longer key lengths increase latency and may reduce compatibility.&lt;/p&gt;&lt;p&gt;&lt;b&gt;7. Save the CSR&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Click Browse to specify the location where you want to save the CSR as a “.txt” file and click Finish.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1HQTQKGgHCOQBjvqapsqjeFsm1pLLOCn0/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;656&quot; data-original-width=&quot;860&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwVIDznkHbf2lfm14ONGOeeGLjarpxh71t92IDuSpM8C99-j1bkeLP33RMU_vW29nUQTU5n6v2ZSfyLK0OYAvErdCbXs_m_snVBiOIDZeSLzFuHIXzvz4U53FVdFt2Dk9wAKzt6aiNmnMQ/w320-h244/IIS-6.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;8. Generate the Order&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Locate and open the newly created CSR from the specified location you choose in a text editor such as Notepad and copy all the text including:&lt;/p&gt;&lt;p&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;/p&gt;&lt;p&gt;And&lt;/p&gt;&lt;p&gt;-----END CERTIFICATE REQUEST-----&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1gQz78TTYSoGLDQnM8jJflsBBhBiTx09e/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;534&quot; data-original-width=&quot;1032&quot; height=&quot;166&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhY-lirWE1Yig-51caksqJBXofnmonbPTJivuKayReSUNmRTb3DnL6W5huILcninJRGCplZ-TAVakKSFqfa4EgXCHBBKzcZtZMmahBIdErHSeJEUyD1_sC6FWco84mhPFB2PoGis-Yv3x1R/w320-h166/IIS-7.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Submit the CSR to Certificate Authority once you receive the SSL certificate follow the below steps.&lt;/p&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Install Your SSL Certificate&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;1. On the server where you created the CSR, save the SSL certificate .cer file (e.g., your_domain_com.cer) that you received from your CA.&lt;/p&gt;&lt;p&gt;2. Open Internet Information Services (IIS) Manager (click Start &amp;gt; Administrative Tools &amp;gt; Internet Information Services (IIS) Manager).&lt;/p&gt;&lt;p&gt;3. In the Connections pane, locate and click the server.&lt;/p&gt;&lt;p&gt;4. In the server Home page (center pane) under the IIS section, double-click Server Certificates.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1wAjz5scKsHNlakkX9JTRnH0jqIIBXec3/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center; text-indent: -24px;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;408&quot; data-original-width=&quot;530&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigTfWIaiIQv-YPC0UA9zpSnUowonBwGsZeNNh83qjJAwZ6sN-8kw06piXuQRZrlYpwA-iNn7D6UhSkrXfsPog1jVscMGDNLhCdhL_pmdUJ5T1cKPdmr3RgqWzRidCHdf0gJW-78NkbHnDG/w320-h246/IIS-8.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5. In the Actions menu (right pane), click Complete Certificate Request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Q9ehzxFN4Am-WNgmBm6ghWwgjsff-lZ1/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center; text-indent: -24px;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;408&quot; data-original-width=&quot;530&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjd7IQVDiaFvPOOSf2oWBg7xyIpOvHQmFja0DUFTVcXSGVOE2F6GYrQ22PFSlclPunwf-k50yRy2YgpaV0rMOTZD-pQHJTPFzIyZW5Oz5JRLBXaQNpy6A65CtAnd5P-c-zH9Z8Z2NKeB8xc/w320-h246/IIS-9.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;6. In the Complete Certificate Request wizard, on the Specify Certificate Authority Response page, provide the following information:&lt;/p&gt;&lt;p&gt;&amp;nbsp;CA&#39;s response file:&lt;/p&gt;&lt;p&gt;Click the&amp;nbsp; …&amp;nbsp; button to locate the .cer file you received from CA&lt;/p&gt;&lt;p&gt;(e.g., your_domain_com.cer).&lt;/p&gt;&lt;p&gt;Friendly name:&lt;/p&gt;&lt;p&gt;Type a friendly name for the certificate. This is not part of the certificate; instead, it is used to identify the certificate.&lt;/p&gt;&lt;p&gt;Note: We recommend that you add the issuing CA (e.g., Globalsign) and the expiration date to the end of your friendly name; for example, yoursite-globalsign-(expiration date). Doing this helps identify the issuer and expiration date for each certificate and also helps distinguish multiple certificates with the same domain name.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/10ZfsuBdIdVIuT73rsYmhfN_1im5zpBLm/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;404&quot; data-original-width=&quot;530&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijMTlRuuVM5GT3Qd8V8Mi9yM-Xzik4KVCG8GbzgftMj3EBpCOXcOd4k-Mzo3PQbU04A1rssQqqZOmjM7hAX65Xr0jVjDWKQ6Y2gdfuAvaM00ML_eu-nPe0OGb1axOBSpJMuZNFO0kU-8_8/w320-h244/IIS-10.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp; 7. Click OK to install the certificate.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/3690569698294906816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/08/create-csr-complete-request-ssl-tls-certificate-iis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/3690569698294906816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/3690569698294906816'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/08/create-csr-complete-request-ssl-tls-certificate-iis.html' title='CREATE CSR AND COMPLETE SSL TLS CERTIFICATE REQUEST RESPONSE IN IIS'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHPO6yUPagp_MwSUpH_b5FxdXrD5PaSJYc9OYjdoPpsKkgcB_pySnsvtjeW5-yFUfY2OG9Khi6kLzYmiYsKh46R_PbjWHqHv32E5TVZ-gPqxvf75OzrI1Rf6LqoWfBoQK4EU0-izWB-6v/s72-w320-h220-c/IIS-1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-1569498709682256498</id><published>2021-08-18T14:48:00.054-07:00</published><updated>2021-09-03T08:49:44.221-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="INTERMEDIATE"/><category scheme="http://www.blogger.com/atom/ns#" term="MMC"/><category scheme="http://www.blogger.com/atom/ns#" term="ROOT"/><category scheme="http://www.blogger.com/atom/ns#" term="SSL"/><title type='text'>IMPORT INTERMEDIATE AND ROOT CERTIFICATE IN MMC</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone, Welcome to another article by &lt;a href=&quot;https://www.pki404.com/&quot; target=&quot;_blank&quot;&gt;PKI404&lt;/a&gt;&amp;nbsp;for importing Intermediate and root certificate in MMC. Follow the steps below&lt;/p&gt;&lt;h2 style=&quot;clear: both; text-align: left;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: red; font-size: 14pt; line-height: 19.9733px; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;IMPORT THE INTERMEDIATE AND ROOT CERTIFICATE IN MMC&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f;&quot;&gt;Import Intermediate Certificate using MMC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h2&gt;&lt;div&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;1. Open MMC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;To open MMC (Microsoft Management Console), go to Run (Win+R), type&amp;nbsp;&lt;strong&gt;mmc&lt;/strong&gt;&amp;nbsp;&amp;amp; click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/11lQ6MdZHzASB_u0XGvin8kzKhu9-AdCP/view?usp=sharing&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;195&quot; data-original-width=&quot;400&quot; height=&quot;195&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcCaRJE3V4OZOZnygiU9PAaKEUMzK25E-oMZT5ACQBx3fg8Zv4K1vVPzH19U2ghpI6IS-CcOZZGZw3l0_CqxcpHzCFAHWDGWCOsG3nk9p1p3Uk-QeHM3SoKyZdYWkYEKrjgHZvBvHZf6I9/w400-h195/MMC-1.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;2.&amp;nbsp; Access Add or Remove Snap-Ins&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;In MMC, click on File &amp;amp; select the option ‘&lt;strong&gt;Add/Remove Snap-in&lt;/strong&gt;’&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1PT3---OdqlwFD8J6OhXL3n9KWaRyO3yM/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;264&quot; data-original-width=&quot;445&quot; height=&quot;238&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRyjCgi_APOtihxKWHL-eY0NWMLsZJZsEaRliKD9Df-sMq_9Hn-ejMSsa3s4y9OG8fXLx7m9mxW2mPeOGFxL0l7jCJ4eLYVMYOg6-nwxdFrX0Q8Qdb9NXFFO6YqcFTrIAFSNF4uYVV8qH/w400-h238/MMC-2.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;3. Select Add&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;In the window ‘Add/Remove Snap-ins,’ select the ‘Certificates’ option and click on the ‘&lt;strong&gt;Add&lt;/strong&gt;’ button&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1o8IWyvcHyL3OYV82R2s-skkV03NDpQ9Y/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;470&quot; data-original-width=&quot;675&quot; height=&quot;279&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMqvgMdrToOr6gC98ZydZsfQ0R3OkD85pNhbZC_mx9usRJ8sKKGgehfzB-vAz265hZ63Z1XohjbnskBBMfa-bvlYMlFe5Hv7I-uAnP9PElfAiWYDEY3eDzEkGythewz5H3rhL3Mrzoroj0/w400-h279/MMC-3.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;4.&amp;nbsp;Select ‘Computer Account’&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1vqqTpj8HKriFKDrN5KYxaxmnL602g1mf/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidJND0dNBSazBncUeTJuL3ieHnqsNPlZlsKHm5sT9x8vOMOTzov-m35zbqxdsZD0Fl4GKUmoSdzwhq3i56XyuI_PLhG5OM_AhRKsB6jDPK-nqYkoRVX63wNh9CqQ97LE6Rt26Qt9C8g7E6/w400-h290/MMC-4.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/h3&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;5.&amp;nbsp;Select ‘Local Computer’&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;This will indicate what the snap-in will manage&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1H9_P1Xwtt_-AaOflYb-R25sCic8MxW4c/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLgof33fRMzylvhbz4VZzFm15rqqavC6NUtLaC_8pzDh8bDVywIxuMy6_swIKIpFWs1qId8z-_AJOceKhHiZz7qUCPaG7kgkHWZcB6OAleX_Wb83Rgbu8dVkFRkDg8GtbvGhaDU2vbq0WA/w400-h290/MMC-5.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;6.&amp;nbsp;‘Certificates (Local Computer)’&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;This will have been selected automatically. Click ‘&lt;strong&gt;OK&lt;/strong&gt;’ to add in console&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Mcf3iO2xtvONP4WmUZ6YdCQhi3nLZRI0/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;470&quot; data-original-width=&quot;675&quot; height=&quot;279&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUveA2KDY4sx4_JYX3cO75cLK9yLX4Dp4SbLCjSHT-qcN95XlNWLFpBzIXZ7Zo-DLcAA-vaXB7P_3KTDRtqjSa_XUw_EIrqHwCstTu5awsKnlcg23xuX-WvCLUoEbczIN51y9TrQm8yxTW/w400-h279/MMC-6.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;7. Import Intermediate&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;For importing the Intermediate Certificate, right click on the ‘Intermediate Certification Authorities’ and then go to&amp;nbsp;&lt;strong&gt;All Tasks &amp;gt; Import&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Bo0c-zBcjiOkgk2L8t-cs72ljIEX8n-b/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;307&quot; data-original-width=&quot;535&quot; height=&quot;230&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD9iaOYQrL1RUGPZlEluAKZqu3CUHnZ6d5Fo7tse_k5nMV0TobBPwFqZlytFazyK8VR76s83dwYQrEA22ZMziKU0B1_7e73XsJg4DnReZfNhoNaa-LmziGSfXw4qgrlksxBUgarAsbwXSK/w400-h230/MMC-7.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;8.&amp;nbsp;Locate your Intermediate in the Certificate Import Wizard&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Browse for your Intermediate Certificate on your Machine. Click on&amp;nbsp;&lt;strong&gt;Next&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1DZ4L50sheJFcbwJf4rtE6dHu8Ciype6w/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;450&quot; data-original-width=&quot;500&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1SJH1286OjvZHomi1sIjPzvF1NbDvj_2PlavSAJ3qn5atM1sedqoNQP7rlAY4jvzocucWe2Pr0qChLSRTgoF2VRL_CSK5HFnybc_3L90PJbRH2YENEaFfCB90eB1nSy2XZWwHAugVByyN/w400-h360/MMC-8.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;9.&amp;nbsp;Automatically select the certificate store based on the type of certificate.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div&gt;&lt;span style=&quot;background-color: white; color: #4f4f4f; font-size: 11.5pt;&quot;&gt;You will be prompted to the window where you can place the certificate in Certificate Store. Leave without making any changes. If you have PKCS7 file with several certificates in it, you can go with ‘Automatically select the certificate store based on the type of certificate.’ Lastly, click on&amp;nbsp;&lt;/span&gt;&lt;strong style=&quot;background-color: white; color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Next&lt;/strong&gt;&lt;span style=&quot;background-color: white; color: #4f4f4f; font-size: 11.5pt;&quot;&gt;.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1-3JDq3fLSMkoRZREjcTBU8qlBcrQ5qvY/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2XEHOleedOgaXQW2DchrNNqByG_ToFbxn3eQUxpXzdllIKpy9mq-Pg1XuWK8-vwyMqUXqSKY0X-rJt6yhomG9FmfC43WGfc39_DDQUIBwqNLxm0TogQqnqbpRTR_ueHwjZ9APzwig2GAJ/w400-h290/MMC-9.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;10. Finish&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Click Finish, as certificate has been imported&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/16vveHJPOaF1u1YdU248GXEhvTG2JVtta/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;145&quot; data-original-width=&quot;227&quot; height=&quot;205&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvMeOrLTd_24QonfZ7fiNXyzB-sZNE55KZRlHRGnvmJqz3yAEN46BTQUQuCDx-cjDn_IQBgx46jGcpyd_kOgzlc6fJx86eJRl6Q99HJjWP0RDx7RjA_Qw5xopLj-mYooVIKsYnW42Etnr_/w320-h205/MMC-10.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;h1 style=&quot;background: white; margin: 0cm 0cm 7.5pt; text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f;&quot;&gt;Import Root Certificate using MMC&lt;/span&gt;&lt;/h1&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;To import&lt;strong&gt;&amp;nbsp;Root Certificates&lt;/strong&gt;&amp;nbsp;through MMC (Windows Microsoft Management Console), you must go through same process. Instead of right-clicking on ‘Intermediate Certification Authorities,’ right-click on the ‘&lt;strong&gt;Trusted Root Certification Authorities&lt;/strong&gt;’ and go to All Tasks &amp;gt; Import. The rest of the steps (steps 8 – 10) are the same for Root certificate.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1py5EM5CCHzq8xidQpV7HZjJlGx-fZbeB/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;305&quot; data-original-width=&quot;540&quot; height=&quot;226&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNxyqb1svjkssGsK_FwPvxfV2pf1kJF9syQ1Qyk7YoqUEpti-yByp_tN-TPsEmdTXglOlhsdLwyj7dOARfWzyVLP3rgqCO1C4P-G2gHzWMycaf15yMM72QAOax5LCuS0RBwddKjrgyhCqx/w400-h226/MMC-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Thank you for your time, Stay connected for upcoming articles. :)&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/1569498709682256498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/08/import-intermediate-root-certificate-mmc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1569498709682256498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1569498709682256498'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/08/import-intermediate-root-certificate-mmc.html' title='IMPORT INTERMEDIATE AND ROOT CERTIFICATE IN MMC'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcCaRJE3V4OZOZnygiU9PAaKEUMzK25E-oMZT5ACQBx3fg8Zv4K1vVPzH19U2ghpI6IS-CcOZZGZw3l0_CqxcpHzCFAHWDGWCOsG3nk9p1p3Uk-QeHM3SoKyZdYWkYEKrjgHZvBvHZf6I9/s72-w400-h195-c/MMC-1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-5973030694816822748</id><published>2021-08-18T14:24:00.027-07:00</published><updated>2021-09-03T08:47:54.216-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CSR"/><category scheme="http://www.blogger.com/atom/ns#" term="EXCHANGE"/><category scheme="http://www.blogger.com/atom/ns#" term="IIS"/><category scheme="http://www.blogger.com/atom/ns#" term="MMC"/><category scheme="http://www.blogger.com/atom/ns#" term="SSL"/><title type='text'>INSTALL SSL ON EXHANGE SERVER 2013 - 2016 VIA IIS</title><content type='html'>&lt;p&gt;&amp;nbsp;Hi Everyone, Welcome to another exciting article by &lt;a href=&quot;https://www.pki404.com/&quot; target=&quot;_blank&quot;&gt;PKI404&lt;/a&gt;. Please follow the below steps thoroughly to install ssl on Exchange server via IIS.&lt;/p&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;INSTALL SSL ON EXHANGE SERVER 2013 - 2016 VIA IIS&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;1.&lt;/b&gt;&amp;nbsp;&lt;b&gt;Open Internet Information Services (IIS) Manager&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Click Start, Control Panel, System and Security, Administrative Tools, and then select Internet Information Services (IIS) Manager.&lt;/p&gt;&lt;p&gt;OR&lt;/p&gt;&lt;p&gt;Open Run - type - inetmgr&lt;/p&gt;&lt;p&gt;&lt;b&gt;2. Select the server where you want to generate the certificate&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the left Connections menu, select the server name (host) where you want to generate the request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1zyzgyu-Vo2hBdkuy0hr6W4tHJ5OWBTCG/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;604&quot; data-original-width=&quot;879&quot; height=&quot;220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHPO6yUPagp_MwSUpH_b5FxdXrD5PaSJYc9OYjdoPpsKkgcB_pySnsvtjeW5-yFUfY2OG9Khi6kLzYmiYsKh46R_PbjWHqHv32E5TVZ-gPqxvf75OzrI1Rf6LqoWfBoQK4EU0-izWB-6v/w320-h220/IIS-1.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;3. Navigate to Server Certificates&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the center menu, click the Server Certificates icon under the Security section near the bottom.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Z0penHVtxobh8orscwveqebbJuTXooX0/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;758&quot; data-original-width=&quot;1101&quot; height=&quot;220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLiYjNttdZKYfP_ltdLBm-LnTGsUgsTVs90zvn-R-lpc9tEbPA2zd78xnPPgn7jyUFVuMvJgczCItIit3VaF4lh_IL_tapGbYeTETP9Ymfy73t3sU_DHZZslAhyphenhyphenvAAvwohR0iIUvsbcQKj/w320-h220/IIS-2.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;4. Select Create a New Certificate&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the right Actions menu, click Create Certificate Request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1EhacSA-icWnagpezN5mJaeGAZOH_lY1g/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;757&quot; data-original-width=&quot;1098&quot; height=&quot;221&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAoJzWR4SbfuCOzJdn1o7CXJpmdwyBwZq1OyZSTxpF0gRMWNlnrXg3N9ZaOd431mUFO2jsoMVPFse3QjgWk703fNLMEBSkk3px0Xmczs-jzsYyajKwslAdDUeKrsb3R4_nAjFFqapNIdaa/w320-h221/IIS-3.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;5. Enter your CSR details&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the Distinguished Name Properties window, enter in the required CSR details and then click Next.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1gTpzvSG1Pk0qf_cHpBCY_KI_AVZ0gYY-/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;657&quot; data-original-width=&quot;862&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdsssN5ahdZrr0L2Agw1uSMW5Yw_Op8j1bbAdpJqG7c1VcbV-m_sPpPSy3NXr2ln1LkVsDq3thFQ338039vUcLgM2c4j4X18QJ8mo_Rtns_mEkJB1-l9GO6dl8ad-SYppkMB34O3bT5Grk/w320-h244/IIS-4.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Note: To avoid common mistakes when filling out your CSR details, for wildcard use *.domain.com&lt;/p&gt;&lt;p&gt;&lt;b&gt;6. Select a cryptographic service provider and bit length&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In the Cryptographic Service Provider Properties window, select Microsoft RSA SChannel Cryptographic Provider and Bit Length of 2048, then click Next.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1fIzE_vBAGQiD7VFdP0X3ZC9_uRVK_JWy/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;656&quot; data-original-width=&quot;861&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPn75i7_TXbXtMiSFB404Mymg6x36McgQsWta5AmGqmflonDo-wZTLdudsfaRxwXOEpKTpmLTphA2j_3v9m9n3NHk9mXdVseGEZGZBHjFjSBfguKKRvnwiFjBkYpgHvl0BQxuAxBB6tCYX/w320-h244/IIS-5.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Note: Bit Length: 2048 is the current industry standard. You may choose a larger key size, but only if you have a requirement to do so, as longer key lengths increase latency and may reduce compatibility.&lt;/p&gt;&lt;p&gt;&lt;b&gt;7. Save the CSR&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Click Browse to specify the location where you want to save the CSR as a “.txt” file and click Finish.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1HQTQKGgHCOQBjvqapsqjeFsm1pLLOCn0/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;656&quot; data-original-width=&quot;860&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwVIDznkHbf2lfm14ONGOeeGLjarpxh71t92IDuSpM8C99-j1bkeLP33RMU_vW29nUQTU5n6v2ZSfyLK0OYAvErdCbXs_m_snVBiOIDZeSLzFuHIXzvz4U53FVdFt2Dk9wAKzt6aiNmnMQ/w320-h244/IIS-6.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;8. Generate the Order&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Locate and open the newly created CSR from the specified location you choose in a text editor such as Notepad and copy all the text including:&lt;/p&gt;&lt;p&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;/p&gt;&lt;p&gt;And&lt;/p&gt;&lt;p&gt;-----END CERTIFICATE REQUEST-----&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1gQz78TTYSoGLDQnM8jJflsBBhBiTx09e/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;create CSR in iis windows&quot; border=&quot;0&quot; data-original-height=&quot;534&quot; data-original-width=&quot;1032&quot; height=&quot;166&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhY-lirWE1Yig-51caksqJBXofnmonbPTJivuKayReSUNmRTb3DnL6W5huILcninJRGCplZ-TAVakKSFqfa4EgXCHBBKzcZtZMmahBIdErHSeJEUyD1_sC6FWco84mhPFB2PoGis-Yv3x1R/w320-h166/IIS-7.png&quot; title=&quot;create CSR in iis windows&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Submit the CSR to Certificate Authority once you receive the SSL certificate follow the below steps.&lt;/p&gt;&lt;h2&gt;&lt;b&gt;Install Your SSL Certificate&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;1. On the server where you created the CSR, save the SSL certificate .cer file (e.g., your_domain_com.cer) that you received from your CA.&lt;/p&gt;&lt;p&gt;2. Open Internet Information Services (IIS) Manager (click Start &amp;gt; Administrative Tools &amp;gt; Internet Information Services (IIS) Manager).&lt;/p&gt;&lt;p&gt;3. In the Connections pane, locate and click the server.&lt;/p&gt;&lt;p&gt;4. In the server Home page (center pane) under the IIS section, double-click Server Certificates.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1wAjz5scKsHNlakkX9JTRnH0jqIIBXec3/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center; text-indent: -24px;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;408&quot; data-original-width=&quot;530&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigTfWIaiIQv-YPC0UA9zpSnUowonBwGsZeNNh83qjJAwZ6sN-8kw06piXuQRZrlYpwA-iNn7D6UhSkrXfsPog1jVscMGDNLhCdhL_pmdUJ5T1cKPdmr3RgqWzRidCHdf0gJW-78NkbHnDG/w320-h246/IIS-8.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5. In the Actions menu (right pane), click Complete Certificate Request.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Q9ehzxFN4Am-WNgmBm6ghWwgjsff-lZ1/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center; text-indent: -24px;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;408&quot; data-original-width=&quot;530&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjd7IQVDiaFvPOOSf2oWBg7xyIpOvHQmFja0DUFTVcXSGVOE2F6GYrQ22PFSlclPunwf-k50yRy2YgpaV0rMOTZD-pQHJTPFzIyZW5Oz5JRLBXaQNpy6A65CtAnd5P-c-zH9Z8Z2NKeB8xc/w320-h246/IIS-9.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;6. In the Complete Certificate Request wizard, on the Specify Certificate Authority Response page, provide the following information:&lt;/p&gt;&lt;p&gt;&amp;nbsp;CA&#39;s response file:&lt;/p&gt;&lt;p&gt;Click the&amp;nbsp; …&amp;nbsp; button to locate the .cer file you received from CA&lt;/p&gt;&lt;p&gt;(e.g., your_domain_com.cer).&lt;/p&gt;&lt;p&gt;Friendly name:&lt;/p&gt;&lt;p&gt;Type a friendly name for the certificate. This is not part of the certificate; instead, it is used to identify the certificate.&lt;/p&gt;&lt;p&gt;Note: We recommend that you add the issuing CA (e.g., Globalsign) and the expiration date to the end of your friendly name; for example, yoursite-globalsign-(expiration date). Doing this helps identify the issuer and expiration date for each certificate and also helps distinguish multiple certificates with the same domain name.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://drive.google.com/file/d/10ZfsuBdIdVIuT73rsYmhfN_1im5zpBLm/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;install ssl in iis&quot; border=&quot;0&quot; data-original-height=&quot;404&quot; data-original-width=&quot;530&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijMTlRuuVM5GT3Qd8V8Mi9yM-Xzik4KVCG8GbzgftMj3EBpCOXcOd4k-Mzo3PQbU04A1rssQqqZOmjM7hAX65Xr0jVjDWKQ6Y2gdfuAvaM00ML_eu-nPe0OGb1axOBSpJMuZNFO0kU-8_8/w320-h244/IIS-10.gif&quot; title=&quot;install ssl in iis&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp; 7. Click OK to install the certificate.&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: red; font-size: 14pt; line-height: 107%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;INSTALL THE INTERMEDIATE AND ROOT CERTIFICATE IN MMC&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f;&quot;&gt;Import Intermediate Certificate using MMC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;1. Open MMC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;To open MMC (Microsoft Management Console), go to Run (Win+R), type&amp;nbsp;&lt;strong&gt;mmc&lt;/strong&gt;&amp;nbsp;&amp;amp; click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/11lQ6MdZHzASB_u0XGvin8kzKhu9-AdCP/view?usp=sharing&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;195&quot; data-original-width=&quot;400&quot; height=&quot;195&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcCaRJE3V4OZOZnygiU9PAaKEUMzK25E-oMZT5ACQBx3fg8Zv4K1vVPzH19U2ghpI6IS-CcOZZGZw3l0_CqxcpHzCFAHWDGWCOsG3nk9p1p3Uk-QeHM3SoKyZdYWkYEKrjgHZvBvHZf6I9/w400-h195/MMC-1.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;2.&amp;nbsp; Access Add or Remove Snap-Ins&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;In MMC, click on File &amp;amp; select the option ‘&lt;strong&gt;Add/Remove Snap-in&lt;/strong&gt;’&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1PT3---OdqlwFD8J6OhXL3n9KWaRyO3yM/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;264&quot; data-original-width=&quot;445&quot; height=&quot;238&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRyjCgi_APOtihxKWHL-eY0NWMLsZJZsEaRliKD9Df-sMq_9Hn-ejMSsa3s4y9OG8fXLx7m9mxW2mPeOGFxL0l7jCJ4eLYVMYOg6-nwxdFrX0Q8Qdb9NXFFO6YqcFTrIAFSNF4uYVV8qH/w400-h238/MMC-2.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;3. Select Add&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;In the window ‘Add/Remove Snap-ins,’ select the ‘Certificates’ option and click on the ‘&lt;strong&gt;Add&lt;/strong&gt;’ button&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1o8IWyvcHyL3OYV82R2s-skkV03NDpQ9Y/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;470&quot; data-original-width=&quot;675&quot; height=&quot;279&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMqvgMdrToOr6gC98ZydZsfQ0R3OkD85pNhbZC_mx9usRJ8sKKGgehfzB-vAz265hZ63Z1XohjbnskBBMfa-bvlYMlFe5Hv7I-uAnP9PElfAiWYDEY3eDzEkGythewz5H3rhL3Mrzoroj0/w400-h279/MMC-3.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;4.&amp;nbsp;Select ‘Computer Account’&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1vqqTpj8HKriFKDrN5KYxaxmnL602g1mf/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidJND0dNBSazBncUeTJuL3ieHnqsNPlZlsKHm5sT9x8vOMOTzov-m35zbqxdsZD0Fl4GKUmoSdzwhq3i56XyuI_PLhG5OM_AhRKsB6jDPK-nqYkoRVX63wNh9CqQ97LE6Rt26Qt9C8g7E6/w400-h290/MMC-4.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;5.&amp;nbsp;Select ‘Local Computer’&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;This will indicate what the snap-in will manage&lt;br /&gt;&lt;/span&gt;&lt;a href=&quot;https://drive.google.com/file/d/1H9_P1Xwtt_-AaOflYb-R25sCic8MxW4c/view?usp=sharing&quot; style=&quot;background-color: transparent; clear: left; display: inline; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLgof33fRMzylvhbz4VZzFm15rqqavC6NUtLaC_8pzDh8bDVywIxuMy6_swIKIpFWs1qId8z-_AJOceKhHiZz7qUCPaG7kgkHWZcB6OAleX_Wb83Rgbu8dVkFRkDg8GtbvGhaDU2vbq0WA/w400-h290/MMC-5.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;6.&amp;nbsp;‘Certificates (Local Computer)’&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;This will have been selected automatically. Click ‘&lt;strong&gt;OK&lt;/strong&gt;’ to add in console&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Mcf3iO2xtvONP4WmUZ6YdCQhi3nLZRI0/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;470&quot; data-original-width=&quot;675&quot; height=&quot;279&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUveA2KDY4sx4_JYX3cO75cLK9yLX4Dp4SbLCjSHT-qcN95XlNWLFpBzIXZ7Zo-DLcAA-vaXB7P_3KTDRtqjSa_XUw_EIrqHwCstTu5awsKnlcg23xuX-WvCLUoEbczIN51y9TrQm8yxTW/w400-h279/MMC-6.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;7. Import Intermediate&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;For importing the Intermediate Certificate, right click on the ‘Intermediate Certification Authorities’ and then go to&amp;nbsp;&lt;strong&gt;All Tasks &amp;gt; Import&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Bo0c-zBcjiOkgk2L8t-cs72ljIEX8n-b/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;307&quot; data-original-width=&quot;535&quot; height=&quot;230&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD9iaOYQrL1RUGPZlEluAKZqu3CUHnZ6d5Fo7tse_k5nMV0TobBPwFqZlytFazyK8VR76s83dwYQrEA22ZMziKU0B1_7e73XsJg4DnReZfNhoNaa-LmziGSfXw4qgrlksxBUgarAsbwXSK/w400-h230/MMC-7.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;8.&amp;nbsp;Locate your Intermediate in the Certificate Import Wizard&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Browse for your Intermediate Certificate on your Machine. Click on&amp;nbsp;&lt;strong&gt;Next&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1DZ4L50sheJFcbwJf4rtE6dHu8Ciype6w/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;450&quot; data-original-width=&quot;500&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1SJH1286OjvZHomi1sIjPzvF1NbDvj_2PlavSAJ3qn5atM1sedqoNQP7rlAY4jvzocucWe2Pr0qChLSRTgoF2VRL_CSK5HFnybc_3L90PJbRH2YENEaFfCB90eB1nSy2XZWwHAugVByyN/w400-h360/MMC-8.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;9.&amp;nbsp;Automatically select the certificate store based on the type of certificate.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;span style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;You will be prompted to the window where you can place the certificate in Certificate Store. Leave without making any changes. If you have PKCS7 file with several certificates in it, you can go with ‘Automatically select the certificate store based on the type of certificate.’ Lastly, click on&amp;nbsp;&lt;/span&gt;&lt;strong style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Next&lt;/strong&gt;&lt;span style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1-3JDq3fLSMkoRZREjcTBU8qlBcrQ5qvY/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;380&quot; data-original-width=&quot;525&quot; height=&quot;290&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2XEHOleedOgaXQW2DchrNNqByG_ToFbxn3eQUxpXzdllIKpy9mq-Pg1XuWK8-vwyMqUXqSKY0X-rJt6yhomG9FmfC43WGfc39_DDQUIBwqNLxm0TogQqnqbpRTR_ueHwjZ9APzwig2GAJ/w400-h290/MMC-9.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h3 style=&quot;background: white; margin-bottom: 3.75pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 3.75pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 15pt; line-height: 21.4px;&quot;&gt;10. Finish&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;Click Finish, as certificate has been imported&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/16vveHJPOaF1u1YdU248GXEhvTG2JVtta/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;145&quot; data-original-width=&quot;227&quot; height=&quot;205&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvMeOrLTd_24QonfZ7fiNXyzB-sZNE55KZRlHRGnvmJqz3yAEN46BTQUQuCDx-cjDn_IQBgx46jGcpyd_kOgzlc6fJx86eJRl6Q99HJjWP0RDx7RjA_Qw5xopLj-mYooVIKsYnW42Etnr_/w320-h205/MMC-10.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;h1 style=&quot;background: white; margin: 0cm 0cm 7.5pt; text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f;&quot;&gt;Import Root Certificate using MMC&lt;/span&gt;&lt;/h1&gt;&lt;h2 style=&quot;background: white; margin-bottom: 7.5pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt;&quot;&gt;&lt;div style=&quot;font-size: medium; font-weight: 400;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #4f4f4f; font-size: 11.5pt;&quot;&gt;To import&lt;strong&gt;&amp;nbsp;Root Certificates&lt;/strong&gt;&amp;nbsp;through MMC (Windows Microsoft Management Console), you must go through same process. Instead of right-clicking on ‘Intermediate Certification Authorities,’ right-click on the ‘&lt;strong&gt;Trusted Root Certification Authorities&lt;/strong&gt;’ and go to All Tasks &amp;gt; Import. The rest of the steps (steps 8 – 10) are the same for Root certificate.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1py5EM5CCHzq8xidQpV7HZjJlGx-fZbeB/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;305&quot; data-original-width=&quot;540&quot; height=&quot;226&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNxyqb1svjkssGsK_FwPvxfV2pf1kJF9syQ1Qyk7YoqUEpti-yByp_tN-TPsEmdTXglOlhsdLwyj7dOARfWzyVLP3rgqCO1C4P-G2gHzWMycaf15yMM72QAOax5LCuS0RBwddKjrgyhCqx/w400-h226/MMC-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/h2&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Now Login to your Exchamge Web Console and follow the below steps&lt;br /&gt;&lt;br /&gt;&lt;p style=&quot;background: white; margin-bottom: 11.25pt; margin-left: 0cm; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 11.25pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #373737; font-size: 13pt; line-height: 107%; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-language: EN-US;&quot;&gt;Enable the certificate by going back to the certificate section of the
Exchange Admin, click on the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;border: 1pt none windowtext; mso-border-alt: none windowtext 0cm; padding: 0cm;&quot;&gt;edit&lt;/span&gt;&lt;/b&gt;&amp;nbsp;button for
highlighted installed certificate from IIS.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/18lPF9Awdd7N0vGu1ySEkC9cvecLjkw3y/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;394&quot; data-original-width=&quot;548&quot; height=&quot;288&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjE6fxjZzR9cFHgMhD_QwEuYpeap9ZtU9XVU_Er5bwod5VXMW3EysAiA6fV1MEkVAYHoXX33O01BOluSUZSftSJFHeOIJ8jnZ3ZDpH1MGP6lb0_GzqIZie_NZ7HrN_Ehsnb9g73ezIKmmeW/w400-h288/Exchange-1.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span face=&quot;Arial, sans-serif&quot; style=&quot;color: #373737;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 13pt; line-height: 107%;&quot;&gt;You will have a screen where you have to click on&amp;nbsp;&lt;b&gt;&lt;span style=&quot;border: 1pt none windowtext; mso-border-alt: none windowtext 0cm; padding: 0cm;&quot;&gt;Services&lt;/span&gt;&lt;/b&gt;&amp;nbsp;tab on the left side, it will give you
options of different services that you wish to enable. Click&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-size: 13pt;&quot;&gt;on&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-size: 13pt;&quot;&gt;&lt;span style=&quot;border: 1pt none windowtext; mso-border-alt: none windowtext 0cm; padding: 0cm;&quot;&gt;save&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 13pt;&quot;&gt;&amp;nbsp;button.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span face=&quot;Arial, sans-serif&quot; style=&quot;color: #373737;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 13pt; line-height: 107%;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/16izBsg7Z5HkFFLLKaSflw2Ojw1901J9T/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;386&quot; data-original-width=&quot;548&quot; height=&quot;281&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnGACV90y7nKscoSrXdER42nwppNFqWgEYXxAOTGxWOuSQOf68vIQTVzMxaOjsl2GsWMlUMmHCkz2sFfkk7oHt0YAs5ad52lhiSlq8okX94IFWwuQ94ZWNX3ZCu-4YbTsVUVQeV2-wvHsl/w400-h281/Exchange-2.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm; margin-left: 18.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 0cm 18pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-align: justify; text-indent: -18pt; vertical-align: baseline;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #373737; font-family: Wingdings; font-size: 10pt; mso-bidi-font-family: Wingdings; mso-bidi-font-size: 13.0pt; mso-fareast-font-family: Wingdings;&quot;&gt;§&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #373737; font-size: 13pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Your SSL certificate is finally installed and
ready to use.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 13pt; line-height: 107%;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Thats All for now stay tuned for more such articles :)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/5973030694816822748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/08/install-ssl-on-exchange-server-2013-2016-via-iis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/5973030694816822748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/5973030694816822748'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/08/install-ssl-on-exchange-server-2013-2016-via-iis.html' title='INSTALL SSL ON EXHANGE SERVER 2013 - 2016 VIA IIS'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHPO6yUPagp_MwSUpH_b5FxdXrD5PaSJYc9OYjdoPpsKkgcB_pySnsvtjeW5-yFUfY2OG9Khi6kLzYmiYsKh46R_PbjWHqHv32E5TVZ-gPqxvf75OzrI1Rf6LqoWfBoQK4EU0-izWB-6v/s72-w320-h220-c/IIS-1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-4820709090067589335</id><published>2021-08-18T11:35:00.003-07:00</published><updated>2021-08-19T10:05:34.515-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="JKS"/><category scheme="http://www.blogger.com/atom/ns#" term="orapki"/><category scheme="http://www.blogger.com/atom/ns#" term="pfx"/><category scheme="http://www.blogger.com/atom/ns#" term="PKCS12"/><title type='text'>HOW TO CONVERT JKS TO WALLET USING ORAPKI</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone!! Welcome to another blog by &lt;a href=&quot;https://www.pki404.com&quot;&gt;PKI404&lt;/a&gt;&amp;nbsp; where i will walk you through how to create JKS file then JKS (Java keystore) to wallet for oracle wallet manager. So let&#39;s start without any further due.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;1.&amp;nbsp; First step is to create a pfx and then p12 file or directly create p12 file.&lt;/p&gt;&lt;p&gt;See steps here :&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/create-pfx-pkcs12-using-certificate-privatekey.html&quot; target=&quot;_blank&quot;&gt;How to create pfx file&lt;/a&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;openssl pkcs12 -in ewallet.pfx -out ewallet.pem&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;then pem to p12&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;openssl pkcs12 -export -in ewallet.pem -out ewallet.p12
-name &quot;server&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Keep the password :&amp;nbsp;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;font-size: 11pt;&quot;&gt;&lt;b&gt;Password@123&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: 14.6667px;&quot;&gt;2. Now Convert pfx to JKS&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: 14.6667px;&quot;&gt;See here :&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/create-jks-file-java-keystoretomcat.html&quot; target=&quot;_blank&quot;&gt;How to create JKS file&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Use the below command to create pfx to JKS file.&lt;/p&gt;&lt;p&gt;In windows open /Program files/ JAVA/ JDK/JRE /bin in Admin command prompt and run below command&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background-color: white; color: red; font-size: 14px;&quot;&gt;keytool -importkeystore -srckeystore &quot;&lt;/span&gt;&lt;span face=&quot;Open Sans, sans-serif&quot; style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;C:\Users\pki404\Desktop\&lt;/span&gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background-color: white; color: red; font-size: 14px;&quot;&gt;ewallet.p12&quot; -srcstoretype pkcs12 -destkeystore&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;color: red; font-size: 14px;&quot;&gt;C:\Users\pki404\Desktop\&lt;/span&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background-color: white; color: red; font-size: 14px;&quot;&gt;certificate.jks&quot; -deststoretype JKS&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;Open Sans, sans-serif&quot;&gt;&lt;span style=&quot;background-color: white; font-size: 14px;&quot;&gt;In Linux run the command anywhere to convert P12/pfx to JKS&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;Open Sans, sans-serif&quot;&gt;&lt;span style=&quot;background-color: white; font-size: 14px;&quot;&gt;3. Now open ORAPKI bin folder it should have orapki tool.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span face=&quot;Open Sans, sans-serif&quot;&gt;&lt;span style=&quot;background-color: white; font-size: 14px;&quot;&gt;Open command prompt with orapki tool path and run below command to create a empty wallet.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;orapki wallet create -wallet ewallet -auto_login -pwd
Password@123&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Now Import JKS into created empty wallet&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;font-size: 11pt; line-height: 107%; mso-ansi-language: EN-IN; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;orapki
wallet jks_to_pkcs12 -wallet ewallet -pwd Password@123 -keystore
D:\servertest.jks -jkspwd Password@123&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;font-size: 11pt; line-height: 107%; mso-ansi-language: EN-IN; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;See the example in below screenshot for creating wallet and importing JKS in wallet&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1yTDcjuQ1_kt8VnV9v7GELx7WyDfjAloI/view?usp=sharing&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Orapki jks to ewallet&quot; border=&quot;0&quot; data-original-height=&quot;847&quot; data-original-width=&quot;1856&quot; height=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAJroEaDOW2Q-V1pmOWZurTSBMKoOjEMxGDqr-IEzcam9v7XA2PbIVV9ENbQ1F7sq2KY2nKk1hYkyd4Uve0KJWu_BYT0U4kTROecZBoW5_nQNl6joBRjJz5Vy9InNq3xnJofpoldWjEUiN/w640-h293/orapki.png&quot; title=&quot;Orapki jks to ewallet&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;font-size: 11pt; line-height: 107%; mso-ansi-language: EN-IN; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;Now that wallet has created Open Oracle wallet manager (OWM) and open the ewallet.p12 and save the wallet.&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;font-size: 11pt; line-height: 107%; mso-ansi-language: EN-IN; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;It should be in ready status.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;font-size: 11pt; line-height: 107%; mso-ansi-language: EN-IN; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;&quot;&gt;Stay tuned for more blogs like this :)&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;span face=&quot;Open Sans, sans-serif&quot;&gt;&lt;span style=&quot;background-color: white; font-size: 14px;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/4820709090067589335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/08/how-to-convert-jks-to-ewallet-using-orapki.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4820709090067589335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4820709090067589335'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/08/how-to-convert-jks-to-ewallet-using-orapki.html' title='HOW TO CONVERT JKS TO WALLET USING ORAPKI'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAJroEaDOW2Q-V1pmOWZurTSBMKoOjEMxGDqr-IEzcam9v7XA2PbIVV9ENbQ1F7sq2KY2nKk1hYkyd4Uve0KJWu_BYT0U4kTROecZBoW5_nQNl6joBRjJz5Vy9InNq3xnJofpoldWjEUiN/s72-w640-h293-c/orapki.png" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-973301593473009395</id><published>2021-07-28T13:20:00.004-07:00</published><updated>2021-07-28T14:04:28.166-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apache"/><category scheme="http://www.blogger.com/atom/ns#" term="CSR"/><category scheme="http://www.blogger.com/atom/ns#" term="ECC"/><category scheme="http://www.blogger.com/atom/ns#" term="ECDSA"/><category scheme="http://www.blogger.com/atom/ns#" term="openssl"/><title type='text'>ECC CSR GENERATION WITH OPENSSL</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone, Welcome to another blog on PKI404 about ECC CSR Generation with openssl. So let&#39;s start without any further due.&lt;/p&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;b style=&quot;text-align: center;&quot;&gt;ECC CSR GENERATION WITH OPENSSL&lt;/b&gt;&lt;/h2&gt;&lt;p style=&quot;text-align: left;&quot;&gt;First Step is to check curves and select as per your usage&lt;br /&gt;&lt;/p&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b style=&quot;text-align: center;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 16pt; line-height: 107%;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;openssl ecparam -list_curves&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;b style=&quot;text-align: center;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 16pt; line-height: 107%;&quot;&gt;prime256v1 is fine&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;Now Follow the below steps.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;if you have apache server installed then you may go to Apache/bin and use openssl tool else download from below Link&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;Download openssl -&amp;nbsp;&lt;span style=&quot;color: #2b00fe;&quot;&gt;https://www.openssl.org/source/&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;Once download open in command prompt in administrator and go to openssl/bin and run below command&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: Arial;&quot;&gt;1.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;At the prompt, type the following command to generate an ECC
private key using the OpenSSL ecparam tool to generate your&amp;nbsp;&lt;i&gt;.key&lt;/i&gt;&amp;nbsp;file:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;openssl ecparam -out&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;server&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;.key
-name&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;prime256v1&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;&amp;nbsp;-genkey&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Where&amp;nbsp;&lt;/span&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;server&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;is the name of your server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-left: 51pt;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note:&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;Recommended ECC key size is 256-bit. If greater
encryption strength is required, your other private key option is secp384r1.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: Arial;&quot;&gt;2.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Save (backup) the generated&amp;nbsp;&lt;i&gt;.key&lt;/i&gt;&amp;nbsp;file, making
sure to note its location. This private key is required later for ECC SSL
Certificate installation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: Arial;&quot;&gt;3.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Next, type the following command to generate a ECC certificate
signing request (CSR):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For Linux&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;openssl req -new -key&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;server&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;.key
-out&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;server&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;.csr -sha256&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;for winodows run in openssl bin folder with below command&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;openssl req -new -key&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;server&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;.key
-out&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;server&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;.csr -sha256 -config openssl.cnf&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;Make Sure you copy
openssl.cnf file from openssl directory to its bin folder in windows only.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Where&amp;nbsp;&lt;/span&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;server&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;is the name of your server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: Arial;&quot;&gt;4.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As you are prompted, enter the following information:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For fields that are not required, you can enter
&#39;.&#39; and those fields will be left blank.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Country Name (2 letter code) [AU]&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;:&amp;nbsp; &lt;b&gt;IN&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;Type the two letter code for the country where your company is legally located.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;State or Province Name (full name) [Some-State]&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;: &lt;b&gt;Delhi&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;Type the name of the state or providence where your company is legally located.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Locality Name (eg, city) [ ]&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;: &lt;/span&gt;&lt;b style=&quot;color: #333333;&quot;&gt;New Delhi&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;Type the name of the city where your company is legally located.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Organization Name (eg, company) [PKI404 Pvt Ltd]&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333; font-size: 14px;&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;color: #333333; font-size: 14px; white-space: pre;&quot;&gt;	&lt;/span&gt;&lt;b&gt;PKI404&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333; font-size: 14px;&quot;&gt;Type your company&#39;s legally registered name.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Organizational Unit Name (eg, section) [ ]&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;: &lt;/span&gt;&lt;b style=&quot;color: #333333;&quot;&gt;IT&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;Type the name of the department within your organization that you want to appear on the ECC SSL Certificate.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 14px;&quot;&gt;Common Name (e.g. server FQDN) [ ]&lt;/span&gt;&lt;span style=&quot;color: #333333; font-size: 14px;&quot;&gt;: &lt;/span&gt;&lt;b style=&quot;font-size: 14px;&quot;&gt;www.pki404.com or *.pki404.com&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;Type the fully qualified domain name (i.e. www.example.com) for the site that you are securing.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Note&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;color: #333333;&quot;&gt;: If you are generating CSR for a Wildcard SSL Certificate, your common name should start with an asterisk (e.g., &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 14px;&quot;&gt;&lt;b&gt;*.example.com&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333; font-size: 14px;&quot;&gt;).&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-bottom: 7.5pt; margin-left: 51.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 51pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: Arial;&quot;&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: Arial; text-indent: -18pt;&quot;&gt;6.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #333333;&quot;&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; text-indent: -18pt;&quot;&gt;Now, open the&amp;nbsp;&lt;i&gt;.csr&lt;/i&gt;&amp;nbsp;file with a text editor and
copy the text of your CSR, including the&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;-----BEGIN NEW CERTIFICATE REQUEST-----&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; text-indent: -18pt;&quot;&gt;&amp;nbsp;and&lt;/span&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: red; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; text-indent: -18pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;-----END NEW CERTIFICATE REQUEST----&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;-&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; text-indent: -18pt;&quot;&gt;&amp;nbsp;tags, and paste it into order form.&lt;/span&gt;&lt;span style=&quot;color: #333333; font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #333333; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This is how your csr file looks.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 16.5pt; margin-left: 51pt;&quot;&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;/b&gt;&lt;span style=&quot;font-family: Courier New;&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;b&gt;MIICrTCCAZUCAQAwaDELMAkGA1UEBhMCSU4xDjAMBgNVBAgMBURlbGhpMRIwEAYD&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;VQQHDAlOZXcgRGVsaGkxEDAOBgNVBAoMB1BLSSA0MDQxCzAJBgNVBAsMAkNBMRYw&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;FAYDVQQDDA1QS0kgNDA0IFN1YkNBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;CgKCAQEA+JiR6HoSazhUkeAye2TvVkQ/xOt+SmKvDizf47RI9oW3aeYNQKP4UGm3&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;FCa9JRuLoNyY72DSlXm0L3u7VUbvUQGF+sKkLV+dG80/r5M5UjZ2odQCQLi18Nt9&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;ilSwgVIFQjEZCMa+d4ts8vvUFfmbkBaM+Ce5Cu8mtQqcc8VcFnvPOTu8KCrJMrzh&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;U5cOIS05BpJnMae7lYxSK3zdDoecDH1VYV9vsKzyfqicOXVzm1tkw9WpDHLTvxQu&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;GgE9Gm7AIZitRmbTPh9cUZKbKqVNrh+8gmjx3LSk3p6JiHzJicqALRirowN9x6ot&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;iUxN+rkUsMc0LJ+a5bFHjBQ9PegbxwIDAQABoAAwDQYJKoZIhvcNAQELBQADggEB&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;AFw+Dtg/o8QGVusabLHAQ+3BK6SLWOXNN2od0LIyR3r4GgRwGnMzm1U7cyivKhp+&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;zyZi4kHO7d1V5Jhf3ICrtbKm41ci3f2UpIfoa3mPMw1h9SUc425m2oODNMCNbtpw&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;XkLp0VPpo12q6EkkYTwsxbUpX7yopmXx+GS5RQorw8O6YtjX0Hsuv1q210PHoTt+&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;0srpkeb51nHUhHMTOFgtsre9b+iG2jW0T6MX+W8ebTZPFERIkKqENayaCl7Xl98C&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;kxIWljG99gwjm+UqJrnFZfXlgO2BZbeov1yIZUE9UC1ntGwodxTXLwKjXLLgNFUk&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;a0GiMRo+C+Vm/uj12Grw894=&lt;br /&gt;&lt;/b&gt;&lt;b style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 14px;&quot;&gt;-----END CERTIFICATE REQUEST-----&lt;/b&gt;&lt;span style=&quot;background-color: transparent;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Check csr content&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;For linux&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;openssl req -in&amp;nbsp; serverecc.csr -noout -text&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;for windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;openssl req -in&amp;nbsp; serverecc.csr -noout -text -config
openssl.cnf&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;



















































&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;output in windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: left;&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzoKs_AWk7mkH0ORECMkW2-DsB6ACJPezWQAGXl7zwOZ_H2Zvu1E7dohf5xbTN4aZJ69SwTekN5DU9iaAQhgAQJ-k7e-PuSzVA69uuDiqmVQYSPhOKBaX5_LyvfHhnPE6K0lqiydUjIV-C/s664/ECC+CSR+output.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;415&quot; data-original-width=&quot;664&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzoKs_AWk7mkH0ORECMkW2-DsB6ACJPezWQAGXl7zwOZ_H2Zvu1E7dohf5xbTN4aZJ69SwTekN5DU9iaAQhgAQJ-k7e-PuSzVA69uuDiqmVQYSPhOKBaX5_LyvfHhnPE6K0lqiydUjIV-C/w640-h400/ECC+CSR+output.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Also read &lt;/span&gt;:-&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/generate-csr-on-linux-server.html&quot; target=&quot;_blank&quot;&gt;How to generate Rsa CSR with openssl&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Stay tuned for more such blogs. See you in next one :)&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/973301593473009395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/ecc-csr-generation-with-openssl.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/973301593473009395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/973301593473009395'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/ecc-csr-generation-with-openssl.html' title='ECC CSR GENERATION WITH OPENSSL'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzoKs_AWk7mkH0ORECMkW2-DsB6ACJPezWQAGXl7zwOZ_H2Zvu1E7dohf5xbTN4aZJ69SwTekN5DU9iaAQhgAQJ-k7e-PuSzVA69uuDiqmVQYSPhOKBaX5_LyvfHhnPE6K0lqiydUjIV-C/s72-w640-h400-c/ECC+CSR+output.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-3785602371796900666</id><published>2021-07-20T13:19:00.002-07:00</published><updated>2021-12-11T06:00:11.166-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apache"/><category scheme="http://www.blogger.com/atom/ns#" term="jboss"/><category scheme="http://www.blogger.com/atom/ns#" term="keytool"/><category scheme="http://www.blogger.com/atom/ns#" term="openssl"/><category scheme="http://www.blogger.com/atom/ns#" term="orapki"/><category scheme="http://www.blogger.com/atom/ns#" term="sapgenpse"/><category scheme="http://www.blogger.com/atom/ns#" term="Tomcat"/><title type='text'>Most common commands for openssl keytool sapgenpse orapki</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone!! Welcome to another exciting article by &lt;b&gt;&lt;a href=&quot;https://www.pki404.com&quot; target=&quot;_blank&quot;&gt;PKI404&lt;/a&gt;&lt;/b&gt;, In this article we will see most common command used in openssl for pfx and key files on apache and iis web servers , keytool for java based servers like jboss, tomcat etc , sapgenpse for sap servers , orapki for oracle wallet manager. So lets start without any further due.&lt;/p&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Most common commands for openssl keytool sapgenpse orapki&lt;/b&gt;&lt;/h2&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Most Common Openssl Commands&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;To Generate CSR and Private key&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl req -new -newkey rsa:2048 -sha256 -nodes -out domainname.csr -keyout privatekey.key&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Convert PEM to DER:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -outform der -in certificate.pem -out certificate.der&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Convert DER to PEM:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -inform der -in certificate.der -out certificate.pem&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Convert PEM/CRT to P7B:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b -certfile CACert.crt&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Convert P7B to PEM/CRT:&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: red;&quot;&gt;openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Convert PEM/CRT &amp;amp; Private Key to PFX/P12:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Convert P7B to PFX: (first convert p7b to pem/crt from above commands then use below)&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx -certfile CACert.cer&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Convert PFX to PEM/CRT and Private Key&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -in certificate.pfx -out certificate.pem -nodes&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;OpenSSL command to remove private key password&lt;/p&gt;&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Or&amp;nbsp;&lt;/p&gt;&lt;p&gt;To convert simple private to&amp;nbsp; RSA&amp;nbsp; private.key&lt;/p&gt;&lt;p&gt;&lt;b style=&quot;color: red;&quot;&gt;openssl rsa -in file.key -out newfile.key&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Create RSA Private Key from PFX (private key without any password)&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -in certificate.pfx -nocerts -nodes | openssl rsa -out newrsaprivatekey.key&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;To View CSR contents&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl req -in mycsr.csr -noout -text&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;To view Certificate X509 contents (.cer/,crt/.pem files)&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl x509 -in certificate.crt -text -noout&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;To Match private key, CSR and certificate (output of all three commands should be the same)&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkey -in privateKey.key -pubout -outform pem | sha256sum&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -in domaincertificate.cer -pubkey -noout -outform pem | sha256sum&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl req -in CSR.csr -pubkey -noout -outform pem | sha256sum&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;openssl command print out md5 checksums of the certificate and key&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl x509 -noout -modulus -in server.cer| openssl md5&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl rsa -noout -modulus -in server.key| openssl md5&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Most Common Java Keytool Commands&lt;/b&gt;&lt;/h4&gt;&lt;p&gt;Generate a Java keystore and key pair:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -genkey -alias mydomainname -keyalg RSA -keystore keystorefilename.jks -keysize 2048&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Generate a certificate signing request (CSR) for an existing Java keystore:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -certreq -alias mydomainname -keystore keystorefilename.jks -file mydomainname.csr&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Generate a keystore and self-signed certificate:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -genkey -keyalg RSA -alias selfsigned -keystore keystorefilename.jks -storepass password -validity 360 -keysize 2048&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Certificate import commands in keystore: (.crt and .cer is same even .pem can be used)&lt;/p&gt;&lt;p&gt;Import a root CA certificate to an existing Java keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -import -trustcacerts -alias root -file root.cer -keystore keystorefilename.jks&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Import a intermediate CA certificate to an existing Java keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore keystorefilename.jks&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Import a signed SSL primary certificate to an existing Java keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -import -trustcacerts -alias mydomainname -file mydomainname.crt -keystore keystorefilename.jks&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;Java Keytool Commands for Conversion:&lt;/h4&gt;&lt;p&gt;If you need to change the type of keystore.&lt;/p&gt;&lt;p&gt;PFX keystore to JKS keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -importkeystore -srckeystore mypfxfile.pfx -srcstoretype pkcs12 -destkeystore newjkskeystore.jks -deststoretype JKS&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;JKS keystore to PFX keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -importkeystore -srckeystore myjksfile.jks -srcstoretype JKS -deststoretype PKCS12 -destkeystore newpfxkeystore.pfx&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;To View JKS java keystore contents&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Keytool -v -list -keystore keystorefilename.jks&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;For only Alias name and entries&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Keytool -list -keystore keystorefilename.jks&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Other Java Keytool Commands:&lt;/p&gt;&lt;p&gt;Delete a certificate from a Java Keytool keystore:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -delete -alias mydomainname -keystore keystorefilename.jks&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Change a Java keystore password:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -storepasswd -new newstorepass -keystore keystorefilename.jks&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Export a certificate from a keystore:&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -export -alias mydomainname -file mydomain.crt -keystore keystorefilename.jks&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;List Trusted CA Certs:&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Import New CA into Trusted Certs:&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;keytool -import -trustcacerts -file /path/to/ca/ca.pem -alias mydomain -keystore $JAVA_HOME/jre/lib/security/cacerts&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;Most Common Sapgenpse commands&lt;/h4&gt;&lt;p&gt;Create server PSE and certificate request using the following commands&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;sapgenpse get_pse &amp;lt;additional_options&amp;gt; -p &amp;lt;PSE_Name&amp;gt; -r &amp;lt;cert_req_file_name&amp;gt; -x &amp;lt;PIN&amp;gt; &amp;lt;Distinguished_Name&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;For Example&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;sapgenpse get_pse -p SAPSSLS.pse -x abcpin -r abc.req &quot; CN=Fully Qualified Domain Name, OU=dept. name, O=Organizational Name, SP=State and Province value, L=Locality value,C=ISO country code value&quot;.&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Import&amp;nbsp; Certificate&amp;nbsp; Using SAPGENPSE&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;sapgenpse import_own_cert &amp;lt;Additional_options&amp;gt; -p &amp;lt;PSE_file&amp;gt; -c &amp;lt;Cert_file&amp;gt; [-r &amp;lt;RootCA_cert_file&amp;gt;] -x &amp;lt;PIN&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;sapgenpse Commands for Conversion:&lt;/h4&gt;&lt;p&gt;SAPGENPSE commands to import pfx file into pse .&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;sapgenpse import_p12 -r intermediate.crt -r root.crt -p SAPSSLS.pse certificate.pfx&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;SAPGENPSE commands to export pfx file through pse .&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;sapgenpse export_p12 -p D:\usr\sap\ABC\PKI404\sec\filename.pse D:\usr\sap\ABC\PKI404\sec\newfilename.p12&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Import&amp;nbsp; Certificate&amp;nbsp; Using SAPGENPSE&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;sapgenpse import_own_cert &amp;lt;Additional_options&amp;gt; -p &amp;lt;PSE_file&amp;gt; -c &amp;lt;Cert_file&amp;gt; [-r &amp;lt;RootCA_cert_file&amp;gt;] -x &amp;lt;PIN&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Most Common commands for ORAPKI-OHS&lt;/p&gt;&lt;p&gt;ORACLE EWALLET(OHS)&lt;/p&gt;&lt;p&gt;Create an auto-login wallet and use the wallet:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;orapki wallet create -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -auto_login -pwd Oracle123&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Create selfsigned certificate command :-&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;orapki wallet add -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -dn &quot;CN= www.pki404.com, OU=IT, O=PKI404 PVT LTD, L=New Delhi, ST=Delhi, C=IN&quot; -keysize 2048 -pwd Oracle123 -validity 365&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Export the CSR from the wallet:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Command: orapki wallet export -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -dn &quot;CN= www.pki404.com, OU=IT, O=PKI404 PVT LTD, L=New Delhi, ST=Delhi, C=IN&quot;&amp;nbsp;-request C:\Oracle\Middleware\ssl\ohs\filename.csr&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Import CA Inter, CA Root, brownbag (ohs) certificates into the wallet&amp;nbsp;&lt;/p&gt;&lt;p&gt;Command:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;orapki wallet add -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -pwd Oracle123 -trusted_cert -cert C:\Oracle\Middleware\ssl\CAInter.pem&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Command:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;orapki wallet add -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -pwd Oracle123 -trusted_cert -cert C:\Oracle\Middleware\ssl\CARoot.pem&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Command:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;orapki wallet add -wallet C:\Oracle\Middleware\ssl\ohs\eWallet -pwd Oracle123 -user_cert -cert C:\Oracle\Middleware\ssl\ohs\pki404.pem&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Using the jks file let us create a wallet:&amp;nbsp;&lt;/p&gt;&lt;p&gt;Create an empty wallet with auto login:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;C:\Oracle\Middleware\oracle_common\bin\orapki wallet create -wallet C:\Oracle\Middleware\ssl -auto_login -pwd Oracle123&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Convert the jks to a wallet:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;C:\Oracle\Middleware\oracle_common\bin\orapki wallet jks_to_pkcs12 -wallet C:\Oracle\Middleware\ssl\eWallet -pwd Oracle123 -keystore C:\Oracle\Middleware\ssl\myIdentity.jks -jkspwd Oracle123&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Stay tuned for more blogs:) Any suggestions are welcome on our social handles and comment section.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/3785602371796900666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/most-common-commands-openssl-keytool-sapgenpse-orapki.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/3785602371796900666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/3785602371796900666'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/most-common-commands-openssl-keytool-sapgenpse-orapki.html' title='Most common commands for openssl keytool sapgenpse orapki'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-6596091129798984137</id><published>2021-07-20T12:17:00.000-07:00</published><updated>2021-07-20T12:17:15.865-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="pfx"/><category scheme="http://www.blogger.com/atom/ns#" term="PKCS12"/><title type='text'>Create pfx PKCS12 using certificate and private key file in openssl for third party CA</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone, Welcome to another article where we will share step by step process to generate pfx PKCS12 using private key and certificate along with chain certificate for third party CA also for self sign certificates. So lets begin without any further due.&lt;/p&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;Create pfx PKCS12 using certificate and private key file for third party CA&lt;/h2&gt;&lt;div&gt;First download openssl for windows here&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;https://www.openssl.org/source/&quot; target=&quot;_blank&quot;&gt;https://www.openssl.org/source/&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On Ubuntu&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;sudo apt update&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;sudo apt install build-essential checkinstall zlib1g-dev -y&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;On Centos first download Development tools and binaries&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;yum group install &#39;Development Tools&#39;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;yum install perl-core zlib-devel -y&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Use below command to install openssl&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;wget https://www.openssl.org/source/openssl-1.0.2o.tar.gz&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After that extract using below command&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;tar -xf openssl-1.0.2o.tar.gz&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;cd openssl-1.0.2o&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In order to create pfx using private key and certificate you need below files handy.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For self signed certificates&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. Domain/Server certificate&amp;nbsp;&lt;/div&gt;&lt;div&gt;2. Private key file&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For Third party CA certificate&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. Domain/Server certificate&lt;/div&gt;&lt;div&gt;2. private key&lt;/div&gt;&lt;div&gt;3. Intermediate certificate&lt;/div&gt;&lt;div&gt;4. Root Certificate&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;To create pfx for self sign certificate use below command in openssl.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;if it is linux use anywhere if windows then go to openssl/bin in command prompt and run below command after modifying the file names.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -export -out certificate.pfx -inkey privatekey.key -in domain.cer&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;keep atleast 6 digit strong password&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;.cer or .crt both are same so use any of these even .pem also can be used as extension.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For Third party CA certificate.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First create chain bundle file by merging Intermediate and root certificate&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On linux run command&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;cat intermediate.cer root.cer &amp;gt; chain.crt&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;it will export chain.crt&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On Windows merge it by copy root certificate content under intermediate certificate in below order and save it as chain-bundle.cer&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;pre style=&quot;background: white; border: 0px; box-sizing: border-box; color: #666666; font-family: inherit; font-size: 14px; font-stretch: inherit; font-variant-east-asian: inherit; font-variant-numeric: inherit; line-height: inherit; margin-bottom: 0px; margin-top: 0px; outline: 0px; overflow: auto; padding: 0px; vertical-align: baseline; white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;background: transparent; border: 0px; box-sizing: border-box; color: #212529; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;DKqC5JlR3XC321Y9YeRq4VzW9v493kHMB65jUr9TU/Qr6cf9tveCX4XSQRjbgbME
HMUfpIBvFSDJ3gyICh3WZlXi/EjJKSZp4A==
&lt;/span&gt;&lt;span style=&quot;background: transparent; border: 0px; box-sizing: border-box; color: red; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----&lt;/span&gt;&lt;span style=&quot;background: transparent; border: 0px; box-sizing: border-box; color: #212529; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;
MIIEYDCCA0igAwIBAgILBAAAAAABL07hRQwwDQYJKoZIhvcNAQEFBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv&lt;/span&gt;&lt;/pre&gt;&lt;pre style=&quot;background: white; border: 0px; box-sizing: border-box; color: #666666; font-family: inherit; font-size: 14px; font-stretch: inherit; font-variant-east-asian: inherit; font-variant-numeric: inherit; line-height: inherit; margin-bottom: 0px; margin-top: 0px; outline: 0px; overflow: auto; padding: 0px; vertical-align: baseline; white-space: pre-wrap;&quot;&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After chain bundle file is created use&amp;nbsp; below command after modifying file names to create pfx, same command can be used on windows and linux.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;openssl pkcs12 -export -out certificate.pfx -inkey privatekey.key -in domain.cer -certfile chain.cer&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;And keep any strong password atleast of 6 digit and it will export pfx file.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;Also read&lt;/span&gt;:-&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/create-jks-file-java-keystoretomcat.html&quot; target=&quot;_blank&quot;&gt;How to create a JKS file&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Stay tuned for more blogs :)&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/6596091129798984137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/create-pfx-pkcs12-using-certificate-privatekey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/6596091129798984137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/6596091129798984137'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/create-pfx-pkcs12-using-certificate-privatekey.html' title='Create pfx PKCS12 using certificate and private key file in openssl for third party CA'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-1402382125725234247</id><published>2021-07-09T09:50:00.012-07:00</published><updated>2021-07-09T15:31:53.807-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="jboss"/><category scheme="http://www.blogger.com/atom/ns#" term="wildfly"/><title type='text'>JBOSS WILDFLY SSL CONFIGURATION FOR FIRST TIME INSTALLATION</title><content type='html'>&lt;p&gt;&amp;nbsp; Hello Everyone Welcome to another exciting blog where i walk you through step by step ssl configuration on jboss wildfly, so let&#39;s start without any further due.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red; font-size: 12pt;&quot;&gt;JBOSS WILDFLY CONFIGURATION FOR FIRST TIME INSTALLATION&lt;/span&gt;&lt;/h2&gt;&lt;h2&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Install ssl on jboss wildfly.&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note: Take backup of original standalone.xml before moving towards configuration&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;modification.&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Create a complete JKS/Keystore file and then proceed with below changes.&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;Helvetica, sans-serif&quot;&gt;&lt;span style=&quot;font-size: 14px;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Visit here to create JKS keystore file&lt;/span&gt;&lt;span style=&quot;color: #636466;&quot;&gt;&amp;nbsp;:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.pki404.com/2021/07/create-jks-file-java-keystoretomcat.html&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;color: #2b00fe;&quot;&gt;How to create JKS keystore file.&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoListParagraph&quot; style=&quot;background: white; line-height: normal; mso-add-space: auto; mso-list: l0 level1 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: Helvetica;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;&lt;span style=&quot;color: #636466;&quot;&gt;1.&lt;/span&gt;&lt;span style=&quot;font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&lt;span style=&quot;color: #636466;&quot;&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Configure WildFly for HTTPS Connector&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start=&quot;1&quot; type=&quot;1&quot;&gt;&lt;ol start=&quot;1&quot; type=&quot;a&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Navigate to&amp;nbsp;&lt;/span&gt;&lt;i&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;$JBOSS_HOME&lt;/span&gt;&lt;/i&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;/standalone/configuration&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;directory and open the&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;standalone.xml&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;file.&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Go to &amp;lt;management&amp;gt; element configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;And Add below connector under &amp;lt;security-realm name=&quot;ApplicationRealm&quot;&amp;gt; just before the &amp;lt;authentication&amp;gt;&amp;nbsp;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&lt;/span&gt;tag&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&amp;lt;server-identities&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&amp;lt;ssl&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&amp;lt;keystore path=&quot;yourjksfile.keystore&quot; relative-to=&quot;jboss.server.config.dir&quot; keystore-password=&quot;PASSWORD&quot; alias=&quot;jboss&quot;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&amp;lt;/ssl&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&amp;lt;/server-identities&amp;gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;After adding the entry it looks like below entry&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1bjOLmgSLkr_H687m28pBKckqXGnLuiPq/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;install ssl on jboss wildfly&quot; border=&quot;0&quot; data-original-height=&quot;681&quot; data-original-width=&quot;1480&quot; height=&quot;184&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd5fy0yZjUwy0gndiKRakEvbKkslsvcr0zyPFHO9gZ56Q-HL1qA3dhAGED6rdVuy7zkz0ig0KDyOB5ogahIkJSUvYKdiekKIuS65gny-GlARzpNmbLov54i1rtQSefWgwcX8tO5kb4T_6n/w400-h184/wildfly1.png&quot; title=&quot;how to install ssl on jboss wildfly&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: rgb(241, 244, 247); line-height: normal; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #636466; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note:&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #636466; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;The&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #636466; font-family: Consolas; font-size: 10.5pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;authentication&amp;gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #636466; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #636466; font-family: Consolas; font-size: 10.5pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;authorization&amp;gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #636466; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;elements are mandatory.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Bonus Tip&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Segoe UI Emoji&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-char-type: symbol-ext; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-symbol-font-family: &amp;quot;Segoe UI Emoji&amp;quot;;&quot;&gt;😎&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;: Make sure you place jks/keystore file in configuration folder and define keystore file without any path, similar to above screenshot. e.g&amp;nbsp;&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;path=&quot;yourjksfile.keystore&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Now that 1&lt;sup&gt;st&lt;/sup&gt;&amp;nbsp;step is completed, Let’s move towards our next step.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoListParagraph&quot; style=&quot;mso-list: l0 level1 lfo1; tab-stops: list 36.0pt left 97.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-fareast-font-family: Helvetica;&quot;&gt;1.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; line-height: 14.98px; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Locate the&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Consolas; font-size: 10.5pt; line-height: 14.98px; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;http-remoting-connector&quot;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; line-height: 14.98px; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp; and make sure it is there&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&amp;lt;http-connector name=&quot;http-remoting-connector&quot; connector-ref=&quot;default&quot; security-realm=&quot;ApplicationRealm&quot;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;It should be under&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;lt;subsystem xmlns=&quot;urn:jboss:domain:remoting:3.0&quot;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;It will look like below highlighted area&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1tuKka7bP5GzRzOTi5hcB2MOvi9rvFe_W/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;install ssl on jboss wildfly&quot; border=&quot;0&quot; data-original-height=&quot;392&quot; data-original-width=&quot;1501&quot; height=&quot;105&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirYZQqnFY0Bv2b5BvbYFqo-iigXZumhGUEs7CxAV7lD8Xuste9TVrzoYWxDFS2OYSSohq_aptSJ1j5IIyyuNXXK0zr3iQdMh6_28ZREOGaJWxxMoqfXx2Oqn2TaotUdtb1qB0pNnP9gz_P/w400-h105/wildfly2.png&quot; title=&quot;how to install ssl on jboss wildfly&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;If it is there that’s great then let’s move to the next step.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p class=&quot;MsoListParagraph&quot; style=&quot;mso-list: l0 level1 lfo1; tab-stops: list 36.0pt left 97.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-fareast-font-family: Helvetica;&quot;&gt;1.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; line-height: 14.98px; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Locate the&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Consolas; font-size: 10.5pt; line-height: 14.98px; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;https-listener&quot;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; line-height: 14.98px; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp; if unable to find then follow below steps to add one.&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Add below line connector&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: red;&quot;&gt;&amp;lt;https-listener name=&quot;https&quot; socket-binding=&quot;https&quot; security-realm=&quot;ApplicationRealm&quot; enable-http2=&quot;true&quot;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Above connector needs to be placed under&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&amp;lt;subsystem xmlns=&quot;urn:jboss:domain:undertow:3.1&quot;&amp;gt;&amp;nbsp;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot;&gt;(values can be different as 3.0 or 3.1 etc here we have 3.1)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;buffer-cache name=&quot;default&quot;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;server name=&quot;default-server&quot;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;http-listener name=&quot;default&quot; max-parameters=&quot;400000&quot; max-post-size=&quot;1717986920&quot; socket-binding=&quot;http&quot; redirect-socket=&quot;https&quot;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;After placing the code it will look like below screenshot.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1uVR1Un6XCFs0rVnofxssJFes19yIyIiJ/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;install ssl on jboss wildfly&quot; border=&quot;0&quot; data-original-height=&quot;371&quot; data-original-width=&quot;1712&quot; height=&quot;86&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRJWjcAzt8K5_x44-LeJLojaanvBRrhtjNo9RnlwOmB6oGhyphenhyphen2LPkODN1TnPRlfsGKpzCHa6L0fYZ3iZAyuK_ywWrVuTMnlVc8F_x0PxMSWbBwItvKALKJ7yxESkcyocq_u5BvD4DpcA-aH/w400-h86/wildfly3.png&quot; title=&quot;how to install ssl on jboss wildfly&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;Lets move ahead with our 4&lt;sup&gt;th&lt;/sup&gt;&amp;nbsp;option which is port configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;p class=&quot;MsoListParagraph&quot; style=&quot;background: white; line-height: normal; mso-add-space: auto; mso-list: l0 level1 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: Helvetica;&quot;&gt;&lt;span style=&quot;color: #636466;&quot;&gt;1.&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&lt;span style=&quot;color: #636466;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Port Configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start=&quot;1&quot; type=&quot;1&quot;&gt;&lt;ol start=&quot;1&quot; type=&quot;a&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Navigate to&amp;nbsp;&lt;/span&gt;&lt;i&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;$JBOSS_HOME&lt;/span&gt;&lt;/i&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;/standalone/configuration&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;directory and open the&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;standalone.xml&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;file.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Change the default WilfFly HTTPS port from 8443 to 443 under&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Consolas; font-size: 10.5pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;socket-binding-group&amp;gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;div style=&quot;background: white; border: 1pt solid rgb(204, 204, 204); margin-left: 54pt; margin-right: 7.5pt; mso-border-alt: solid #CCCCCC .75pt; mso-element: para-border-div; padding: 4pt;&quot;&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin: 0cm 0cm 7.5pt 18pt; padding: 0cm; text-indent: -18pt; word-break: break-all;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: Consolas; mso-fareast-font-family: Consolas;&quot;&gt;c.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;socket-binding-group name=&quot;standard-sockets&quot; default-interface=&quot;public&quot; ...&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin: 0cm 0cm 7.5pt 18pt; padding: 0cm; text-indent: -18pt; word-break: break-all;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: Consolas; mso-fareast-font-family: Consolas;&quot;&gt;d.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;socket-binding name=&quot;http&quot; port=&quot;80&quot; /&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin: 0cm 0cm 7.5pt 18pt; padding: 0cm; text-indent: -18pt; word-break: break-all;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: Consolas; mso-fareast-font-family: Consolas;&quot;&gt;e.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;socket-binding name=&quot;https&quot; port=&quot;443&quot;&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;/&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin: 0cm 0cm 7.5pt 18pt; padding: 0cm; text-indent: -18pt; word-break: break-all;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: Consolas; mso-fareast-font-family: Consolas;&quot;&gt;f.&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-size: 7pt; font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div style=&quot;background: white; border: 1pt solid rgb(204, 204, 204); margin-left: 72pt; margin-right: 7.5pt; mso-border-alt: solid #CCCCCC .75pt; mso-element: para-border-div; padding: 4pt;&quot;&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin-bottom: 7.5pt; padding: 0cm; word-break: break-all;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;lt;/socket-binding-group&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In my case I am using 8443, see the below screenshot.&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://drive.google.com/file/d/1Hn4GNSCuuPHX6xADehddIpZOc-WlBjQo/view?usp=sharing&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img alt=&quot;install ssl on jboss wildfly&quot; border=&quot;0&quot; data-original-height=&quot;469&quot; data-original-width=&quot;1618&quot; height=&quot;116&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjheSG6eWI2a9aOW_E3kuVrMyDLTY8KQl3QeeWxH4afyo94tRxFRVh0eA_C_7qeaG7UZEDrIKbMG76TbfyGDtYmfdohuvuCUmKAe95kdbSGgzju9kjBmolfsjO-L2TXrtsk4E1N2qAj0mw3/w400-h116/wildfly4.png&quot; title=&quot;how to install ssl on jboss wildfly&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;ol start=&quot;1&quot; type=&quot;1&quot;&gt;&lt;ol start=&quot;1&quot; type=&quot;a&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Save the updated&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: &amp;quot;Courier New&amp;quot;; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;standalone.xml&lt;/span&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;file.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Restart jboss-wildfly services to test the configuration.&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level1 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Verify SSL Configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;ol start=&quot;1&quot; type=&quot;a&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; mso-list: l0 level2 lfo1; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 72.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Type the following url into your browser:&lt;span style=&quot;color: #636466;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;div style=&quot;background: white; border: 1pt solid rgb(204, 204, 204); margin-left: 72pt; margin-right: 7.5pt; mso-border-alt: solid #CCCCCC .75pt; mso-element: para-border-div; padding: 4pt;&quot;&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: none; line-height: normal; margin-bottom: 7.5pt; padding: 0cm; word-break: break-all;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #333333; font-family: Consolas; font-size: 10pt; mso-bidi-font-family: &amp;quot;Courier New&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;https://&lt;i&gt;IPaddress&lt;/i&gt;:443/eml/Login&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: normal; margin-bottom: 7.5pt; margin-left: 72.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 7.5pt 72pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Helvetica&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #636466; font-size: 10.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;If the your page Login screen is displayed, an SSL is successfully configured.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Stay tune for more such blogs :)&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/1402382125725234247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/JBOSS-WILDFLY-SSL-CONFIGURATION.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1402382125725234247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/1402382125725234247'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/JBOSS-WILDFLY-SSL-CONFIGURATION.html' title='JBOSS WILDFLY SSL CONFIGURATION FOR FIRST TIME INSTALLATION'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd5fy0yZjUwy0gndiKRakEvbKkslsvcr0zyPFHO9gZ56Q-HL1qA3dhAGED6rdVuy7zkz0ig0KDyOB5ogahIkJSUvYKdiekKIuS65gny-GlARzpNmbLov54i1rtQSefWgwcX8tO5kb4T_6n/s72-w400-h184-c/wildfly1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-879631273693370549</id><published>2021-07-07T14:55:00.004-07:00</published><updated>2021-07-07T14:57:50.388-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Tomcat"/><title type='text'>Create a JKS file java keystore for tomcat and jboss</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone, Welcome to another important blog post where i will walk you through step by step to generate jks (java keystore) file. Follow the below steps.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Create a JKS file java keystore for tomcat and jboss&lt;/b&gt;&lt;/p&gt;&lt;p&gt;We will be requiring below files to create JKS java keystore file in terms of third party CA.&lt;/p&gt;&lt;p&gt;1.Root certificate&lt;/p&gt;&lt;p&gt;2.Intermediate certificate&lt;/p&gt;&lt;p&gt;3.Domain certificate&lt;/p&gt;&lt;p&gt;4.Private key&lt;/p&gt;&lt;p&gt;merge intermediate and root to create chain file.&lt;/p&gt;&lt;p&gt;cat intermediate.cer root.cer &amp;gt; chain.crt&lt;/p&gt;&lt;p&gt;it will export chain.crt&lt;/p&gt;&lt;p&gt;In windows just copy the root certificate content and paste under intermediate one and make sure there is no space after -----End Certificate----- and save it as chain.crt&lt;/p&gt;&lt;p&gt;See the below example.&lt;/p&gt;&lt;pre style=&quot;background-color: white; border: 0px; box-sizing: border-box; font-family: inherit; font-stretch: inherit; font-variant-east-asian: inherit; font-variant-numeric: inherit; line-height: inherit; margin-bottom: 0px; margin-top: 0px; overflow: auto; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;color: #212529;&quot;&gt;DKqC5JlR3XC321Y9YeRq4VzW9v493kHMB65jUr9TU/Qr6cf9tveCX4XSQRjbgbME
HMUfpIBvFSDJ3gyICh3WZlXi/EjJKSZp4A==
&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----&lt;/span&gt;&lt;span style=&quot;color: #212529;&quot;&gt;
MIIEYDCCA0igAwIBAgILBAAAAAABL07hRQwwDQYJKoZIhvcNAQEFBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv&lt;/span&gt;&lt;/pre&gt;&lt;p&gt;Now run below command to generate pfx in &lt;b&gt;openssl&lt;/b&gt;. for windows run in&lt;b&gt; openssl/bin&lt;/b&gt; make sure &lt;b&gt;openssl.cnf &lt;/b&gt;is available in bin, if using &lt;b&gt;apache/bin&lt;/b&gt; then copy &lt;b&gt;openssl.cnf from conf directory&lt;/b&gt; and paste in&lt;b&gt; bin&lt;/b&gt; directory.&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Windows&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl pkcs12 -export -out certificate.pfx -inkey privatekey.key -in domain.crt -certfile chain.crt -config openssl.cnf&lt;/span&gt;&lt;/p&gt;&lt;p&gt;keep atleast 6 digit password.&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Linux&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;openssl pkcs12 -export -out certificate.pfx -inkey privatekey.key -in domain.crt -certfile chain.crt&lt;/span&gt;&lt;/p&gt;&lt;p&gt;keep atleast 6 digit password.&lt;/p&gt;&lt;p&gt;it will export pfx file.&lt;/p&gt;&lt;p&gt;now run below command to covert pfx to jks, if you have windows run in java/jdk or jre bin, if linux run anywhere.(Java must be installed to run the below command)&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -importkeystore -srckeystore certificate.pfx -srcstoretype pkcs12 -destkeystore certificate.jks -deststoretype JKS&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;give the same password as pfx else keystore won&#39;t work.&lt;/p&gt;&lt;p&gt;now import root and intermediate certificate also&amp;nbsp;&lt;/p&gt;&lt;p&gt;run command&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -import -trustcacerts -alias intermediate –file intermediateCertFileName.crt -keystore certificate.jks&lt;/span&gt;&lt;/p&gt;&lt;p&gt;it will import intermediate cert&lt;/p&gt;&lt;p&gt;now for root cert&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -import -trustcacerts -alias root –file RootCertFileName.crt -keystore certificate.jks&lt;/span&gt;&lt;/p&gt;&lt;p&gt;after doing above steps verify the jks by running below command&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;keytool -v -list -keystore certificate.jks&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Note the &lt;b&gt;alias name&lt;/b&gt; for private key from output And also make sure private key entry chain length is 3 to avoid intermediate certificate error on browsers.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: red;&quot;&gt;Also read&lt;/span&gt;:&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/apache-tomcat-ssl-installation-steps.html&quot; target=&quot;_blank&quot;&gt;How to install ssl on tomcat&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Stay tuned for more such blogs. See you in next one. :)&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/879631273693370549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/create-jks-file-java-keystoretomcat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/879631273693370549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/879631273693370549'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/create-jks-file-java-keystoretomcat.html' title='Create a JKS file java keystore for tomcat and jboss'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-2607155244302832033</id><published>2021-07-04T08:34:00.009-07:00</published><updated>2021-07-06T23:42:07.550-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Apache"/><title type='text'>Generate csr on linux server using openssl</title><content type='html'>&lt;p style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background-color: white; color: #666666;&quot;&gt;Hello Everyone, Welcome to another blog where i&#39;ll walk you through step by step CSR generation process on&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;background: rgb(255, 255, 255); border: 0px; box-sizing: border-box; color: #666666; font-family: &amp;quot;Open Sans&amp;quot;, sans-serif; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Apache &lt;/b&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background: rgb(255, 255, 255); border: 0px; box-sizing: border-box; color: #666666; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;web&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Open Sans&amp;quot;, sans-serif&quot; style=&quot;background-color: white; color: #666666;&quot;&gt;server. So lets start without any further due.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Generate a CSR on a Linux server&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&amp;nbsp; At the
command prompt, type the following and hit Return. Change the bit length (2048)
to the appropriate bit length for the SSL issuer. Typically 2048 is sufficient.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
General OpenSSL Commands&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;Step 1: Generate a Key
Pair&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;The utility “openssl” is
used to generate the key and CSR. This utility comes with theOpenSSL package
and is usually installed under /usr/local/ssl/bin. If you have installed them
elsewhere you will need to adjust these instructions appropriately.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;Type the following
command at the prompt:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;•&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Generate a new private key and Certificate Signing Request&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #1f497d;&quot;&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: red; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;openssl
req -out domain.csr -new -newkey rsa:2048 -nodes -keyout domainprivate.key&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #1f497d;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt; Fill
out the requested information below. For the State, use the full name not an
abbreviation. The Organization Name should be a publicly verifiable name (such
as is listed on bank statements, bills, taxes, etc). The common name is the
domain for which the SSL is being issued. For example, if you&#39;re ordering an
SSL for domain.com, then the name would be domain.com. If you&#39;re ordering an
SSL for &lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;a href=&quot;http://www.domain.com/&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;www.domain.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;, then the name would be &lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;a href=&quot;http://www.domain.com/&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;www.domain.com&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span&gt;, for wildcard certificate use *.domain.com&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You
may chose to leave the email address and challenge password blank by simply
hitting return when prompted.&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Generating a 2048 bit RSA private key&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #1f497d;&quot;&gt;&amp;nbsp; &amp;nbsp; ...........+++&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
.............................+++&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
writing new private key to &#39;private.key&#39;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You
are about to be asked to enter information that will be incorporated&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; into
your certificate request.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; What
you are about to enter is what is called a Distinguished Name or a DN.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; There
are quite a few fields but you can leave some blank&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; For
some fields there will be a default value,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you
enter &#39;.&#39;, the field will be left blank.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Country Name (2 letter code) :&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;IN&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; State
or Province Name (full name):&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Delhi&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Locality Name (eg, city:&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;New Delhi&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Organization
Name (eg, company) [My Company Ltd]:&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;My Company Name (e.g. PKI404)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Organizational Unit Name (eg, section) []:&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common
Name (eg, your name or your server&#39;s hostname) []:&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;www.domain.com (e.g www.pki404.com)&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email
Address []: &lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Not Required(do not enter anything)&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please
enter the following &#39;extra&#39; attributes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; to be
sent with your certificate request&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; A
challenge password []: &lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Not Required(do not enter anything)&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; An
optional company name []: &lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Not Required(do not enter anything)&lt;/span&gt;&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;&lt;span face=&quot;&amp;quot;Calibri&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #1f497d; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt; &lt;/span&gt;&lt;span face=&quot;Calibri, sans-serif&quot; lang=&quot;EN-US&quot;&gt;Once
the form is filled out, two files will be created in the directory in which the
command was run one will be domain.csr and other domainprivate.key. The file
domain.csr has the CSR for the SSL which will need to provide to the SSL
issuer.&lt;span style=&quot;color: #1f497d;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span&gt;Stay tuned for more such blogs. :)&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;height: 0px; text-align: left;&quot;&gt;&lt;span&gt;x&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/2607155244302832033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/generate-csr-on-linux-server.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/2607155244302832033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/2607155244302832033'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/generate-csr-on-linux-server.html' title='Generate csr on linux server using openssl'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-4334493860992976324</id><published>2021-07-04T08:03:00.003-07:00</published><updated>2021-07-04T08:13:58.081-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Tomcat"/><title type='text'>Apache Tomcat ssl installation steps</title><content type='html'>&lt;p&gt;&amp;nbsp;Hello Everyone, Welcome to another blog where i&#39;ll walk you through step by step ssl certificate installation on&amp;nbsp;&lt;b&gt;Apache Tomcat&lt;/b&gt;&amp;nbsp;server. So lets start without any further due.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Apache Tomcat ssl installation steps&amp;nbsp;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; mso-outline-level: 1; text-align: center;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #3998d4; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-font-kerning: 18.0pt;&quot;&gt;Tomcat SSL Installation Instructions&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;ol start=&quot;1&quot; type=&quot;1&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;color: #666666; mso-list: l1 level1 lfo2; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Download your certificate files from your certificate authority and save them to the same directory as the keystore that you created during the CSR creation process. The certificate will only work with the same keystore that you initially created the CSR with. The certificates must be installed to your keystore in the correct order.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #666666; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;ol start=&quot;2&quot; type=&quot;1&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;color: #666666; mso-list: l1 level1 lfo2; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Install the Root Certificate file in java keystore&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;: Every time you install a certificate to the keystore you must enter the keystore password that you chose when you generated it. Enter the following command to install the Root certificate file:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;background: rgb(240, 240, 240); border: 1pt solid rgb(204, 204, 204); color: black; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: solid #CCCCCC .75pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 4pt;&quot;&gt;keytool -import -trustcacerts -alias root –file RootCertFileName.crt&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span style=&quot;background-color: #f0f0f0; font-family: &amp;quot;Courier New&amp;quot;;&quot;&gt;-keystore yourdomain.jks&lt;/span&gt;&lt;/p&gt;&lt;ol start=&quot;3&quot; type=&quot;1&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;color: #666666; mso-list: l1 level1 lfo2; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Install the Intermediate Certificate file in java keystore&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;: If your certificate authority provided an intermediate certificate file, you will need to install it here by typing the following command:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;background: rgb(240, 240, 240); border: 1pt solid rgb(204, 204, 204); color: black; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: solid #CCCCCC .75pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 4pt;&quot;&gt;keytool -import -trustcacerts -alias intermediate -file&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;background: rgb(240, 240, 240); border: 1pt solid rgb(204, 204, 204); color: black; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: solid #CCCCCC .75pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 4pt;&quot;&gt;&amp;nbsp;IntermediateCertFileName.crt -keystore yourdomain.jks&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #666666; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;If successful, you will see &quot;Certificate was added to keystore&quot;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start=&quot;4&quot; type=&quot;1&quot;&gt;&lt;li class=&quot;MsoNormal&quot; style=&quot;color: #666666; mso-list: l1 level1 lfo2; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto; tab-stops: list 36.0pt;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Install the Primary Certificate file in java keystore&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;: Type the following command to install the Primary certificate file (for your domain name):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;background: rgb(240, 240, 240); border: 1pt solid rgb(204, 204, 204); color: black; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: solid #CCCCCC .75pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 4pt;&quot;&gt;keytool -import -trustcacerts -alias tomcat -file&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;background: rgb(240, 240, 240); border: 1pt solid rgb(204, 204, 204); color: black; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: solid #CCCCCC .75pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 4pt;&quot;&gt;&amp;nbsp;PrimaryCertFileName.crt -keystore yourdomain.jks&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: #666666; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;If successful, you will see &quot;Certificate reply was installed in keystore&quot;. You now have all the certificates installed to the keystore file. You just need to configure your server to use the keystore file.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 36pt; mso-margin-bottom-alt: auto; mso-margin-top-alt: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;&amp;quot;Arial&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;border: 1pt none windowtext; color: #015e95; mso-border-alt: none windowtext 0cm; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 0cm;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; mso-line-height-alt: 10.5pt;&quot;&gt;&lt;span face=&quot;Arial, sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;border: 1pt none windowtext; color: #015e95; padding: 0cm;&quot;&gt;&lt;b&gt;Configuring your SSL Connector&lt;/b&gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; line-height: 10.5pt; margin-bottom: 12pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Tomcat will first need an SSL Connector configured before it can accept secure connections.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;1.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Open the Tomcat server.xml file in a text editor (this is usually located in the conf folder of your Tomcat&#39;s home directory).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;2.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Find the connector that will be secured with the new keystore and uncomment it if necessary (it is usually a connector with port 443 or 8443 like the example below).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;3.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Specify the correct keystore filename and password in your connector configuration. When you are&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoListParagraph&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;border: 1pt none windowtext; color: red; font-family: &amp;quot;Courier New&amp;quot;; mso-border-alt: none windowtext 0cm; padding: 0cm;&quot;&gt;&amp;lt;Connector port=&quot;443&quot; protocol=&quot;HTTP/1.1&quot; maxThreads=&quot;150&quot; scheme=&quot;https&quot; secure=&quot;true&quot; SSLEnabled=&quot;true&quot; keystoreFile=&quot;conf/yourdomain.jks&quot; keystorePass=&quot;keystorepassword&quot; clientAuth=&quot;false&quot; SSLProtocol=&quot;TLSv1+TLSv1.1+TLSv1.2&quot; keyAlias=&quot;server&quot; ciphers=&quot;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA&quot; /&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt;&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note: If you are using version 7 of Tomcat you will need to change &quot;keypass&quot; to &quot;keystorePass&quot;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;4.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Save your changes to the server.xml file.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;5.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Restart Tomcat.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;That&#39;s it for now, Hope this has helped you. Stay tuned for more.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;Don&#39;t forget to bookmark this page for your future references. :)&lt;/p&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/4334493860992976324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/apache-tomcat-ssl-installation-steps.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4334493860992976324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4334493860992976324'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/apache-tomcat-ssl-installation-steps.html' title='Apache Tomcat ssl installation steps'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-4822098095064789851</id><published>2021-07-04T07:57:00.003-07:00</published><updated>2021-07-04T08:14:06.153-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Tomcat"/><title type='text'>Apache Tomcat CSR generation steps</title><content type='html'>&lt;p&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp; Hello Everyone, Welcome to another blog where i&#39;ll walk you through step by step&amp;nbsp;&lt;/span&gt;&lt;b&gt;CSR generation&lt;/b&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp;on&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: inherit;&quot;&gt;Apache Tomcat&lt;/b&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp;server&lt;/span&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;. So lets start without any further due.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Apache Tomcat CSR generation steps&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; margin-bottom: 6pt; mso-outline-level: 3;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #015e95; font-family: inherit; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;CSR GENERATION STEPS:-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; margin-bottom: 6pt; mso-outline-level: 3;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #015e95; font-family: inherit; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; margin-bottom: 6pt; mso-outline-level: 3;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #015e95; font-family: inherit;&quot;&gt;&lt;b&gt;Step A -- Create a new Keystore&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l1 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;1.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;You will be using the keytool command to create your new key-CSR pairing. Enter the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 15pt; mso-line-height-alt: 10.5pt;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;border: 1pt none windowtext; color: red; font-family: inherit; mso-border-alt: none windowtext 0cm; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 0cm;&quot;&gt;keytool -genkey -alias server -keyalg RSA -keysize 2048 -keystore yourdomain.jks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; font-family: inherit; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; font-family: inherit; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&#39;Yourdomain&#39; is the name of the domain you are securing. However, if you are ordering a Wildcard Certificate, do not include * in the beginning of the filename as this is not a valid filename character.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l1 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;2.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;You will be prompted for the DN information. Please note: when it asks for first and last name, this is not YOUR first and last name, but rather your domain name and extension(i.e.,&amp;nbsp;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;a href=&quot;http://www.yourdomain.com/&quot;&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; style=&quot;mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;www.yourdomain.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;). If you are ordering a Wildcard Certificate this must begin with *. (example: *.domain.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l1 level1 lfo1; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;3.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Confirm that the information is correct by entering &#39;y&#39; or &#39;yes&#39; when prompted. Next you will be asked for your password to confirm. Make sure to remember the password you choose.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;background: white; margin-bottom: 6pt; mso-outline-level: 3;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: #015e95; font-family: inherit; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Step B -- Generate your CSR with your new keystore&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo2; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;1.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Next, use keytool to actually create the Certificate Signing Request. Enter the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;margin-left: 15pt; mso-line-height-alt: 10.5pt;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;border: 1pt none windowtext; color: red; font-family: inherit; mso-border-alt: none windowtext 0cm; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; padding: 0cm;&quot;&gt;keytool -certreq -alias server -keyalg RSA -file yourdomain.csr -keystore yourdomain.jks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-left: 15pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; font-family: inherit; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt;&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; font-family: inherit; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Again, &#39;yourdomain&#39; is the name of the domain you are securing. (without the * character if you are ordering a Wildcard Certificate).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo2; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;2.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Enter the keystore password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo2; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana;&quot;&gt;&lt;span style=&quot;mso-list: Ignore;&quot;&gt;3.&lt;span style=&quot;font-stretch: normal; font-variant-east-asian: normal; font-variant-numeric: normal; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span face=&quot;&amp;quot;Verdana&amp;quot;,sans-serif&quot; lang=&quot;EN-US&quot; style=&quot;color: black; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Then the SSL Certificate CSR file is created. Open the CSR with a text editor, and copy and paste the text (including the BEGIN and END tags) into the Certificate Authority web order form.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo2; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;Hope you have generated CSR without any issue, Now follow the next step for ssl installation&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: 10.5pt; margin-bottom: 12.0pt; margin-left: 15.0pt; margin-right: 0cm; margin-top: 0cm; margin: 0cm 0cm 12pt 15pt; mso-list: l0 level1 lfo2; tab-stops: list 36.0pt; text-indent: -18pt;&quot;&gt;Also read :&amp;nbsp;&lt;a href=&quot;https://www.pki404.com/2021/07/apache-tomcat-ssl-installation-steps.html&quot; target=&quot;_blank&quot;&gt;Apache Tomcat ssl installation steps&lt;/a&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/4822098095064789851/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/apache-tomcat-csr-generation-steps.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4822098095064789851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/4822098095064789851'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/apache-tomcat-csr-generation-steps.html' title='Apache Tomcat CSR generation steps'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4458964827866241824.post-7343085349992018693</id><published>2021-07-02T07:26:00.003-07:00</published><updated>2021-07-02T14:01:45.904-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Tomcat"/><title type='text'>File base authentication in Tomcat with .well-known directory on windows</title><content type='html'>&lt;p&gt;Hi Everyone, today i&#39;ll walk you through step by step to create http file base authentication on tomcat windows for Certificate Authority domain Validation. So let&#39;s begin without wasting anymore time.&lt;/p&gt;&lt;p&gt;&lt;b&gt;File base authentication on Tomcat with .well-known directory on windows&lt;/b&gt;&lt;/p&gt;&lt;p&gt;When uploading/creating the folder/file to Tomcat, please keep in mind that the file should be accessible via the standard ports - 80 (for a non-secure connection) or 443 (for a secure one).&lt;/p&gt;&lt;p&gt;Domain url needs be accessed publicly same as below&lt;/p&gt;&lt;p&gt;&lt;b&gt;http://domain.com/.well-known/pki-validation/filename.txt&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;By default, Tomcat uses the 8080 and 8443 ports, respectively.&lt;/p&gt;&lt;p&gt;If the file will be accessible via the default Tomcat ports 8080 and 8443 only, the validation will not be completed.&lt;/p&gt;&lt;p&gt;The document root folder for the website on Tomcat can be found in the ‘server.xml’ file in the following line:&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&amp;lt;Context path=&quot;/&quot; docBase=&quot;/some/full/path/to/document/root/folder&quot; /&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Usually, the server root folder is located in the folder set under the variable&lt;b&gt; $CATALINA_HOME&lt;/b&gt; or &lt;b&gt;webapps&amp;nbsp;&lt;/b&gt;and the document root folder for the website is set to the particular folder under the server root folder.&lt;/p&gt;&lt;p&gt;You can create the ‘.well-known’ and ‘pki-validation’ folders for placing the validation file using the command line with command like mkdir from command prompt in same folder as .well-known folder can not be created by clicking on create folder&lt;/p&gt;&lt;p&gt;open command prompt in root folder and type&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;mkdir .well-known&lt;/b&gt;&amp;nbsp;as dot(.) file can not be created with GUI.&lt;/p&gt;&lt;p&gt;rest folders like pki-validation can be created from GUI and so as empty txt file and then paste the random value inside txt file.&lt;/p&gt;&lt;p&gt;so the url becomes&amp;nbsp;&lt;b&gt;http://domain.com/.well-known/pki-validation/filename.txt &lt;/b&gt;followed by random value/meta tag in txt file. url should be publicly accessible on default 80 or 443 port displaying the value on browser.&lt;/p&gt;&lt;p&gt;Incase url is not acessible from outside check ports open status from firewall.&lt;/p&gt;&lt;p&gt;Should you have any queries then please write them in comments and will be happy to answer.&lt;/p&gt;&lt;p&gt;Stay tuned for more blogs. :&amp;nbsp;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.pki404.com/feeds/7343085349992018693/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.pki404.com/2021/07/tomcat-file-base-authentication-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/7343085349992018693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4458964827866241824/posts/default/7343085349992018693'/><link rel='alternate' type='text/html' href='http://www.pki404.com/2021/07/tomcat-file-base-authentication-with.html' title='File base authentication in Tomcat with .well-known directory on windows'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/01308431164596248321</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>