/
How to Get a Certificate from an internal CA

How to Get a Certificate from an internal CA

All of the steps are completed on the web server. None of them are performed on the machine that is the certificate authority.

Create Certificate - Windows Server 2016+ and Windows 10

  1. Start -> Manage computer certificates

  2. Right-click Personal → All Tasks → Request New Certificate...

  3. Next

  4. Next

  5. Under "Active Directory Enrollment Policy" check "Computer"

  6. Click the arrow next to "Details"

  7. Click Properties

  8.  

    1. General tab

      1. Friendly name: ex: myserver.mydomain.local

    2. Subject tab

      1. Subject name: 

        1. Type: Common Name

        2. Value: FQDN of server, ex: myserver.foray.local

        3. Add

      2. Alternative name:

        1. Type: DNS

        2. Value: FQDN of server, ex: myserver.foray.local

        3. Add

    3. Private Key tab

      1. Click “Key options” arrow

        1. Key size: 2048

        2. Check "Make private key exportable"

    1. OK

  9. Enroll

Now is a good time to make sure that