{"id":28,"date":"2003-08-15T11:48:18","date_gmt":"2003-08-15T16:48:18","guid":{"rendered":"http:\/\/192.168.33.66\/wp\/?p=28"},"modified":"2003-08-15T11:48:18","modified_gmt":"2003-08-15T16:48:18","slug":"instructions-on-how-to-generate-cert-with-openssl-for-iis","status":"publish","type":"post","link":"http:\/\/www.wildow.com\/blog\/?p=28","title":{"rendered":"instructions on how to generate cert with openssl for IIS"},"content":{"rendered":"<p>How to use OpenSSL to act as a CA to sign an IIS certificate request for<br \/>\nSSL use<\/p>\n<p>1. Create a certificate request via the Internet Services Manager under<br \/>\n&#8216;Directory Security->Secure Communication->Server Certificate&#8217;. This<br \/>\nis found under the property tab for the webserver you want to secure.<br \/>\nFollow the wizard to create a certificate request and fill up all<br \/>\nrequired details. At the end of the wizard, it will generate a<br \/>\ncertreq.txt file. Move this to your favorite linux box (e.g Debian) or<br \/>\nrun openssl under cygwin.  contd..<br \/>\n<!--more--><\/p>\n<p>2. We now have to generate a private key using OpenSSL<\/p>\n<p>openssl genrsa -des3 -out cakey.pem 2048<\/p>\n<p>The process will prompt you to supply a PEM pass phrase to help secure the<br \/>\nkey.<\/p>\n<p>3. Now we have to create a CA certificate for our bogus CA<\/p>\n<p>openssl req -new -x509 -key cakey.pem -out cacert.pem -days 1825<\/p>\n<p>4. Create the following directories in your home directory<\/p>\n<p>demoCA<br \/>\ndemoCA\/private<br \/>\ndemoCA\/newcerts<\/p>\n<p>Also create in demoCA a empty text file called &#8216;index.txt&#8217; and a text<br \/>\nfile called &#8216;serial&#8217; with the numbers &#8217;01&#8217;<\/p>\n<p>5. Move your private key cakey.pem to the demoCA\/private directory<br \/>\nand cacert.pem to demoCA\/<\/p>\n<p>6. Sign our previously created IIS certificate request<\/p>\n<p>openssl ca -in certreq.txt -out iis.cer<\/p>\n<p>7. Open iis.cer in your favorite text editor (eg vi) and remove all the text<br \/>\nbefore the line &#8216;&#8211; Begin Certificate &#8211;&#8216;. IIS is not able to handle<br \/>\nthe text above that line and may get confused!<\/p>\n<p>8. Move iis.cer back to your Windows machine and complete the<br \/>\ncertificate request in IIS by importing the iis.cer file.<\/p>\n<p>All done!<\/p>\n<p>&#8212; <br \/>\nBest regards,<br \/>\n Derek Chew En-Hock                   mailto:sdchew@ieee.org<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to use OpenSSL to act as a CA to sign an IIS certificate request for SSL use 1. Create a certificate request via the Internet Services Manager under &#8216;Directory Security->Secure Communication->Server Certificate&#8217;. This is found under the property tab &#8230; <a class=\"more-link\" href=\"http:\/\/www.wildow.com\/blog\/?p=28\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-28","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=28"}],"version-history":[{"count":0,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/28\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=28"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=28"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}