

CA Risk Authentication Administration Guide › Configure SSL › Prepare for SSL Communication › Obtain Certificates Directly Though a Certificate Authority (CA) › Download Certificates
Download Certificates
The certificates that you requested through Microsoft CA 2008 are installed in the browser store, from where you have to download them. The format in which you have to download the certificate depends on the encryption mode:
- If software encryption is used, then certificates must be In PKCS#12 Format.
- If hardware encryption is used, then certificates must be In PEM Format.
In PKCS#12 Format
To download the certificate and private key to a PKCS#12 file by using Microsoft CA 2008:
- Open an Internet Explorer window.
- Navigate to Tools and then Internet Options.
The Internet Options dialog box appears.
- Activate the Content tab, in the Certificates section click Certificates.
The Certificates dialog box appears.
- Select the certificate that you want to download and click Export.
The Certificate Export Wizard appears.
- Click Next on the Welcome screen.
- Choose Yes, export the private key option, and click Next.
- Ensure that the Personal Information Exchange - PKCS # 12 (.PFX) option is selected.
- Select Enable Strong Protection option, and click Next.
- Enter the password for the PKCS#12 (.PFX) file in the Password and Confirm password fields, and click Next.
- Enter the File name with which you want to download the PKCS#12 (.PFX) file and click Next.
- Click Finish to complete the wizard.
The certificate and private key are now available on your system in the specified location.
In PEM Format
You cannot directly export the certificate in .PEM format from the browser certificate store. As a result, you must first download it in .DER format (by using Microsoft CA 2008) and then convert to .PEM as follows:
- Open an Internet Explorer window.
- Navigate to Tools and then Internet Options.
The Internet Options dialog box appears.
- Activate the Content tab, in the Certificates section click Certificates.
The Certificates dialog box appears.
- Select the certificate that you want to download and click Export.
The Certificate Export Wizard appears.
- Click Next on the Welcome screen.
- Choose No, do not export the private key option and then Next.
- Ensure that the DER encoded binary X.509 (.CER) option is selected.
- Click Next.
- Enter the File name with which you want to download the certificate, and click Next.
- Click Finish to complete the wizard.
The certificate is now available on your system in the specified location.
- Convert DER to PEM format.
To convert the certificate from DER to PEM format, you can use open source tools such as OpenSSL. Use the following command to convert using OpenSSL tool:
openssl x509 -inform der -in <certificate>.cer -out <certificate>.pem
Copyright © 2014 CA Technologies.
All rights reserved.
 
|
|