Introduction
Secure Socket Layer (SSL) certificates play a crucial role in ensuring the security and integrity of data transmitted over the internet. In addition to encrypting communication between a server and a client, SSL certificates can also support client authentication. This article will walk you through the process of creating an SSL certificate with client authentication support using the Microsoft Certificate Manager and a trusted certificate authority (CA).
Prerequisites
Before we begin, make sure you have the following prerequisites in place:
- Microsoft Certificate Manager: This tool is available on Windows operating systems and provides a user-friendly interface for managing certificates.
- Trusted Certificate Authority: Choose a reputable certificate authority (CA) that supports client authentication or use an internal certificate authnority that is trusted by your organisation.
Step 1 - Generate a Certificate Signing Request (CSR)
- Launch the Microsoft Certificate Manager. You can access it by typing "certmgr.msc" in the Run dialog box or the command prompt.
- In the Certificate Manager, navigate to the "Personal" folder and right-click on "Certificates." Select "All Tasks" and then "Advanced Operations," followed by "Create Custom Request."
- Choose "Proceed without enrolment policy" and click "Next."
- Select a suitable server template. The template needs to support creation of certificates with both the "Client Authentication" and "Server Authentication" intended purposes. Click "Next."
- Choose the desired cryptographic service provider and key size. For client authentication, a key size of 2048 bits is recommended. Click "Next."
- In the "Certificate Information" section, click on Details and then click on Properties
- In the "Subject" section enter the necessary details, including the Common Name (CN) of the certificate, which should match the domain name of the server associated with the SSL certificate. Please ensure that the Subject section complies with the restrictions listed below.
- In the "Extensions" section open the "Extended Key Usage" section, select "Server Authentication" and "Client Authentication" and click "Add."
- Click OK to close the certificate Properties and click "Next."
- Enter a file name and click "Finish" to generate the CSR file.
Step 2 - Submit the CSR to the Certificate Authority (CA)
- Save the CSR file generated in Step 1 to your local machine.
- Go to the website of your chosen certificate authority (CA) and locate their certificate issuing portal.
- Follow the instructions provided by the CA to submit the CSR file. Provide any additional information required during the process.
- Pay the necessary fees, if applicable, and complete the validation process specified by the CA.
- Once the CA verifies the information and approves the request, they will issue the SSL certificate with client authentication support.
Step 3 - Install the SSL Certificate
- After receiving the SSL certificate from the CA, save it to your local machine.
- Launch the Microsoft Certificate Manager and navigate to the "Personal" folder.
- Right-click on "Certificates" and select "All Tasks" > "Import."
- Follow the Import Wizard to locate and import the SSL certificate file.
- Once the import process is complete, the SSL certificate will be available in the "Personal" folder of the Certificate Manager.
Step 4 - Export the Certificate in a PCKS#12 keystore
- Launch the Microsoft Certificate Manager and navigate to the "Personal" folder.
- Click on "Certificates", select the desired certificate, rigth click and choose "All Tasks" > "Export".
- Select "Yes, export the private key" and click Next.
- Choose the Personal Information Exchange - PKCS#12 format, select "Include all certificates in the certification path if possible" and "Export all extended properties" and click Next
- Enter a file Name and click Next
- Review all settings and click Finish.
- The PCKS#12 keystore can be used during installation of a Connector.
Step 5 - Export the Certificate in a PCKS#7 keystore
- Launch the Microsoft Certificate Manager and navigate to the "Personal" folder.
- Click on "Certificates", select the desired certificate, rigth click and choose "All Tasks" > "Export".
- Choose the Cryptographic Message Syncax Standard - PKCS#7 format, select "Include all certificates in the certification path if possible" and click Next
- Enter a file Name and click Next
- Review all settings and click Finish.
- The PCKS#7 keystore can be sent to EnergySys for validation of the certificate and to establish trust of the certificate chain.
Restrictions on Certificate Subject
- Subject should be less than 100 characters in length, including white spaces
- Subject should not contain the wildcard character *
- Subject should contain only the following characters:
- alphanumeric characters: a-z, A-Z and 0-9
- special characters are restricted to: _ :;.,\/"'?!(){}[]@<>=-+#$&|~^%