Below are some examples of how to install a certificate that is created by a
certificate issuer. We make no recommendations on who should be used as a
certificate issuer and we are not partnered with any issuer.
For troubleshooting, download the SSL Dia
gnostics Tool from Microsoft:
There is a tutorial on the
Instructions posted at:
How to install you
r SSL Certificate to your Windows 2000/2003 Server
Save just the Bundle Certificate (CertificateBundle.p7b) from your DigiCert Customer
Account to the desktop of the web server you are securing.
1) Install your Certificate:
Go to your Administrative Tools,
and Open the Internet Services Manager.
Click on the Default Website and select Properties. Go to the Directory Security
on "Server Certificate..." button. This will start the certificate wizard. Hit
Process the pending request and install th
and click Next.
"Browse" for your SSL Certificate. Make sure to view all file types (Windows only looks
for .cer files by def
ault.) Locate your Bundle Certificate (CertificateBundle.p7b) Click
Next. Follow the rest of the wizard steps until finished.
2) Restart your Server.
*** Note: The installation of your DigiCert Certificate is complete once you have
finished Step 1 (above)
. In most situations IIS will instantly begin using the new
certificate and a restart is not necessary. However, if you notice that the server continues
to use an old certificate or the server will not load https at all then shutdown and restart
3) Backup the certificate and private key (Recommended)
It is always good to keep a backup of your certificate and private key incase your server
crashes. You must backup your certificate from your server in order to include a backup
of your private key
. The private key is not included in your certificate files, and the
certificate is not functional without the private key.
To backup your SSL Certificate and private key do the following:
, select 'Run...'. Type 'mmc' and hit Enter.
Under the File menu, choose Add/Remove Snap in.
Go to Add, then from the Add Standalone Snap
in panel choose Certificates, and click
and click Finish.
Close the snap
in panel, clicking
This should retur
n you to the MMC.
Expand the Personal Folder and view the contents of the Certificates. You will see your
primary certificate listed (this is the Primary Certificate which was installed to the
pending request). Right
click your Primary Certificate and choo
se All Tasks, then choose
Export. This opens the Certificate Export Wizard
Select the option to 'Yes, export the private key' and hit next. Choose to backup the
certificate to a PKCS 12 (.PFX) file. Select the option to include all Certificat
es in the
Certification Path if possible. Select to enable protection. Do Not select the option to
Delete the Private
Key if the export is successful. You will be prompted to choose a
password. Be sure to remember it, as it will be required if you ever nee
d to import the
This will save a .pfx file
Save it to a secure location off of the server.
4) Import the Intermediate Certificate (Not required for most installations)
Because the DigiCert Intermediate Certificate is installed automatically w
hen you install
the Certificate Bundle file (your_domain_name.cer) to your server in Step 1, this step
should not be necessary for most installations. When the certificate is correctly installed
to your server browsers will not display any certificate warn
ings whatsoever. However, if
your clients are getting a warning stating that the certificate was issued by a company that
you have not chosen to trust, then the following procedure will fix that problem.
Download the DigiCertCA.crt Certificate file from i
nside your DigiCert account and save
it to your desktop.
click the certificate. This will open the certificate to view.
At the bottom o
f the General tab, click the "Install Certificate..." button. This will start
the certificate import wizard. Click "Next".
Choose to "Place al
l certificates in the following store", and click "Browse".
First, click the "Show physical stores" box, then expand the Intermediate Certific
Authorities folder, select the underlying Local Computer folder, and click ok. Hit "Next",
Your intermediate certificate is now installed. Restart your server.
Instructions posted at:
IIS SSL Instructions
Microsoft IIS 5 and 6
Internet Information Services 5
Installing your SSL Certificate / Web Server Certificate
/ Secure Server Certificate from RapidSSL.com
Firstly when your issuance email arrives you will hav
e two certificates in the email
server certificate and a chained certificate.
Copy the chained certificate into a text editor such as notepad and save as chain.cer.
Copy your web server certificate into a text editor such as notepad and save as
First install the chained certificate as follows:
On your webserver open by the Certificates snap
in on the MMC:
1. Click the
Add/Remove Snap in
Add Standalone Snap
box and click
Add Standalone Snap
Return to the MMC:
entry in the MMC and right c
2. Complete the import wizard, locating the chained certificate (cha
prompted for the Certificate file to import.
3. Ensure that the chained certificate appears under Intermediate Certification Authorities
Secondly, install your web server certificate:
1. Start IIS and right click
Default Web Site
from the menu.
2. When the
appear, click on the
3. Click on
and follow the on screen
• Ensure that you select
Process the pending request and install the certificate
• Locate the yourdomain.cer file when prompted to locate your webserver certificate.
• Review the summary screen and ensure that you
are processing the correct certificate.
on the confirmation screen.
4. Make sure that you have assigned Port 443 as the SSL port for https for your site. To
do this, right click Properties for your website and make sure that 44
3 has been entered
into the SSL port box:
You must restart your physical machine for the install to be completed.
Backing up your key pair file
in Management Console
in consoles (MMC) are not preconfigured. You will need to configure
in before you can perform any Export/Import functionality. To configure your
in, follow the steps below. The system administ
rator will have to create the console.
. This will bring up an empty
console with no management functionality.
ins added to box will list only the Console
and then click
Managing your certificates
Go to the
Microsoft Management Console
(MMC) and add the Snap
Select the f
Right click on the certificate to export.
The Welcome to the Certificate Manager Import Wizard window opens.
Yes, export the private
Make sure the Personal Information Exchange
PKCS # 12 (.pfx) box is selected.
Warning: Make sure that the "Delete the private key if the export is
Check the box
Enable strong protection requires IE5.0, NT4.0
SP4 or above
Check the box to
Include all certificates in the chain
Type and confirm your export password.
(Note: this password field can be left blank, but we recommend using a good
password for security)
Warning: If you lose the passwor
d, you must purchase another certificate.
the file to a disk or other form of media. You should choose a form of media that
you would be able to recover if your system has to be rebuilt. Save this file in a secure
*** Microsoft has an aler
t addressing a problem with exporting and importing
Service Pack 2 is intended to correct this problem. There is also a hotfix that may be
obtained from Microsoft that must be run prior to exporting and importing your
go to the following URL for more information or email us at
Once your SSL certificate has been signed and issued,Go Daddy® will send you an e
mail message that allows you to download the signed certificate and our intermediat
certificates, all of which must be installed on your Web site.
The specific installation procedure is determined by your choice of Web server software.
Installation instructions are available for the Web servers listed below.
If your Web server i
s operated by an ISP or hosting service, the provider/service
will install your certificates.
Web Server List
Microsoft Internet Information Services 4.x
Microsoft Internet Information Services
Microsoft Internet Information Services 6.0
Exchange Server 2007
Mac OS X 10.4
Mac OS X 10.5
If the Web server software you are using is not listed, contact your server software
vendor for installation instructions.