Solved

Export IIS 7 SSL key and certificate in x509 format?

Posted on 2014-11-13
3
512 Views
Last Modified: 2014-11-14
I have a working SSL certificate installed on a WIndows 2008 R2 (IIS 7.5) server.

I've been asked to export the certificate and key in x509 format.

Can someone provide a step-by-step "for Dummies" recipe for doing that?   I assume that I must first export the certificate to PFX and then convert it?

I understand that I don't understand all the definitions/relationships/formats of PEM, DER, PKCS7, x509, CRT, CER.  While I want to understand it all better, I first need to get the export completed.

Thank you.
0
Comment
Question by:RichardKline
3 Comments
 
LVL 23

Assisted Solution

by:Dirk Kotte
Dirk Kotte earned 150 total points
ID: 40441933
X.509 is "the certificate" definition and define which content is included.
PEM, DER, PKCS7, x509, CRT, CER are only file extensions and define how the x.509 cert is stored/encoded.
so the .p12 file (PKCS#12) may contain the password protected private key. but it is also X.509.

the questions at windows IIS should be:
- with or without private key
- DER or base64 coded

mostly the certificates are usable if i save the files as .txt or .test also. because the file header contains the necessary information.

more details:
http://en.wikipedia.org/wiki/X.509
0
 
LVL 63

Accepted Solution

by:
btan earned 350 total points
ID: 40442131
iis support pfx as it is and the key has to be marked as exportable else it cannot be exported as required. the below is reference on the requirement and steps per se.
https://www.digicert.com/ssl-support/pfx-import-export-iis-7.htm

in fact x.509 should be x.509v3. the other format (such as p12 or pkcs12, pem, der) is not the direct mapping for pfx. there are means to convert them and most are using the s/w called openssl. below are some example.
http://wiki.gandi.net/en/ssl/troubleshoot
https://sslguru.sg/faq/technical-questions/convert-certificates-formats-pem-p7b-pfx-der.html
0
 
LVL 1

Author Closing Comment

by:RichardKline
ID: 40443140
My question could not be answered as simply as I would have liked.     Both answers contain part of the needed information.    btan's showed me the necessary program and command line Thank you.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Most MSPs worth their salt are already offering cybersecurity to their customers. But cybersecurity as a service is wide encompassing and can mean many things.  So where are MSPs falling in this spectrum?
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question