Solved

Export IIS 7 SSL key and certificate in x509 format?

Posted on 2014-11-13
3
477 Views
Last Modified: 2014-11-14
I have a working SSL certificate installed on a WIndows 2008 R2 (IIS 7.5) server.

I've been asked to export the certificate and key in x509 format.

Can someone provide a step-by-step "for Dummies" recipe for doing that?   I assume that I must first export the certificate to PFX and then convert it?

I understand that I don't understand all the definitions/relationships/formats of PEM, DER, PKCS7, x509, CRT, CER.  While I want to understand it all better, I first need to get the export completed.

Thank you.
0
Comment
Question by:RichardKline
3 Comments
 
LVL 23

Assisted Solution

by:Dirk Kotte
Dirk Kotte earned 150 total points
Comment Utility
X.509 is "the certificate" definition and define which content is included.
PEM, DER, PKCS7, x509, CRT, CER are only file extensions and define how the x.509 cert is stored/encoded.
so the .p12 file (PKCS#12) may contain the password protected private key. but it is also X.509.

the questions at windows IIS should be:
- with or without private key
- DER or base64 coded

mostly the certificates are usable if i save the files as .txt or .test also. because the file header contains the necessary information.

more details:
http://en.wikipedia.org/wiki/X.509
0
 
LVL 61

Accepted Solution

by:
btan earned 350 total points
Comment Utility
iis support pfx as it is and the key has to be marked as exportable else it cannot be exported as required. the below is reference on the requirement and steps per se.
https://www.digicert.com/ssl-support/pfx-import-export-iis-7.htm

in fact x.509 should be x.509v3. the other format (such as p12 or pkcs12, pem, der) is not the direct mapping for pfx. there are means to convert them and most are using the s/w called openssl. below are some example.
http://wiki.gandi.net/en/ssl/troubleshoot
https://sslguru.sg/faq/technical-questions/convert-certificates-formats-pem-p7b-pfx-der.html
0
 
LVL 1

Author Closing Comment

by:RichardKline
Comment Utility
My question could not be answered as simply as I would have liked.     Both answers contain part of the needed information.    btan's showed me the necessary program and command line Thank you.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Healthcare organizations in the United States must adhere to the guidance of both the HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) for securing and protec…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now