How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (2024)

How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (1) 12/11/2023 How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (2) 798 People found this article helpfulHow can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (3) 540,147 Views

Description

This article describes how to obtain a certificate from an internal CA for the purpose of SonicWall Web Management.

Deployment Prerequisites

  • Microsoft Windows Active Directory Services installed and configured.
  • Microsoft Certificate Services installed and configured.
  • Microsoft Internet Information Services (IIS) 7.0 installed and configure.

Deployment Steps

  1. Exporting the CA Certificate from the Active Directory Server.
  2. Importing the CA Certificate onto the SonicWall.
  3. Creating a New Signing Request in SonicWall Appliance.
  4. Requesting certificate for the new signing Request by the MS Certificate Authority.
  5. Validating the Certificate on the SonicWall Appliance.
  6. How to Test

Resolution

Exporting the Root CA Certificate from the Active Directory (AD) Server
  1. In the AD server, launch the Certificate Authority application by Start |Run|certsrv.msc.
  2. Right click the CA you created and select Properties.
  3. On the General tab, clickView Certificate button.
  4. On the Details tab, select Copy to File.
  5. Follow through the wizard, and select the DER Encoded binary X.509 (.cer) format.
  6. Click browse and specify a path and filename to save the certificate.
  7. ClickNext button and clickFinish.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (4)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (5)How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (6)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (7)How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (8)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (9)How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (10)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (11)How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (12)
Importing the CA Certificate onto the SonicWall
  1. Click Manage in the top navigation menu.
  2. Navigate to Appliance | Certificates.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (13)
  3. ClickImport. Select the certificate file you just exported.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (14)
  4. Select Import a CA certificate from a PKCS#7 (.p7b), PEM (.pem) or DER (.der or .cer) encoded file,
  5. ClickBrowse and Select the certificate file you just exported from the MS Certificate Authority.
  6. Once the root certificate is selected, Clickimport button.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (15)
  7. Once the CA root certificate is imported, it will be listed under the Appliance | Certificatespage with type as CA Certificate.

    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (16) TIP: This page can be filtered to easily locate this certificate by changing theView Style to Imported certificates and requests.


    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (17)
Creating a Certificate Signing Request (CSR) in SonicWall Appliance
  1. Navigate toAppliance | Certificates page and clickNew Signing Request.
  2. Fill out the CSR form in SonicWall device and clickGenerate. For the most part, you can leave the drop-down boxes to their defaults and fill out each field as suggested by its corresponding drop-down box.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (18)
  3. The Appliance | Certificates page will refresh and your new certificate will appear with a type ofPending Request.

    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (19) NOTE: You may need to refresh the page for this status to appear.


    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (20)
  4. ClickExport How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (21)button. In the new Pop-up window, click Export and save the file locally on your device for later import to the Windows Server.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (22)
Requesting a certificate for the CSR from the MS Certificate Authority

How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (23) TIP: If the MS CA server is running IIS (and the admin has allowed access to this interface), the easiest way to submit the firewall s CSR is via web browser.

  1. Open a browser and enter http://x.x.x.x/certsrv/ (replace x.x.x.x with the IP address of your MS CA server). You will be presented with the certificate services interface (see below).
  2. Select the task Request a Certificate.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (24)
  3. Clickadvanced certificate request.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (25)
  4. Select Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (26)
  5. Copy and paste the contents of the CSR in the Saved Request box.
  6. Select Web Server under Certificate Template.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (27)
  7. Select DER encoded and clickDownload Certificate. Save the file to your local system using whatever name you wish this file will be imported into SonicWall appliance.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (28)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (29)
Validating the Certificate on the SonicWall Appliance
  1. Navigate toSystem|Certificates page.
  2. ClickUpload Signed certificateHow can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (30) for the certificate that has type Pending request.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (31)
  3. Browse for the downloaded file from the CA and clickUpload.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (32)

    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (33)
  4. Once the certificate has been uploaded, the certificate will show typeas Local Certificate and Validated as YES.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (34)
How to Test

Now that a signed certificate has been imported into the SonicWall, it can be used for HTTPS management of SonicWall interfaces as well as for SSL-VPN. To set the imported certificate as the management certificate, perform the following steps

  1. Navigate toAppliance | Base Settings.
  2. Under the Web Management Settings section, select the imported certificate under Certificate Selection.
  3. ClickAccept to save the changes.
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (35)
  4. When logging into the SonicWall after importing the signed certificate you may receive the following browser errors:
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (36)
    How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (37) CAUTION:
    "The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority".
    You get this error because the issuing CA certificate is not in the certificate store of the browser. To resolve it, install the certificate in the certificate store of the browser.
    "The name on the security certificate is invalid or does not match the name of the site".
    You get this error because you are accessing the site using a different name from the certificate Common Name (CN) you entered when creating the Certificate Signing Request (CSR). In the above example the SonicWall is being accessed using an IP address although the CN in the certificate is SonicWall.local (see above) : You have two options to overcome this error:
  • When creating the CSR enter the CN as 192.168.168.168.
  • Map the IP address of the SonicWall to the CN.

Related Articles

  • NSv upgrade from 7.0.1 to 7.1.X
  • Netextender failing to connect with error "Initializing engine…failed"
  • High Availability setup not working - Error Contacting Peer HA Firewall

Categories

  • Firewalls > SonicWall SuperMassive 9000 Series > System
  • Firewalls > TZ Series > System
  • Firewalls > NSa Series > System
  • Firewalls > NSv Series > System

Not Finding Your Answers?

ASK THE COMMUNITY

Was This Article Helpful?

How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (38)YESHow can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (39)NO

How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall (2024)

FAQs

How can I obtain a Certificate from a Windows Certificate Authority (CA)? | SonicWall? ›

Using a web browser, connect to https://<servername>/certsrv , where <servername> is the host name of the computer running the CA Web Enrollment role service. Select Request a certificate. Select Advanced certificate request. Select Create and submit a certificate request to this CA.

How to obtain a certificate from a Certificate Authority CA? ›

Use the AD-CS web portal to request a certificate
  1. On the Microsoft Active Directory Certificate Services Welcome page, select Request a certificate.
  2. On the Request a Certificate page, select advanced certificate request.
  3. Select Create and submit a request to this CA.
  4. An Advanced Certificate Request opens. ...
  5. Select Submit.
Aug 9, 2024

How to generate a certificate from a Certificate Authority? ›

Open Certification Authority MMC Snap-in:
  1. Press Windows Key + R to open the Run dialog.
  2. Type mmc and press Enter.
  3. In the MMC console, go to File > Add/Remove Snap-in .
  4. Select "Certificates" and click "Add >".
  5. Choose "Computer account" and click "Next >".
  6. Select "Local computer" and click "Finish".
Dec 26, 2023

How do I request a certificate from Windows CA Server? ›

Using a web browser, connect to https://<servername>/certsrv , where <servername> is the host name of the computer running the CA Web Enrollment role service. Select Request a certificate. Select Advanced certificate request. Select Create and submit a certificate request to this CA.

How do I find CA certificates in Windows? ›

Go to Start -> Run -> Write adsiedit. msc and press on Enter button. Under Certification Authorities, you'll find your Enterprise Root Certificate Authority server.

How do I download a certificate from a Certificate Authority? ›

Log on to Root Certification Authority Web Enrollment Site. ip_address = Root Certification Authority Server IP. fqdn = Fully qualified domain name of the Root Certification Authority Server. Select Download a CA certificate, certificate chain, or CRL.

How to get CA certificate from Active Directory? ›

Exporting the Root CA Certificate from the Active Directory (AD) Server
  1. In the AD server, launch the Certificate Authority application by Start | Run | certsrv. ...
  2. Right click the CA you created and select Properties.
  3. On the General tab, click View Certificate button.
  4. On the Details tab, select Copy to File.

Where is the certificate File in Windows CA? ›

If you just enter a filename without browsing to a location, your CSR will end up in C:\Windows\System32. When you are done, click Finish. Use a text editor (such as Notepad) to open the file.

How to access Certificate Authority? ›

You can go to your Domain Controller and find the Cert Publishers group in Active Directory. It should have your servers with the Certificate Authority role. If you run the Certutil cmd there, you can get the info of the certificates installed.

How do I export a certificate from Windows CA? ›

Exporting a CA Certificate

Select a root certificate created for your AD domain. The certificate has the same name as your domain. Right-click the certificate, and then select All Tasks > Export from the drop-down menu.

How to find CA certificate file? ›

On the Root Certificate Authorities page, select the root CA certificate. On the Root certificate authority page, above On this page menu on the right, in the Download CA (paper with down arrow icon) dropdown, select the format you want to download the certificate in: Download certificate .

What is my CA certificate? ›

A certificate authority (CA), also sometimes referred to as a certification authority, is a company or organization that acts to validate the identities of entities (such as websites, email addresses, companies, or individual persons) and bind them to cryptographic keys through the issuance of electronic documents ...

How do you send the certificate request to the certificate authority of your choice? ›

  1. Go to the Certificate Authority Service page on the Google Cloud console. ...
  2. Click Request a certificate.
  3. Select a region. ...
  4. Select a CA pool.
  5. To choose a CA, click Use a specific CA from this CA pool, and then select a CA from the list.

How to generate a certificate from CSR? ›

Steps to generate a key and CSR
  1. Set the OpenSSL configuration environment variable (optional).
  2. Generate a key file.
  3. Create a Certificate Signing Request (CSR).
  4. Send the CSR to a certificate authority (CA) to obtain an SSL certificate.
  5. Use the key and certificate to configure Tableau Server to use SSL.

How to purchase an SSL certificate from a trusted certificate authority? ›

Purchase an SSL/TLS certificate from a trusted Certificate Authority (CA).
  1. Create a private key.
  2. Create a certificate signing request (CSR) with a private key. ...
  3. Send the CSR to the trusted CA authority.
  4. The CA authority will send you the SSL certificate signed by their root certificate authority and CA private key.
Oct 26, 2023

How does Certificate Authority CA work? ›

They help secure the internet for both organizations and users. The main goal of a CA is to verify the authenticity and trustworthiness of a website, domain and organization so users know exactly who they're communicating with online and whether that entity can be trusted with their data.

Top Articles
Can You Back Out of a House Offer? (Buyer’s Guide) | Chase
Buying a House With an LLC: Pros & Cons | BiggerPockets Blog
Melson Funeral Services Obituaries
Walgreens Pharmqcy
Kobold Beast Tribe Guide and Rewards
oklahoma city for sale "new tulsa" - craigslist
Konkurrenz für Kioske: 7-Eleven will Minisupermärkte in Deutschland etablieren
Oppenheimer & Co. Inc. Buys Shares of 798,472 AST SpaceMobile, Inc. (NASDAQ:ASTS)
Jcpenney At Home Associate Kiosk
What Is Njvpdi
Lenscrafters Huebner Oaks
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Interactive Maps: States where guns are sold online most
Milspec Mojo Bio
Lcwc 911 Live Incident List Live Status
Buy Swap Sell Dirt Late Model
bode - Bode frequency response of dynamic system
Azpeople View Paycheck/W2
We Discovered the Best Snow Cone Makers for Carnival-Worthy Desserts
12 Top-Rated Things to Do in Muskegon, MI
10 Best Places to Go and Things to Know for a Trip to the Hickory M...
Marlene2995 Pagina Azul
Remnants of Filth: Yuwu (Novel) Vol. 4
Mawal Gameroom Download
United E Gift Card
Life Insurance Policies | New York Life
De beste uitvaartdiensten die goede rituele diensten aanbieden voor de laatste rituelen
Weekly Math Review Q4 3
11 Pm Pst
Indiefoxx Deepfake
Is The Nun Based On a True Story?
The Banshees Of Inisherin Showtimes Near Reading Cinemas Town Square
Trap Candy Strain Leafly
Gifford Christmas Craft Show 2022
Hireright Applicant Center Login
Umd Men's Basketball Duluth
LumiSpa iO Activating Cleanser kaufen | 19% Rabatt | NuSkin
Az Unblocked Games: Complete with ease | airSlate SignNow
Lawrence E. Moon Funeral Home | Flint, Michigan
Minterns German Shepherds
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Theater X Orange Heights Florida
Freightliner Cascadia Clutch Replacement Cost
Every Type of Sentinel in the Marvel Universe
Slug Menace Rs3
Wvu Workday
Ciara Rose Scalia-Hirschman
Sj Craigs
Ihop Deliver
Texas 4A Baseball
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 5888

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.