Create a CSR request
- Log in to the computer hosting BEMS with the service account.
- Open the Microsoft Management Console (MMC).
- Click Console Root.
- Click File > Add/Remove Snap-in
- In the Available snap-ins column, click Certificates > Add.
- In the Certificates snap-in wizard, select Computer account. Click Next.
- On the Computer > Select Computer screen, select Local Computer. Click Finish.
- Click OK.
- In the Microsoft Management Console, expand Certificates (Local Computer).
- Right-click Personal and click All Tasks > Advanced Operations > Create Custom Request.
- In the Certificate Enrollment wizard, click Next.
- On the Select Certificate Enrollment Policy screen, select Proceed without enrollment policy. Click Next.
-
On the Custom
request screen, select the following settings:
- In the Template field, select (No template) Legacy key
- In the Request format option, select PKCS #10
- Click Next.
- On the Certificate Information screen, expand Details for the custom request.
- Click Properties.
- Click the Subject tab.
-
On the Subject tab,
in the Subject name section, complete
the following actions:
- In the Type drop-down list, select Common Name.
- In the Value field, type the <BEMSFQDN> of the computer that hosts the Connect service (for example, BEMSHost.mycompany.com).
- Click Add.
-
In the Alternative
name section, add two values by completing the following
actions:
- In the Type drop-down list, select DNS.
- In the Value field, type the <BEMSFQDN> of the computer that hosts the Connect service (for example, BEMSHost.mycompany.com).
- Click Add.
-
On the Extensions
tab, complete the following actions:
- In the Extended Key Usage (application policies) drop-down list, in the Available options column, click Server Authentication.
- Click Add.
-
On the Private Key
tab, complete the following actions:
- In the Cryptographic Service Provider drop-down list, in the Select cryptographic service provider(CSP) section, clear all the check boxes.
- Select the Microsoft RSA SChannel Crytographic Provider (Encryption) check box.
- In the Key size field, type 2048.
- In the Key options drop-down list, in the Key type drop-down list, select Exchange.
- Click Apply.
- Click OK.
- Click Next.
- Enter a name for the certificate request and save it to your desktop.
- In the File format section, select Base 64.
- Click Finish.
- Submit the certificate request that you created to the certificate authority to obtain a certificate.
- Import the signed certificate to the computer that hosts the Connect service