Create a CSR request
- Log in to the computer hostingBEMSwith the service account.
- Open theMicrosoftManagement Console (MMC).
- ClickConsole Root.
- ClickFile > Add/Remove Snap-in
- In theAvailable snap-inscolumn, clickCertificates > Add.
- In theCertificates snap-in wizard, selectComputer account. ClickNext.
- On theComputer > Select Computerscreen, selectLocal Computer. ClickFinish.
- ClickOK.
- In theMicrosoftManagement Console, expandCertificates (Local Computer).
- Right-clickPersonaland clickAll Tasks > Advanced Operations > Create Custom Request.
- In theCertificate Enrollmentwizard, clickNext.
- On theSelect Certificate Enrollment Policyscreen, selectProceed without enrollment policy. ClickNext.
- On theCustom requestscreen, select the following settings:
- In theTemplatefield, select(No template) Legacy key
- In theRequest formatoption, selectPKCS #10
- ClickNext.
- On theCertificate Informationscreen, expandDetailsfor the custom request.
- ClickProperties.
- Click theSubjecttab.
- On theSubjecttab, in theSubject namesection, complete the following actions:
- In theTypedrop-down list, selectCommon Name.
- In theValuefield, type the <BEMSFQDN> of the computer that hosts theConnectservice (for example, BEMSHost.mycompany.com).
- ClickAdd.
- In theAlternative namesection, add two values by completing the following actions:
- In theTypedrop-down list, selectDNS.
- In theValuefield, type the <BEMSFQDN> of the computer that hosts theConnectservice (for example, BEMSHost.mycompany.com).
- ClickAdd.
- On theExtensionstab, complete the following actions:
- In theExtended Key Usage (application policies)drop-down list, in theAvailable optionscolumn, clickServer Authentication.
- ClickAdd.
- On thePrivate Keytab, complete the following actions:
- In theCryptographic Service Providerdrop-down list, in theSelect cryptographic service provider(CSP)section, clear all the check boxes.
- Select theMicrosoft RSA SChannel Crytographic Provider (Encryption)check box.
- In theKey sizefield, type2048.
- In theKey optionsdrop-down list, in theKey typedrop-down list, selectExchange.
- ClickApply.
- ClickOK.
- ClickNext.
- Enter a name for the certificate request and save it to your desktop.
- In theFile formatsection, selectBase 64.
- ClickFinish.
- Submit the certificate request that you created to the certificate authority to obtain a certificate.