<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows PKI blog : certificate requests</title><link>http://blogs.technet.com/pki/archive/tags/certificate+requests/default.aspx</link><description>Tags: certificate requests</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Creating offline certificate requests through the user-interface on Windows Vista or Windows Server 2008</title><link>http://blogs.technet.com/pki/archive/2008/10/04/creating-offline-certificate-requests-through-the-user-interface-on-windows-vista-or-windows-server-2008.aspx</link><pubDate>Sat, 04 Oct 2008 17:43:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3132238</guid><dc:creator>MS2065</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/pki/comments/3132238.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=3132238</wfw:commentRss><description>&lt;p&gt;Windows Vista and Windows Server 2008 have a convenient user interface to create custom certificate requests.  &lt;p&gt;If you want to create a custom certificate request, perform the following steps:  &lt;ol&gt; &lt;li&gt;Start the &lt;strong&gt;Certificates MMC&lt;/strong&gt; snap-in and expand the &lt;strong&gt;Personal – Certificates&lt;/strong&gt; container in the left pane.  &lt;li&gt;Right click the &lt;b&gt;Certificates&lt;/b&gt; container and chose &lt;b&gt;Create custom request&lt;/b&gt; from the context menu.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_2.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Create custom request" border="0" alt="Create custom request" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb.png" width="609" height="277"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="3"&gt; &lt;li&gt;Click &lt;b&gt;Next&lt;/b&gt; to accept the welcome page of the wizard.  &lt;li&gt;If you have Enterprise CA connectivity in your Active Directory forest, you can chose from a list of available certificate templates and create the request based on a specific certificate template. If you want to be independent of any certificate template, select &lt;b&gt;(No template) CNG key.&lt;/b&gt; For more information on Cryptography Next Generation (CNG), see the documentation on &lt;a href="http://msdn2.microsoft.com/en-us/library/aa376210.aspx"&gt;MSDN&lt;/a&gt;.  &lt;li&gt;Click &lt;b&gt;Next&lt;/b&gt; to continue.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_4.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Custom request" border="0" alt="Custom request" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb_1.png" width="610" height="450"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="6"&gt; &lt;li&gt;To customize your certificate request click the little arrow next to the word &lt;b&gt;Details&lt;/b&gt; in the Certificate Enrollment page.  &lt;li&gt;Click the &lt;b&gt;Properties&lt;/b&gt; button.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_6.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Certificate information" border="0" alt="Certificate information" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb_2.png" width="609" height="450"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="8"&gt; &lt;li&gt;Use the dialog tabs to define the certificate properties.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_8.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Certificate properties" border="0" alt="Certificate properties" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb_3.png" width="524" height="519"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="9"&gt; &lt;li&gt;After defining all certificate attributes, click &lt;b&gt;OK&lt;/b&gt;  &lt;li&gt;Finally, specify a filename to save the offline certificate request and click &lt;b&gt;Finish&lt;/b&gt;.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_10.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb_4.png" width="610" height="450"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="11"&gt; &lt;li&gt;The pending certificate request appears in the &lt;i&gt;Certificate Enrollment Requests &lt;/i&gt;container in the &lt;i&gt;Certificates&lt;/i&gt; MMC snap-in until the offline request was accepted.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_12.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/pki/WindowsLiveWriter/e3e110e4aee8_DCD1/image_thumb_5.png" width="610" height="331"&gt;&lt;/a&gt; &lt;/p&gt; &lt;ol start="12"&gt; &lt;li&gt;To verify the certificate request, double-click the pending request in the MMC snap-in. Alternatively use &lt;b&gt;certutil [mycert.req]&lt;/b&gt; at a command-line where [mycert.req] is equal to the file that you saved in step 10.  &lt;li&gt;To enroll for the certificate request, submit the request with &lt;b&gt;certreq –submit&lt;/b&gt;. If no certificate template was selected in the wizard, it is required to specify one as command-line parameter. Also don’t forget the &lt;i&gt;–config&lt;/i&gt; parameter to specify the name of the certification authority where you are enrolling from. The &lt;em&gt;certreq&lt;/em&gt; command might look like the following example:&lt;/li&gt;&lt;/ol&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;certreq –config "myCAserver\myCAname" –submit –attrib "CertificateTemplate:User" mycert.req&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ol start="12"&gt; &lt;li&gt;To install the certificate once it was enrolled, accept the certificate. This will also remove the pending certificate request from the &lt;i&gt;Certificate Enrollment Requests&lt;/i&gt; container. Use &lt;b&gt;certutil –accept [certificatename.cer]&lt;/b&gt; to accept the certificate request.&lt;/li&gt;&lt;/ol&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3132238" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/certificate+requests/default.aspx">certificate requests</category></item></channel></rss>