Generating a certificate at a Certification Authority
These instructions are applicable to a Microsoft Enterprise Certification Authority deployed on Windows Server 2016.
It is recommended to use the Internet Explorer browser. Other browsers may incorrectly display some pages of the Microsoft Enterprise Certification Authority.
In a browser, open the page of your Certification Authority: https://<server address>/certsrv.
Select Request a certificate.
The Request a certificate page opens.
Select advanced certificate request.
The Advanced Certificate Request page opens.
Select Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
The Submit a Certificate Request or Renewal Request page opens.
In the Base-64-encoded certificate request (CMC or PKCS #10 or PKCS #7) field, paste the request file contents that you copied at step 1.
In the Certificate Template drop-down list, select Subordinate Certification Authority.
Click Submit.
The Certificate Issued page opens.
Do the following:
Select the certificate file encoding.
The application supports operations with certificates in DER and Base64 encoding.
Select the certificate format:
If you want to download an end certificate file with the CER extension that does not contain intermediate certificates, select Download certificate.
If you want to download the full chain of certificates in PKCS#7-container format with the P7B extension, select Download certificate chain.
It is recommended to download the full chain of certificates to avoid problems associated with verifying intermediate Certification Authorities.
The certificate will be generated and saved on your computer in the browser's downloads folder.