How to create a CSR and import a third-party SSL certificate for MDaemon using Certreq
MDaemon does not have a method of creating a Certificate Signing Request (CSR) for you in order to obtain a third party SSL certificate issued by a Trusted Root Authority (such as Verisign or GoDaddy). In the past, we have recommended installing Internet Information Server (IIS) and using it to generate the certificate request, but that may be difficult for Administrators who are not used to working with that product or who do not wish to install IIS on their server. Windows has a command line utility, certreq.exe that will allow you to create a certificate request and import the new certificate into the Windows Certificate Store, where it can be used with MDaemon.
The example below will generate a CSR for a 2048 bit key length certificate.
- Purchase an SSL Certificate from an issuing authority
- Create the Certificate Signing Request (CSR):
- Log into your mail server using an Administrator account
Create a file named CSRParameters.inf on the C:\ drive using the contents below as a template (replace the single quotes with double quotes):
[NewRequest] Subject='CN=mail.example.com,OU=Research In Motion Limited,O=Research In Motion Limited,S=Nevada,L=Las Vegas,C=US' KeySpec=1 KeyLength=2048 Exportable=TRUE MachineKeySet=TRUE SMIME=False PrivateKeyArchive=FALSE UserProtected=FALSE UseExistingKeySet=FALSE ProviderName='Microsoft RSA SChannel Cryptographic Provider' ProviderType=12 RequestType=PKCS10 KeyUsage=0xa0 Silent=TRUE [EnhancedKeyUsageExtension] OID=126.96.36.199.188.8.131.52.1
- Open a command prompt and type in:
C:\>certreq -new CSRParameters.inf CSROutput.pem
- Open Windows Explorer and browse to the C drive to locate the CSROutput.pem file
- Using the CSROutput.pem file, go back to the certificate authority and use the file to request your certificate
- Install the certificate:
- Download the certificate as a .crt file
- On the server, open a command prompt type (substituting mail.example.com.crt for the actual name of the .crt file you received from the certificate authority):
C:\>certreq -accept mail.example.com.crt
- Configure MDaemon to use the certificate through the console (see link below)
For more information about the Certreq.exe utility, please see Microsoft's website: http://technet.microsoft.com/en-us/library/cc725793(WS.10).aspx
This article contains reference to an external link or links. Alt-N Technologies is not responsible for the content or availability of external links.
Note: The request and installation of third party SSL certificates is NOT supported by Alt-N Technical Support, and those who choose to use a third party certificate should be aware of all security issues related to installing and using SSL certificates with their Operating System. If you have questions or issues regarding your third party SSL certificate, please contact the vendor from whom you purchased the certificate.
KBA-01714 Using SSL with WorldClient