Export and restore a PFX file to IIS

Certificates snap-in

1. Open the Microsoft Management Console (MMC).

Start -> Ausführen -> Geben Sie «mmc» (ohne Anführungszeichen) ein und klicken Sie auf OK oder drücken Sie die Eingabetaste.

Starten Sie Ausführen MMC

2. Öffnen Sie das Snap-In- Fenster » Hinzufügen / Entfernen» .

File -> Add / Remove Snap-In

AddRemove SnapIn

3. Add the Certificates snap-in.
Click Add and double-click You then Certificates.



4. Select Computer Account and click Next .

Note: This step is very important. It must be the computer account and not another account!

5. Select Local Computer and click Finish.

6. Close the standalone snap in Add window and click OK in the Add / Remove Snap-in window.

7. Click the plus sign (+) next to Personal , then click the Certificates folder.

export process

1. Right-click the certificate you want to export and select All Tasks -> Export.

2. When the Certificate Export Wizard starts, click Next on the welcome page.

3. Select Yes, export private key , then click Next .

4. Behalten Sie die Standardeinstellungen des Fensters bei und klicken Sie auf Further .

Please note: Dies sind die Standardeinstellungen. Aktivieren Sie jedoch das Kontrollkästchen «Wenn möglich, alle Zertifikate in die Kette aufnehmen», und belassen Sie den Rest wie er ist.

5. Enter and confirm a password for the PFX file. Then click Next .

Note: This is a password that you create.

6. Save the file on the page to be exported in a safe and easy to remember place (example: My files, C drive or desktop) and then click on Next .

Note: Instead of entering , you can click the Browse button to navigate to a place where You want to save .

7. When the previous step is complete, a confirmation page will appear. Click Finish to complete the export process.

You now have the PFX file ready for transport. This file usually only contains your certificate and private key in one file.
Note: If you selected Include all certificates in the certification path if possible In this case your file contains the complete certificate chain with the private key and the end entity / domain certificate ,

import process

Note: The following steps assume that you are in the Certificates snap-in part of the MMC. If you're not there yet, follow the section above entitled Certificates Snap-In .

1. Right-click the Certificates folder under the Personal folder and select All Tasks-> Import. The

Import Certificate Wizard appears.

2. When the Certificate Import Wizard starts, click Next


4. Enter the password for the PFX file in the field provided and click on Next .

Note: If you need to save this key again during import, make sure that the check box is selected. Mark this key as exportable ... is deactivated.

5. Automatically select the certificate store based on the certificate type and click Next .

6. On the Certificate Import Wizard page, click Finish .

7. Close the MMC. If you are prompted, you do not have to save the changes.

You have successfully completed the certificate import wizard.

Place the newly imported certificate in IIS 5.x and 6.x.

  1. Open the IIS manager
  2. Right-click the site where you want to use the certificate and select Properties .
  3. Klicken Sie auf der Verzeichnissicherheit , und klicken Sie auf der Server – Zertifikat – Taste.
  4. Follow the wizard.
  5. If a certificate already exists on the website, select Replace and click You then Next .
    Note: If a certificate does not yet exist on this site, click Assign ... and then click Next .
  6. Complete the Certificate Assistant.
  7. Restart website


Placing a newly imported certificate in IIS 7.x.

  1. Open IIS (Start -> Administrative Tools -> IISM -> Server Name).
  2. Open websites by left-clicking the small triangle to the left of websites .
  3. Left-click the website name once. Example: Default Web Site.
  4. Wählen Sie im Untermenü » Site bearbeiten» die Option » Bindungen» . (siehe Bild)
  5. In the next window, left-click the https, type to select it.
  6. Click Edit .
  7. In the SSL Certificate drop-down box, select the appropriate SSL certificate.
  8. click on OK , um die Änderungen zu speichern.
  9. Verify that the certificate on the website works by visiting the website in your web browser.
