How to Renew your Expiring SSL Certificate for IIS 5/6

Generate a New CSR in the Utility

  1. Download the Certificate Management Tool and run it on your IIS 5/6 server with the expiring certificate.

  2. Select your SSL Certificate that's expiring and click Create CSR.

    Click Create CSR for IIS 6

  3. Click Yes to 'import the attributes from the current certificate into the new CSR'.

    Create a renewal CSR for IIS 6

  4. Click the Copy CSR button.

    Copy your CSR to the Clipboard

  5. Log into your account, click '+' next to your order number, then click Renew and fill out all of the details and paste your CSR into step 2 of the order process.

IIS 6 SSL Certificates, Guides, & Tutorials

Buy Now Learn More

Import the Certificate with the Utility

Once your renewal certificate order has been validated and issued, you will need to use the Certificate Management Tool to import the file to your Microsoft Server.

  1. Run the Certificate Management Tool (DigiCertUtil.exe).

  2. Click the Import button and find your_domain_com.cer, and choose Next.

    Import an IIS 6 .cer SSL Certificate

  3. For 'Friendly Name' enter an alias for this SSL Certificate to help you keep track of it in the future and press Finish.

    Assign a Friendly Name

Replace the Old Certificate in IIS

    Next configure IIS to start using the new certificate is assign the certificate in IIS following the instructions below.

  1. Open Internet Information Services Manager (IIS) by clicking Start > Administrative Tools > Internet Information Services (IIS) Manager.

  2. Right click on the website you are assigning the SSL certificate onto and choose Properties.

  3. Go to the Directory Security tab and click Server Certificate.

  4. When given the choice to Remove, Replace or Renew the current certificate, choose Replace and click Next.

  5. Select the certificate that was just installed with the certificate management tool and click through the wizard until it is completed.

Check Your SSL Installation

Go to www.digicert.com/help and enter the DNS name of the site you are securing to test your certificate (e.g. www.yourdomain.com, or mail.yourdomain.com) to verify the installation is correct and the expiration date shows the renewed certificate.