Exchange 2010 CSR Command Wizard

Create a CSR with the Exchange 2010 Powershell. Fill in the requested information, then click Generate.
You can copy your CSR command from the Information box on the right.

Note:    After 2015, certificates for internal names will no longer be trusted.

Certificate Details
Common Name:
Subject Alternative
State / Province:
Key Size:
Making your CSR is easy!

It looks like JavaScript is disabled in your browser. If you enable JavaScript, this panel will show helpful information as you switch from field to field.
Common Name (required)

Your Exchange server's fully qualified domain name. If you are not sure what name to use, please refer to the notes below.

To secure, your common name or one of your subject alternative names must be

Less commonly, you may also enter the public IP address of your server.
Subject Alternative Names (optional)

One per line, or comma separated, either way is fine.

Microsoft recommends including your Exchange server's full public domain name (eg and

If your company has a separate internal active diretory domain you can also include the names users will connect with to access their mail (e.g.,
Department (optional)*

This information is not required. You can leave this field blank.

For private TLS/SSL certificates, this is the department within your organization that you want to appear in the certificate. It will be listed in the certificate's subject as Organizational Unit, or "ou."

*Note: Industry regulations no longer allow Certificate Authorities (CAs) to include the department (organization unit) in public TLS/SSL certificates. See our knowledge base article: DigiCert will deprecate the Organizational Unit field.

The city where your organization is legally located.
State or Province

The state or province where your organization is legally located.

We guessed your country based on your IP address, but if we guessed wrong, please choose the correct country. If your country does not appear in this list, there is a chance we cannot issue certificates to organizations in your country.
Organization name

The exact legal name of your organization. Example: "DigiCert, Inc."

Less commonly, if you do not have a legal registered organization name, you must enter your own full name here.
Key Size

Key sizes smaller than 2048 are considered insecure.
Now just copy and paste this command into Exchange Management Shell. Your CSR will be written to .\\###FILE###.txt.
Learn more about SSL for Exchange Where do I paste this command?

Run the command in the Exchange Management Shell on your server:

  1. Login to your Exchange 2010 server
  2. Click Start > Programs > Microsoft Exchange Server 2010 > Exchange Management Shell
  3. Paste the New-ExchangeCertificate command from this page into the Exchange Management Shell window and press Enter
  4. Your CSR file will appear in text format in the Exchange Management Shell.

    You can copy that text by right clicking in the shell window and selecting mark, and then highlighting the entire body of text, including the Begin and End Certificate Request tags.

What Subject Alternate Names Should I Include?

Our page on choosing SAN names in Exchange 2010 can help you know what names to include in your certificate request.

What should you use as the Common Name?

Use the fully qualified domain name of your Exchange server--the name clients use when connecting to the server, such as

If you'll be using mobile devices to connect to Exchange, you may want to read about Subject Alternative Name compatibility for more details.