On This Page
Generate and Install a Private Key and Client Certificate on a Client Machine
This topic provides the basic steps for generating and installing
a new private key and a client certificate from DigiCert
onto a client machine.
IMPORTANT
If you keep the root certificate authority (CA) offline in order
to provide a complete chain of trust to clients while using mTLS, the root CA signs
an
intermediate certificate
which in turn signs end-entity
certificates
.In this case, you will need to concatenate the intermediate
certificate to the client certificate that you obtain from DigiCert. This step is
specified in Step 6 of this procedure.
- To generate and install a private key and a DigiCert client certificate on a client machine:
- Log in to DigiCert and access your account.
- Navigate to the certificate request section and provide the required information.
ADDITIONAL INFORMATION
This information is required:- Common name (CN)—fully qualified domain name (FQDN) that your certificate will secure.
- Country (C)—two-digit ISO country code.See country-codes.html.
- State or locality (ST)—state, province, or region where the organization is legally registered or located. Specify the full name and not an abbreviation.
- Organization (O)—full legal company or personal name as registered in your locality.
- Organizational unit (OU)—department in your organization the that certificate is for.
- Use a tool such as Java Key Tool or OpenSSL to generate a certificate signing request (CSR).
ADDITIONAL INFORMATION
In this example, OpenSSL is used in a bash environment to generate a new 2048-bit RSA private key and request a CSR.
The private key is for the domain client.key, and the key is not encrypted in a PKCS#12 file. The CSR filename is client.csr.openssl req -new -newkey rsa:2048 -nodes -keyout client.key -out client.csr - Upload the CSR to DigiCert.
ADDITIONAL INFORMATION
DigiCert verifies the information provided in the CSR. Verification might involve contacting your organization for validation. - Download the newly generated client certificate from your DigiCert account.
- If you keep the root CA offline (as described in the Note at the top of this procedure), you must concatenate the client certificate and the intermediate certificate.
ADDITIONAL INFORMATION
In this example, the Linux cat command is used in a bash environment to create the certificate file client_bundle.crt by concatenating the intermediate certificate intermediate.crt to the client certificate client.crt.bash cat client.crt intermediate.crt > client_bundle.crt - Install the client certificate (or combined certificates) and private key on a client machine.
ADDITIONAL INFORMATION
- To install the certificate and key on a Linux-based client machine, use the sudo command-line utility. In this example, the sudo command is used in a bash environment to install the client certificates and private key:
The client certificate bundle is copied to /etc/ssl/certs/, and the private key is copied to /etc/ssl/private/.sudo cp client_bundle.crt /etc/ssl/certs/ sudo cp client.key /etc/ssl/private/ - To install the certificate and key on a Windows client machine, use the certmgr.exe tool, which uses the Microsoft Management Console (MMC).
AFTER COMPLETING THE TASK
After you successfully install the private key and client certificate on a client machine,
continue to Exchange the Client and Server Public Certificates.