FILTER BY TAG

Generate and Install a Private Key and Client Certificate on a Client Machine

This topic provides the basic steps for generating and installing a new private key and a client certificate from DigiCert onto a client machine.
IMPORTANT
If you keep the root certificate authority (CA) offline in order to provide a complete chain of trust to clients while using mTLS, the root CA signs an
intermediate certificate
which in turn signs
end-entity certificates
.
In this case, you will need to concatenate the intermediate certificate to the client certificate that you obtain from DigiCert. This step is specified in Step 6 of this procedure.
  1. To generate and install a private key and a DigiCert client certificate on a client machine:
  2. Log in to DigiCert and access your account.
  3. Navigate to the certificate request section and provide the required information.

    ADDITIONAL INFORMATION

    This information is required:
    • Common name (CN)—fully qualified domain name (FQDN) that your certificate will secure.
    • Country (C)—two-digit ISO country code.
    • State or locality (ST)—state, province, or region where the organization is legally registered or located. Specify the full name and not an abbreviation.
    • Organization (O)—full legal company or personal name as registered in your locality.
    • Organizational unit (OU)—department in your organization the that certificate is for.
  4. Use a tool such as Java Key Tool or OpenSSL to generate a certificate signing request (CSR).

    ADDITIONAL INFORMATION

    In this example, OpenSSL is used in a bash environment to generate a new 2048-bit RSA private key and request a CSR.
    openssl req -new -newkey rsa:2048 -nodes -keyout client.key -out client.csr
    The private key is for the domain client.key, and the key is not encrypted in a PKCS#12 file. The CSR filename is client.csr.
  5. Upload the CSR to DigiCert.

    ADDITIONAL INFORMATION

    DigiCert verifies the information provided in the CSR. Verification might involve contacting your organization for validation.
  6. Download the newly generated client certificate from your DigiCert account.
  7. If you keep the root CA offline (as described in the Note at the top of this procedure), you must concatenate the client certificate and the intermediate certificate.

    ADDITIONAL INFORMATION

    In this example, the Linux cat command is used in a bash environment to create the certificate file client_bundle.crt by concatenating the intermediate certificate intermediate.crt to the client certificate client.crt.
    bash cat client.crt intermediate.crt > client_bundle.crt
  8. Install the client certificate (or combined certificates) and private key on a client machine.

    ADDITIONAL INFORMATION

    • To install the certificate and key on a Linux-based client machine, use the sudo command-line utility. In this example, the sudo command is used in a bash environment to install the client certificates and private key:
      sudo cp client_bundle.crt /etc/ssl/certs/ sudo cp client.key /etc/ssl/private/
      The client certificate bundle is copied to /etc/ssl/certs/, and the private key is copied to /etc/ssl/private/.
    • To install the certificate and key on a Windows client machine, use the certmgr.exe tool, which uses the Microsoft Management Console (MMC).

AFTER COMPLETING THE TASK

After you successfully install the private key and client certificate on a client machine, continue to Exchange the Client and Server Public Certificates.