On This Page
Install and Use a Server Certificate on a Client Machine
This topic provides the basic steps for installing and using a server certificate on
a client machine.
Requirements:
- You have the server's public certificate.
- If you keep the root certificate authority (CA) offline, you have the intermediate certificates.
- To install and use a server certificate on a client machine:
- Install the server certificate on a client machine.
ADDITIONAL INFORMATION
- On a Linux-based client machine:
- Copy the server certificate to the appropriate directory. Example:bash sudo cp server.crt /etc/ssl/certs/
- Update the CA certificates. Example:bash sudo update-ca-certificates
- On a Windows client machine, use the certmgr.exe tool to import the server certificate into the Trusted Root Certification Authorities Store.
- Configure the client application to use the standard server certificate for mTLS. The configuration details vary depending on the application.
ADDITIONAL INFORMATION
- Example for the client URL (cURL) command-line tool:bash curl --cert client_bundle.crt --key client.key --cacert server.crt https://example.com
- Example for Java:bash keytool -import -alias client -file client_bundle.crt -keystore keystore.jks keytool -import -alias server -file server.crt -keystore truststore.jks
AFTER COMPLETING THE TASK
After you successfully install and use a server certificate on a client machine,
continue to the tasks contained in the section Encrypt and Upload the Batch File.