Install and Use a Server Certificate on a Client Machine {#batch-uploading-rest-inst-use-s-cert}
================================================================================================

This topic provides the basic steps for installing and using a server certificate on a client machine.  
Requirements:

* You have the server's public certificate.
* If you keep the root certificate authority (CA) offline, you have the intermediate certificates.

1. To install and use a server certificate on a client machine:

2. Install the server certificate on a client machine.

   #### ADDITIONAL INFORMATION

   * On a Linux-based client machine:

     1. Copy the server certificate to the appropriate directory. Example:

        ```
        bash
        sudo cp server.crt /etc/ssl/certs/
        ```
     2. Update the CA certificates. Example:

        ```
        bash
        sudo update-ca-certificates
        ```
   * On a Windows client machine, use the certmgr.exe tool to import the server certificate into the Trusted Root Certification Authorities Store.

3. Configure the client application to use the standard server certificate for mTLS. The configuration details vary depending on the application.

   #### ADDITIONAL INFORMATION

   * Example for the client URL (cURL) command-line tool:

     ```
     bash
     curl --cert client_bundle.crt --key client.key --cacert server.crt https://example.com
     ```
   * Example for Java:

     ```
     bash
     keytool -import -alias client -file client_bundle.crt -keystore keystore.jks
     keytool -import -alias server -file server.crt -keystore truststore.jks
     ```

#### AFTER COMPLETING THE TASK

After you successfully install and use a server certificate on a client machine, continue to the tasks contained in the section [Encrypt and Upload the Batch File](/docs/cybs/en-us/batch/user/all/rest/batch-upload/batch-uploading-rest-api/batch-uploading-rest-api-task.md "").
