| ¤ Home » SSL Certificate Help » The Process » Generating Private Key & CSR Generating Private Key & CSRGenerate a Private Key and Certificate Signature Request (CSR) from your Web ServerPrior to enrolling/reissuing/renewing a Certificate, you must generate a minimum of 2048-bit Private Key and CSR pair from your web server. Digital IDs make use of a technology called Public Key Cryptography, which uses Public and Private Key files. The Public Key, also known as a Certificate Signature Request (CSR), is the key that will be sent to Thawte. The Public Key is generated on your server and validates the computer-specific information about your web server and Organization when you request a Certificate from Thawte. The Private Key will remain on the server and should never be released into the public. Thawte does not have access to your Private Key. It is generated locally on your server and is never transmitted to thawte. The integrity of your Digital ID depends on your Private Key being controlled exclusively by you. A CSR can not be generated without generating a Private Key file. Similarly the Private Key file can not be generated without generating a CSR file. In certain web server software platforms like Microsoft IIS, both are generated simultaneously through the Wizard on the web server. Typically, you will be prompted to enter the following information about your Organization in order to generate the Private Key and CSR (Public Key) pair from the web server:
You need to get in touch with your Web Hosting provider and request them to generate a CSR for your business after supplying them the above mentioned information. If you have bought Web Hosting for the domain name from us, we will take care of generating the CSR for you. NoteWhile generating a Certificate Signature Request (CSR) for a domain name hosted on a Windows server, you need to set a Password that contains only alphanumeric characters. If non alphanumeric characters are included, you will encounter the below error message while enrolling/ reissuing/ renewing your Digital certificate: CSR contains unsupported extensions You need to use a valid 2-letter country code while generating a Certificate Signature Request (CSR). Otherwise, you will encounter the below error message while enrolling/ reissuing/ renewing your Digital certificate: CSR contains an invalid 2-letter country code This message is also encountered if your generate a Certificate Signature Request (CSR) on an IIS Server, using the Renew Certificate option. Hence, this option is not to be selected while generating the CSR. |





