11.3.7.4. Procedure – Signing CA certificates with external CAs

If you want to use an external CA to sign the certificate of a local CA, complete the following steps.

  1. Generate a private-public keypair and an associated CSR using the Generate button of the Certificates tab.

  2. Export this CSR into a file using the Export button.

  3. Have the CSR signed.

  4. If the CA approves your identity and signs the certificate, Import it to the PKI system of MS.

    Note

    Be sure to select the appropriate entity (that is, to import the signed certificate to the proper CSR) and to check the Import into selected object option.

  5. The certificate entity can now be distributed and used on your machines.