SSL Market Guide - Sourcing and Installation
u: gerryg@spiderscope.com
p: SSLSpiD3r1688
New Certificate
- Login.
- Order New (left hand side)
- Check RapidSSL click 'Order'
- Complete form:
- Domain: www.spiderscope.com (example)
- Validity: 1 Year
- Date of Issue: NEW
- Certificate Applicant (company you're buying for: i.e. London Party Boats)
- Person for Authorization: (Your own details or support@)
- Uncheck " Technical contact is the same as the authorization contact" ensure technical contact email is set to gerryg@spiderscope.com (required for renewal notices)
- Billing details – should be left with Gerry's details.
- Email – doesn't matter, we wont be using this method (unless we don't host the site / have ftp access).
- Alternative verification (preferred method) – select 'by a file to FTP'
- Generate CSR and private key, SAVE and KEEP this file in jid folder.
- Check the checkboxes and click 'Order an SSL certificate'
- Pay for certificate, List of Orders > Detail > Pay via PayPal (pp@spiderscope.com)
- Follow the verification steps under 'Domain Verification' below.
- Follow the pfx generation and certificate installation procedures below.
Renewal
- Login.
- List of certificates (left hand side)
- Find the domain in the list - probably under the exipiring certifiates section - click magnifying glass.
- Click the big green Renew button
- Click proceed under 'I want to renew the same certificate'
- Select '1 year' validity and proceed.
- The forms should already be filled out already, apart from the next point.
- Uncheck " Technical contact is the same as the authorization contact" ensure details are set to gerryg@spiderscope.com (required for renewal notices)
- Click proceed
- Billing details – should be left with Gerry's details - proceed
- Email – doesn't matter, we wont be using this method (unless we don't host the site / have ftp access).
- Alternative verification (preferred method) – select 'by a file to FTP'
- Click the "Generate CSR and private key" link, SAVE and KEEP this file in jid folder. - Proceed
- Check the T&C's checkboxes and click 'Order an SSL certificate'
- Pay for certificate, List of Orders (Left Menu) > Detail (magnifying glass) > Pay via PayPal (pp@spiderscope.com)
- The main list of orders will now show the new certificate as 'request placed'
- After a short while the fileauth.txt will be available to download from the main order details page, save it to the JID folder, check the code is different from last years as the old one will still be available to download and there is no indication it has updated
- Follow the verification steps under 'Domain Verification' below.
- Wait for the request to be processed, this may take about 20 min -
- Follow the pfx generation and certificate installation procedures below.
Domain Verification
- Create folder(s) in root: /.well-known/pki-validation/
- Upload file the provided "fileauth.txt" file to /.well-known/pki-validation/
- Click 'Update' near top of page. Certificate is usually issued within 15-20 minutes – Gerry will receive an email confirming how to verify domain (provided you filled your details in as the person for authorization).
- Validation may be hampered by any redirects from HTTP to HTTPS (purely conjecture at the moment)
Generating PFX File
- Under the "Export of the SSL certificate (PFX format)" heading (almost bottom fo page) click 'Show Form'
- Paste your private key (as saved in step 11 above)
- Enter a password (usually www.domain.co.uk)
- Click 'Create PFX file' (errors appear at very top of page)
- Download file, save in jid folder.
Installing Certificate
Part One / Server Certificate Installation
- Upload the PFX file via FTP
- RDP in to server
- Double click certificate, place in 'Local Machine', click through the steps, mark as exportable and enter password specified previously (usually the domain name)
Part Two / IIS Bindings
- Open Internet Information Serviecs (IIS)
- Expand Server > Sites > Click IIS Instance of Website.
- Click 'Bindings' in the right hand Actions panel
- If renewing select new certificate for both www and non www https bindings (Select https binding, edit, click 'select' and choose the new certificate which is obvious by expiry date)
- Check the "Require Server Name Indication" option is ticked
- If new – add bindings for www and non www. (also make sure you set up canonical domain rewrite rule and redirect to https)
- If you disabled the HTTPS redirect for the validation step, re-enable it now
- Visit website in your browser, click the padlock and view the certificate to check the expiration date is correct.
