Generate a CSR for Windows 2012/IIS 8.5

This article will show you how to generate a Certificate Signing Request (or CSR) in Microsoft’s Internet Information Services manager.

    1. From the 2012 Server Start screen, open Internet Information Services (IIS) Manager
    2. In IIS, click on the server name.
    3. Find the Server Certificate icon in the middle pane; double click to open it.
    4. Check the right pane for the Actions group and click Create Certificate Request.
    5. The Distinguished Name Properties page will appear; fill in all of the fields accordingly:
      • Common Name –  The hostname that will use the certificate (usually a fully-qualified domain name like, or
      • Organization – The legal name of your company or organization.
      • Organization Unit – The departmental or division name for your group.
      • City/Locality – The city where your company is located.
      • State/Province – The state where your company is located.
      • Country/Region – Please use the two-character abbreviation for your country.

      Click Next when finished.

    6. The “Cryptographic Service Provider Properties” window now appears.  Use the default Cryptographic Service Provider, unless you have a specific one to use.  In the Bit Length field, select at least 2048 (or higher) and click Next.
    7.  The “File Name” page will now appear.  You are asked to enter a file name for the new Certificate Signing Request; please browse to a location and save the file.
      If you do not enter a path, the file will be saved to c:/Windows/System32.
    8. Click “Next” when you have entered the file name and recorded the path in your notes.
    9. You are done!  You may now open the newly created CSR file with a text editor and copy and paste to  submit the contents to your CSR submission page at